GHGatehousePublic alpha

Zero-install browser access for private web applications

Invite someone into one internal web app, not your whole network.

Gatehouse is a controlled access gateway for professional teams that need temporary, auditable browser access to internal dashboards, admin panels, staging tools, and support portals without issuing VPN credentials or opening inbound firewall ports.

Browser
HTTPS
Gatehouse Relay
multiplexed WebSocket
Gatehouse Connector
private HTTP
Internal Service
allow-listed target

What it is

Gatehouse is a narrow, policy-bound route to selected private HTTP and HTTPS services.

The system creates time-limited access sessions for named users, named services, and permitted HTTP methods. It is designed for accountable support, vendor review, incident response, and internal operations workflows where a full private network tunnel would be excessive.

It is not a VPN, remote desktop system, SSH gateway, port scanner, or general-purpose reverse proxy.

Security posture

Built around explicit authority and a reviewable record.

Deny by default

Only registered services can be reached. The connector rejects arbitrary destinations and blocks private metadata endpoints.

Scoped sessions

Each access link is bound to one user, one service, allowed methods, expiration, and revocation state.

Audit-minded records

Gatehouse records metadata about grants, sessions, streams, revocations, and connector status without storing private response bodies.

How it works

Install one connector in the private network. Visitors use only a browser.

1Enroll connector

Run the .NET or Docker connector near the private web application. It dials out to the relay.

2Register service

Declare the internal URL and method policy. Gatehouse never discovers the network for you.

3Create grant

Choose the user, service, capabilities, and expiration window.

4Share access link

The visitor opens a scoped browser session through the Gatehouse gateway.

Getting started

What you need to install

For the alpha, the public control plane is hosted at Gatehousebox. Your private side runs one outbound connector and points it at the relay.

Connector runtime.NET or Docker
Network pathOutbound WebSocket only
Private appHTTP or HTTPS allow-listed target

Pricing

Public alpha is free. Commercial plans are coming soon.

Alpha

Evaluation workspace for one organization, two connectors, and five private services.

Free during alpha

Professional

Team administration, expanded audit retention, branded access pages, and production support.

Coming soon

MSP

Multi-client operations, delegated administration, and customer-specific relay policy.

Coming soon