Private applications
Provide approved access to an internal web application or service without directly publishing the underlying host.
DC CORE
Reach approved private applications and infrastructure through Central. Outbound agent connections reduce the need to expose management ports on the public internet, while your systems stay with their existing host.
An internal management interface can remain behind your site firewall while an authorised operator reaches it through a controlled Central path. The local service still needs suitable credentials and firewall rules; private transport does not replace its own security.
Provide approved access to an internal web application or service without directly publishing the underlying host.
Reach supported devices for diagnostics, administration and service checks across customer premises and hosted environments.
Connect authorised systems across locations. For an Ethernet-level requirement, explore Ethernet Fabric.
Scroll sideways to compare all columns →
| Mode | How it works | When to consider it |
|---|---|---|
| L0: HTTPS to mesh | Secured ingress receives and terminates public HTTPS, then routes an authorised connection through the mesh to a private service. | Approved web or service publishing with platform identity and tenant controls. |
| L1: encrypted mesh | Traffic is encrypted between communicating endpoints. Relays assist discovery, session establishment or routing and are not intended to inspect the encrypted payload. | Endpoint-to-endpoint paths where the payload must remain protected between the participants. |
L0 and L1 have different encryption boundaries. Do not treat every relay path as end-to-end encrypted. Review connection security or read the architecture detail.
You do not normally need a public inbound management port for supported agent paths. Local segmentation, endpoint security, application authentication and the target service’s firewall rules remain necessary.
Supported platforms · Access behind NAT · Plan access controls
Central starts at £10/month for up to five enrolled devices, with larger monthly packages available. Prices exclude VAT. Compare plans and device limits. Normal monitoring, administration, interactive remote access and private networking are included. There is no separate basic L0 or L1 licence.
Continuous high-volume transfer, large-scale replication, dedicated capacity or specialist transit may require separate pricing agreed for that requirement. See pricing and optional services.
DC Core operates its platform, relay and managed connectivity components. You or your existing provider retain responsibility for local networks, user approvals and endpoints outside a managed service agreement. Global relays may process encrypted traffic and limited service metadata; they are not intended as primary customer tenancy-data storage.
Use Central with your existing infrastructure, or ask us to design and operate the connection. Start with the service address, its location and who needs access.