DC CORE

Private networking built to reduce inbound exposure.

Reach approved private applications and infrastructure through Central. Outbound agent connections reduce the need to expose management ports on the public internet, while your systems stay with their existing host.

Connect to the service you need.

An internal management interface can remain behind your site firewall while an authorised operator reaches it through a controlled Central path. The local service still needs suitable credentials and firewall rules; private transport does not replace its own security.

Private applications

Provide approved access to an internal web application or service without directly publishing the underlying host.

Remote operations

Reach supported devices for diagnostics, administration and service checks across customer premises and hosted environments.

Sites and devices

Connect authorised systems across locations. For an Ethernet-level requirement, explore Ethernet Fabric.

Plan access for a private application →

Choose the connection mode.

Scroll sideways to compare all columns →

ModeHow it worksWhen to consider it
L0: HTTPS to meshSecured ingress receives and terminates public HTTPS, then routes an authorised connection through the mesh to a private service.Approved web or service publishing with platform identity and tenant controls.
L1: encrypted meshTraffic is encrypted between communicating endpoints. Relays assist discovery, session establishment or routing and are not intended to inspect the encrypted payload.Endpoint-to-endpoint paths where the payload must remain protected between the participants.

L0 and L1 have different encryption boundaries. Do not treat every relay path as end-to-end encrypted. Review connection security or read the architecture detail.

Prepare one connection.

  1. Identify: name the target service, local address and authorised users or systems.
  2. Choose: match the connection mode to the access and confidentiality requirement.
  3. Connect: place an approved agent with appropriate access to the target and allow the outbound connections specified in Central.
  4. Verify: test the route from the actual remote location, confirm permissions and check that access can be revoked.

You do not normally need a public inbound management port for supported agent paths. Local segmentation, endpoint security, application authentication and the target service’s firewall rules remain necessary.

Supported platforms · Access behind NAT · Plan access controls

Standard connectivity is included.

Central starts at £10/month for up to five enrolled devices, with larger monthly packages available. Prices exclude VAT. Compare plans and device limits. Normal monitoring, administration, interactive remote access and private networking are included. There is no separate basic L0 or L1 licence.

Continuous high-volume transfer, large-scale replication, dedicated capacity or specialist transit may require separate pricing agreed for that requirement. See pricing and optional services.

DC Core operates its platform, relay and managed connectivity components. You or your existing provider retain responsibility for local networks, user approvals and endpoints outside a managed service agreement. Global relays may process encrypted traffic and limited service metadata; they are not intended as primary customer tenancy-data storage.

Connect your first private service.

Use Central with your existing infrastructure, or ask us to design and operate the connection. Start with the service address, its location and who needs access.