SECURE NETWORKING
Remote access without exposing the shop floor
Secure VPN connects operators to machines across sites over an encrypted tunnel, with no inbound ports open to the internet.
Reach the machine without publishing it
Getting to a printer from outside its network normally means one of three uncomfortable things: forwarding a port, standing up a reverse proxy, or running a third-party mesh VPN across equipment you would rather not expose at all.
Protype's networking layer replaces all three. Each printer and each client establishes an outbound encrypted tunnel and is addressed inside it. Nothing on the printer listens for inbound connections from the public internet, and no part of your network needs a static address.
- No port forwarding, no public IP, no dynamic DNS
- Printers enrolled by serial number and a one-time code
- Only printer traffic is routed through the tunnel
Your printers
Each opens an outbound tunnel on first boot
Encrypted endpoint
Where clients and machines are addressed
Your operators
Desktop and mobile, on any network
How a printer becomes reachable
Each machine and each operator opens an encrypted link outwards, and the two meet inside it.
- Printer enrolsOutbound tunnel, on first boot
- Encrypted endpointWhere machines and operators meet
- Firewall grantThis operator, that machine
- On-machine proxyChecks the role, then acts
No port forwarding, no public IP, no dynamic DNS. Nothing inbound from the public internet.
Allowlist the serial, pair it once. The machine brings its own link up on every boot.
Built into Protype Hub and Protype OS. Only traffic bound for your printers goes through it.
A firewall rule per operator and machine. Withdrawing it takes effect at once, not next sign-in.
How it behaves in production
Enrolment without a technician
A machine registers itself on first boot, receives its tunnel configuration, and brings the link up. The tunnel returns on every subsequent boot without intervention.
Split tunnel by default
Only traffic bound for your printers goes through the tunnel. Ordinary internet traffic on the operator's device is untouched.
Each device reaches only its own printers
Access is granted per pair — this operator, that machine — and enforced by firewall rules on the hub rather than by a check inside the app. Operators cannot see each other's machines, and revoking access takes effect immediately rather than at the next sign-in.
Authentication at the machine
Reaching a printer over the tunnel is not the same as being allowed to control it: control and file requests are validated against roles by a proxy running on the machine. Camera streams are the exception: they are reachable to anyone on the tunnel without a separate credential, so treat tunnel access as camera access.
Multi-site by design
Sites join the same address space, so a fleet spread across buildings behaves like one fleet rather than several islands.
Specifications
- Protocol
- WireGuard
- Topology
- Hub and spoke — clients and printers terminate on one endpoint and are addressed inside the tunnel
- Access control
- Per user-and-printer pair, enforced in the hub's firewall; grants and revocations apply immediately
- Inbound ports on the printer
- None from the public internet
- Identity
- Single sign-on with two-factor; printers enrolled from an operator-issued serial allowlist and paired with a one-time code
- Client platforms
- macOS, Windows, Linux, iOS, Android — built into Protype Hub
- Printer side
- Built into Protype OS, enrolled on first boot
Questions
Is this a separate product I install?
No. The tunnel is built into Protype Hub on the client side and into Protype OS on the machine side. There is nothing extra to deploy.
Is traffic encrypted end to end between my laptop and the printer?
Each side's link is encrypted, and connections meet at a Protype-operated endpoint rather than peer to peer. If your security review requires end-to-end encryption with no intermediary, talk to us — that is a deployment conversation, not a checkbox.
Does it work across multiple sites?
Yes. Machines in different buildings join the same address space and appear in one fleet.
Discuss your network
Tell us how your sites are connected today and what your security review requires.
Request a demo