Identify
Office clients use the Edge as DNS, or the existing DNS forwards selected zones to it.
Selective egress for business networks
Keep ordinary internet traffic on its normal route. Send only the services that need another region through a gateway you choose — without installing EgressLane software on user devices.
Business release candidate · controlled pilot
A narrow lane, not a full-tunnel detour
PILOTDNS policy and virtual addresses identify managed destinations. TLS and QUIC remain end-to-end.
What changes — and what does not
EgressLane is software for customer-controlled networks. The Office Edge answers managed DNS names with virtual addresses, then routes those flows over an encrypted overlay to the selected gateway. Everything else stays on the office route.
How it works
Office clients use the Edge as DNS, or the existing DNS forwards selected zones to it.
A managed name receives a stable virtual address. Unmanaged answers pass through normally.
The Edge translates and policy-routes only the matching TCP or UDP flow into the encrypted tunnel.
The chosen gateway applies an allow-list and sends the flow to the public service from its region.
Product surfaces
DNS policy, virtual addresses, route health, multi-gateway policy and local operational metadata.
A regional gateway you deploy and operate on infrastructure you control.
An optional regional gateway operated by EgressLane, subject to availability.
Maintained domain groups that customers may install. Catalog updates never choose or overwrite a customer route policy.
Deployment choices
Run Office Edge and regional Gateway on customer-owned Ubuntu virtual machines, IP addresses and bandwidth.
Maximum infrastructure controlKeep Office Edge on-premises and combine self-built gateways with optional EgressLane Managed Gateways.
Flexible region coverageSecurity and privacy
EgressLane does not terminate TLS, install a trusted CA, or inspect encrypted application content. TLS and QUIC remain between the client and the destination service.
No payload, URL path, prompt or response logging
Limited operational and connection metadata with bounded retention
Private and reserved origin addresses are rejected
Gateway forwarding is restricted to synchronised destinations and allowed ports
Service Catalog
Install a maintained service group, review exact and suffix rules, then decide locally which route policy it uses. Parent and child domains follow most-specific-match precedence, and overlaps are shown before activation.
Policy stays at the customer EdgePricing
Pricing is based on concurrent managed flows and the number of Gateway connections. Contact us for a proposal tailored to your deployment.
Contact us
We will review the office network, target regions and deployment ownership before proposing a controlled pilot.
Controlled pilots are engineering-assisted and do not carry a general-availability SLA. Third-party regional access and service availability are not guaranteed. EgressLane Managed Gateway service is not offered for mainland China.