
They can't attack what they can't see
NoPorts is a zero trust secure remote access platform from Atsign that eliminates exposed network ports entirely. It uses cryptographic authentication and end-to-end encryption to make SSH, RDP, VNC, SMB, and MQTT connections invisible to attackers, with no inbound ports, no VPN, and no public IPs required.
Eliminates all exposed listening ports so devices and servers are invisible to internet scanners and attackers.
Every connection is authenticated with cryptographic keys tied to a unique global identity (atSign), not IP addresses or passwords.
Traffic is encrypted device-to-device with keys stored locally on each endpoint, so no intermediary (including Atsign) can decrypt sessions.
Supports SSH, RDP, VNC, SMB file sharing, and MQTT, replacing multiple bastion and VPN tools with one platform.
Implements ZTNA principles with per-device identity and policy enforcement instead of perimeter-based trust.
Works through CGNAT, mobile networks, and Starlink connections without needing port forwarding or static IPs.
Provides direct, segment-of-one connections that remove the lateral movement risk inherent in traditional VPNs.
Reach remote IoT devices behind CGNAT or restrictive networks without exposing them to the internet.
Replace legacy VPNs with per-device zero trust connections that limit lateral movement.
Keep internal AI workloads and MCP servers off the public internet while still serving authorized clients.
Give engineers SSH and RDP access to servers and workstations without bastions or open ports.
Protects private AI workloads and MCP servers by keeping them off the public internet while still allowing authorized remote access.
Built on the open source atPlatform SDK, allowing developers to embed NoPorts connectivity into custom applications and devices.
Manage edge devices on Starlink or mobile networks where inbound connections are normally impossible.

Zero trust access that scales