# Pangolin > Built for IT/OT, IoT, and engineering, provide your users with secure, identity-based remote access to applications and infrastructure. Easy to deploy and scale. Better than your existing VPN. ## Marketing - [Home](https://pangolin.net/): Built for IT/OT, IoT, and engineering, provide your users with secure, identity-based remote access to applications and infrastructure. Easy to deploy and scale. Better than your existing VPN. - [Product](https://pangolin.net/product): Organizations of every scale use Pangolin to unify and their remote access into one seamless, secure, and easy to deploy zero trust platform. - [Pricing](https://pangolin.net/pricing): Compare Pangolin cloud and self-hosted pricing. Free for personal use. Team plans from $4 per user/month, business from $9 per user/month. - [Contact](https://pangolin.net/contact): Contact Pangolin for sales, support, or enterprise inquiries. - [Partner With Us — MSP and Reseller Program](https://pangolin.net/partners): Unlock new opportunities with Pangolin partnerships. Resell, refer, and implement identity-based zero trust access with co-marketing, deal protection, and partner portal support. - [Register a Deal — Partner Program](https://pangolin.net/partners/register-deal): Register your Pangolin sales opportunity to protect your deal and receive partner support through the sales cycle. ## News & Articles - [News & Articles](https://pangolin.net/news): Stay up to date with the latest product updates, guides, and insights in the zero trust remote access space by reading Pangolin's articles. - [Pangolin 1.20: Resource Launcher & Global Command Palette](https://pangolin.net/news/1-20-release): Pangolin 1.20 rebuilds the Resource Launcher with saved views, grouping, and filtering, and adds a global command palette for administrators. - [RDP in the Browser: Remote Desktop Without Installing a Client](https://pangolin.net/news/browser-based-rdp-remote-access): Access Windows desktops through a full RDP session rendered in the browser, with clipboard, file transfer, and standard RDP features. Users need only a web browser on their side. - [SSH in the Browser: Web-Based Terminal Access Without a Client](https://pangolin.net/news/browser-based-ssh-remote-access): Run a full SSH session in any modern browser. Users connect with a URL and authentication, without installing an SSH client, VPN, or desktop app. - [VNC in the Browser: Remote Display Access Without a Viewer](https://pangolin.net/news/browser-based-vnc-remote-access): View and control remote displays through a VNC session in your browser. Users connect with a URL instead of installing a standalone VNC viewer or VPN client. - [How to SSH with Pangolin: Browser Access and Private CLI](https://pangolin.net/news/how-to-ssh-with-pangolin): SSH to private servers through Pangolin with a browser terminal or private CLI over a scoped tunnel. Automatic user provisioning via PAM, without opening port 22 or distributing static keys. - [Pangolin 1.19: Browser Remote Access — SSH, RDP, VNC & More](https://pangolin.net/news/1-19-release): Pangolin 1.19 adds browser-based remote access with SSH, RDP, and VNC in the browser, a simpler Pangolin SSH mode, automatic site updates, labels, and resource policies. - [What Are MCP Tunnels? Secure Private MCP Servers Explained](https://pangolin.net/news/what-are-mcp-tunnels): Learn what MCP tunnels are, how they connect AI agents to private Model Context Protocol servers over outbound-only connections, and why they matter for enterprise security. - [5 Remote Access Policy Examples for Secure Teams](https://pangolin.net/news/remote-access-policy-examples): Use these remote access policy examples to scope access for admins, contractors, OT systems, internal web apps, and emergency workflows. - [Secure Remote Access: Enterprise ZTNA Implementation Guide](https://pangolin.net/news/secure-remote-access): Learn how to modernize secure remote access with identity-driven ZTNA, resource-level policy, and reduced public exposure. - [Peer-to-Peer Alternative to Cloudflare Tunnels with Edge TLS Termination](https://pangolin.net/news/building-a-peer-to-edge-peer-reverse-proxy): How Pangolin built a peer-to-edge reverse proxy that keeps TLS termination and private application traffic on infrastructure you control. - [GitOps for Pangolin Blueprints: Access Control via CI/CD](https://pangolin.net/news/gitops-pangolin-blueprints-ci-cd): Manage Pangolin Blueprints with GitOps using declarative YAML, pull request review, and GitHub Actions automation. - [Templated Provisioning and Rollouts for the Edge](https://pangolin.net/news/templated-provisioning-and-rollouts-for-the-edge): Automate edge device rollouts with Pangolin provisioning keys, declarative blueprints, and golden-image workflows. - [Pangolin 1.18: HTTPS Private Resources, Multi-Site, & Alerts](https://pangolin.net/news/1-18-release): Pangolin 1.18 adds HTTPS private resources, multi-site routing, uptime tracking, alert rules, and wildcard resources. - [Pangolin Remote Nodes: Cloud Control Plane & Failover](https://pangolin.net/news/pangolin-remote-nodes-guide): Pangolin remote nodes let you keep the traffic edge on infrastructure you control while Pangolin Cloud handles DNS, certificates, health checks, and failover. - [Ignition Remote Access Without Open Ports](https://pangolin.net/news/ignition-remote-access-without-open-ports): Keep Ignition private while providing authenticated browser access and narrow engineering connectivity without open ports. - [IoT Provisioning at Scale with Golden Edge Images](https://pangolin.net/news/iot-device-provisioning-at-scale-with-golden-images-for-edge-fleets): Provision IoT edge fleets with golden images, first-boot assignment, Pangolin sites, and declarative blueprints. - [Remote PLC/SCADA Access Without Open Ports](https://pangolin.net/news/remote-plc-scada-access-without-open-ports): Secure remote PLC and SCADA access by keeping interfaces private, closing open ports, and scoping engineering access. - [Remote Access for Tridium Niagara Without Open Ports](https://pangolin.net/news/remote-access-for-tridium-niagara-without-open-ports): Provide Tridium Niagara remote access with authenticated browser access and narrow engineering paths without open ports. - [Pangolin 1.17 - Full RBAC, Site Provisioning Keys, Log Streaming](https://pangolin.net/news/1-17-release): Pangolin 1.17 improves roles, identity provider mapping, site provisioning, connection logs, and log streaming. - [What is an Identity-Aware Proxy (IAP)?](https://pangolin.net/news/what-is-an-identity-aware-proxy): Learn what an identity-aware proxy is, how it compares to VPNs and ZTNA, and how Pangolin protects private web apps. - [Modernizing Enterprise SSH Access](https://pangolin.net/news/modernizing-enterprise-ssh-access): Modernize enterprise SSH with identity-driven access, short-lived credentials, and private connectivity instead of static keys. - [How Does ZTNA Work? Unlocking the Secrets of Enhanced Security](https://pangolin.net/news/how-ztna-works): Learn how ZTNA works, why it differs from VPN-based remote access, and how identity, device posture, and policy combine to protect private applications. - [Pangolin for MSPs: Secure Remote Access Per Customer](https://pangolin.net/news/pangolin-for-msps): Pangolin helps MSPs replace VPN sprawl with a multi-tenant, identity-based remote access platform built to scale across client environments. - [What Is a Tunneled Reverse Proxy? Architecture & Uses](https://pangolin.net/news/tunneled-reverse-proxy): Learn how tunneled reverse proxies publish private apps through outbound tunnels without broad VPN access or exposed networks. - [Comparison - Pangolin vs. WireGuard](https://pangolin.net/news/pangolin-vs-wireguard): Compare WireGuard tunnels with Pangolin’s full remote access platform for identity, policy, automation, and browser access. - [Comparison - Pangolin vs. Teleport](https://pangolin.net/news/pangolin-vs-teleport): Compare Pangolin and Teleport across workforce access, engineering sessions, protocol coverage, and zero trust architecture. - [How Pangolin Works](https://pangolin.net/news/how-pangolin-works): Learn how Pangolin connects sites, resources, identity, and policy to provide zero trust remote access without opening ports. - [Comparison - Pangolin vs. Zscaler](https://pangolin.net/news/pangolin-v-zscaler): How a self-hostable open-source access platform and an enterprise cloud security suite differ in architecture, traffic routing, deployment, and fit. - [Pangolin 1.16 - Certificate Based SSH](https://pangolin.net/news/1-16-0-release): Pangolin 1.16 adds certificate-based SSH, short-lived credentials, and just-in-time user provisioning for private infrastructure. - [How Pangolin Punches Through NATs and Firewalls](https://pangolin.net/news/nat-holepunching): A deep dive into how Pangolin establishes direct peer-to-peer connections through NAT devices and firewalls without opening ports. - [Comparison - Pangolin vs. Cloudflare One](https://pangolin.net/news/pangolin-v-cloudflare): How an open-source, self-hostable remote access platform compares to Cloudflare One (ZTNA, WARP, Access, and Tunnel). - [Comparison - Pangolin vs. Pomerium](https://pangolin.net/news/pangolin-v-pomerium): How an identity-based remote access platform and an identity-aware reverse proxy differ in scope, layer, and deployment. - [Comparison - Twingate vs. NetBird](https://pangolin.net/news/twingate-v-netbird): How Twingate and NetBird are solving different problems in modern remote access. - [Comparison - Twingate vs. Tailscale](https://pangolin.net/news/twingate-v-tailscale): How Twingate and Tailscale are solving different problems in modern remote access. - [Pangolin SSO with Google, Microsoft & OAuth2/OIDC](https://pangolin.net/news/idp-support): You can now log in to Pangolin with your existing identity provider - including Google, Microsoft, and any OAuth2/OIDC compatible IdP. - [Comparison - Pangolin vs. Twingate](https://pangolin.net/news/pangolin-v-twingate): How two identity-based remote access platforms differ in architecture, web access, and deployment options. - [Comparison - Pangolin vs. NetBird](https://pangolin.net/news/pangolin-v-netbird): A comparison of two WireGuard-powered remote access solutions and their differences in architecture, permissions, and use cases. - [Comparison - Pangolin vs. Tailscale](https://pangolin.net/news/pangolin-v-tailscale): How two WireGuard-based tools for remote access differ in design, access control, and fit. - [Pangolin 1.15: Mobile Apps, Device Approvals & Posture](https://pangolin.net/news/1-15-0-release): Pangolin 1.15 adds iOS and Android apps, device approvals, posture tracking, fingerprinting, and stability improvements. - [Declarative Configuration with YAML and Docker Labels](https://pangolin.net/news/blueprints): Pangolin Blueprints let you manage resources as code with YAML or Docker labels, making configurations automated, consistent, and scalable. - [Pangolin Cloud is Now Available in Europe](https://pangolin.net/news/pangolin-cloud-eu): We've deployed dedicated points of presence in the EU for our European cloud users. - [Health Checks and Load Balancing on Targets for Resources](https://pangolin.net/news/health-check): Configure Pangolin health checks and target-level load balancing to improve resource availability. - [How to Geo-block with Pangolin](https://pangolin.net/news/how-to-geoblock): Learn how to use Pangolin rules to geo-block resources and limit access by country or region. - [Self-hosted Remote Nodes - What Are They, and Why Do They Exist?](https://pangolin.net/news/manage-self-hosted): Learn about our new remote node self-hosted offering, which combines the best of self-hosted and cloud solutions. ## Downloads - [Downloads](https://pangolin.net/downloads): Download Pangolin clients for desktop and mobile platforms. - [macOS](https://pangolin.net/downloads/mac): Requires macOS Sonoma 14.0 or later. - [Windows](https://pangolin.net/downloads/windows): Requires Windows 10 or later. - [Linux](https://pangolin.net/downloads/linux): Available for most Linux distributions. - [iOS](https://pangolin.net/downloads/ios): Requires iOS 17.0 or later. - [Android](https://pangolin.net/downloads/android): Requires Android 7.0 or later. ## Legal - [Privacy policy](https://pangolin.net/privacy): Fossorial Inc. privacy policy for Pangolin websites and services. - [Terms of service](https://pangolin.net/tos): Fossorial Inc. terms of service for Pangolin. - [Data processing addendum](https://pangolin.net/dpa): Fossorial Inc. data processing addendum for Pangolin. GDPR and privacy obligations when Fossorial processes personal data on behalf of customers. - [Service level agreement](https://pangolin.net/sla): Fossorial Inc. service level agreement for Pangolin Enterprise services. - [Fossorial commercial license](https://pangolin.net/fcl): Fossorial Inc. commercial license for Pangolin software. ## External resources - [Documentation](https://docs.pangolin.net/): Pangolin product documentation and self-hosting guides. - [Sign up](https://app.pangolin.net/auth/signup): Create a Pangolin Cloud account. - [Status](https://status.pangolin.net): Pangolin service status and uptime. - [Trust center](https://trust.pangolin.net): Security, compliance, and trust documentation. - [GitHub](https://github.com/fosrl/pangolin): Open-source Pangolin repository. ## Optional - [Full documentation](https://pangolin.net/llms-full.txt): Complete inline content for all pages in one file. - [Sitemap](https://pangolin.net/sitemap.xml): XML sitemap of all indexable pages. - [Robots](https://pangolin.net/robots.txt): Crawler directives.