CHERT KATULA
Self-hosted edge security platform

The fortified gate between the open internet and your edge.

CHERT Katula stands in front of your sites and devices — resolving their DNS, filtering their traffic, and carrying it through an authenticated tunnel to hardware that never has to face the internet directly. Your infrastructure, your keys, one console.

gate operational · self-hosted authoritative DNS · real TLS at the edge

The path through the gate

Traffic never reaches your box until it has passed the wall.

Every request enters through Katula. It is resolved, inspected, and filtered at the edge, then handed to your ChertBox over a tunnel only Katula can open.

Origin

The open internet

Visitors, clients, and — inevitably — probes and attacks, all arriving at your public name.

resolve
inspect
The gate

CHERT Katula

Your own nameservers answer. The WAF and edge filter reject what shouldn't pass.

DNSWAFTLSedge filter
authenticated
tunnel
Destination

Your ChertBox

No public IP. No open ports. Reachable only through the tunnel the gate holds open.

What the platform does

Six systems, one wall — run from a single control plane.

DNS

Self-hosted DNS

Your own authoritative nameservers, replicated across nodes. Every domain you serve resolves from infrastructure you control — no third party in the path.

WAF

Application firewall

The OWASP Core Rule Set enforced at the gate. Injection, cross-site scripting, and known exploits are blocked before they reach anything behind you.

Tunnel

Encrypted tunnels

Your box stays reachable without a public IP or a single open port. An authenticated tunnel carries traffic through the gate — and only an enrolled box can open one.

Fleet

Fleet management

Provision, monitor, and update every box from one place. Configuration and inventory live in one source of truth — the whole fleet, one pane of glass.

SSO

Single sign-on

One identity across every console. Access is SSO-gated end to end, so the control plane is never left open to the world.

Observability

Full observability

Metrics, logs, and alerts across the whole edge. NOC and SOC views show exactly what your gate is doing — and warn you before it becomes a problem.

Why self-hosted

The gate is yours — not rented from someone else's cloud.

01 Your infrastructure

Katula runs on servers you own. DNS, certificates, and keys stay inside your perimeter — nothing critical to your name depends on a third-party edge.

02 Defense in depth

Edge filtering, a web application firewall, authenticated tunnels, and SSO stack in front of every box. An attacker has to pass all of it — not one shared front door.

03 Nothing exposed by accident

Boxes carry no public IP; consoles are never on the open internet. What faces the world is only what you deliberately put through the gate.

Put your edge behind the wall.

Bring your domains and your boxes; Katula becomes the gate in front of them.