SECURE NETWORKING

Remote access without exposing the shop floor

Secure VPN connects operators to machines across sites over an encrypted tunnel, with no inbound ports open to the internet.

Reach the machine without publishing it

Getting to a printer from outside its network normally means one of three uncomfortable things: forwarding a port, standing up a reverse proxy, or running a third-party mesh VPN across equipment you would rather not expose at all.

Protype's networking layer replaces all three. Each printer and each client establishes an outbound encrypted tunnel and is addressed inside it. Nothing on the printer listens for inbound connections from the public internet, and no part of your network needs a static address.

  • No port forwarding, no public IP, no dynamic DNS
  • Printers enrolled by serial number and a one-time code
  • Only printer traffic is routed through the tunnel
  1. Your printers

    Each opens an outbound tunnel on first boot

  2. Encrypted endpoint

    Where clients and machines are addressed

  3. Your operators

    Desktop and mobile, on any network

Printers and clients meet inside the tunnel, not on the open internet

How a printer becomes reachable

Each machine and each operator opens an encrypted link outwards, and the two meet inside it.

  1. Printer enrols
    Outbound tunnel, on first boot
  2. Encrypted endpoint
    Where machines and operators meet
  3. Firewall grant
    This operator, that machine
  4. On-machine proxy
    Checks the role, then acts
That last check covers control and file requests, not camera streams — treat tunnel access as camera access.
Nothing to open

No port forwarding, no public IP, no dynamic DNS. Nothing inbound from the public internet.

No network to configure

Allowlist the serial, pair it once. The machine brings its own link up on every boot.

Nothing extra to install

Built into Protype Hub and Protype OS. Only traffic bound for your printers goes through it.

Nothing to wait for

A firewall rule per operator and machine. Withdrawing it takes effect at once, not next sign-in.

How it behaves in production

Enrolment without a technician

A machine registers itself on first boot, receives its tunnel configuration, and brings the link up. The tunnel returns on every subsequent boot without intervention.

Split tunnel by default

Only traffic bound for your printers goes through the tunnel. Ordinary internet traffic on the operator's device is untouched.

Each device reaches only its own printers

Access is granted per pair — this operator, that machine — and enforced by firewall rules on the hub rather than by a check inside the app. Operators cannot see each other's machines, and revoking access takes effect immediately rather than at the next sign-in.

Authentication at the machine

Reaching a printer over the tunnel is not the same as being allowed to control it: control and file requests are validated against roles by a proxy running on the machine. Camera streams are the exception: they are reachable to anyone on the tunnel without a separate credential, so treat tunnel access as camera access.

Multi-site by design

Sites join the same address space, so a fleet spread across buildings behaves like one fleet rather than several islands.

Specifications

Protocol
WireGuard
Topology
Hub and spoke — clients and printers terminate on one endpoint and are addressed inside the tunnel
Access control
Per user-and-printer pair, enforced in the hub's firewall; grants and revocations apply immediately
Inbound ports on the printer
None from the public internet
Identity
Single sign-on with two-factor; printers enrolled from an operator-issued serial allowlist and paired with a one-time code
Client platforms
macOS, Windows, Linux, iOS, Android — built into Protype Hub
Printer side
Built into Protype OS, enrolled on first boot

Questions

Is this a separate product I install?

No. The tunnel is built into Protype Hub on the client side and into Protype OS on the machine side. There is nothing extra to deploy.

Is traffic encrypted end to end between my laptop and the printer?

Each side's link is encrypted, and connections meet at a Protype-operated endpoint rather than peer to peer. If your security review requires end-to-end encryption with no intermediary, talk to us — that is a deployment conversation, not a checkbox.

Does it work across multiple sites?

Yes. Machines in different buildings join the same address space and appear in one fleet.

Discuss your network

Tell us how your sites are connected today and what your security review requires.

Request a demo