Souvera Private Access · Work in Progress
Your cloud practically does not exist for the public internet
Souvera Private Access makes your workspace invisible: no public IP, no open port, no attack surface. You connect exclusively through an encrypted VPN tunnel – with device authentication and state-of-the-art WireGuard technology.
The architecture
How Souvera Private Access works
The path from the internet to your private Souvera cloud leads through a single, hardened access point:
Souvera Access Gateway
Single, hardened access point
Private Souvera Cloud
Invisible to the public internet
The principle
A massively reduced attack surface
Every publicly reachable interface is a potential entry point. Private Access removes them – along with the most common attack vectors:
No public IP
Your workspace has no publicly reachable address. To attackers, your cloud simply does not exist.
No brute-force attacks
Without a public login screen, there is nothing for attackers to target with password attempts.
No external zero-day exploits
Vulnerabilities can only be exploited if services are reachable. With Private Access, they are not.
No port scanning
Your infrastructure appears in no scan – neither from automated botnets nor targeted attacks.
A single access point
Instead of dozens of open ports, there is exactly one hardened gateway – centrally monitored and secured.
Compliance bonus
The architecture demonstrably reduces the risk of unauthorized access – a strong argument for audits and customers.
The technology
Encrypted, authenticated, modern
Private Access relies on proven technologies with maximum security:
WireGuard VPN
WireGuard is considered the most modern VPN protocol: lean code, audited cryptography, minimal attack surface – and significantly faster than classic VPNs.
Device authentication
Only registered devices gain access. Unknown devices are rejected at the gateway – regardless of username and password.
End-to-end encryption
All traffic between your devices and your private cloud runs through an encrypted tunnel.
Sovereign infrastructure
Gateway and cloud are operated exclusively in German data centers – under German law, without US access.
Full functionality
Nextcloud, Collabora, Talk, Assistant and Mail remain fully usable – just no longer publicly reachable.
Future-proof
The architecture scales with you: new modules are automatically protected behind the same gateway.
FAQ
Frequently asked questions about Private Access
The most important answers about private access:
What exactly is Souvera Private Access?
Private Access removes your Souvera workspace from the public internet. Instead of a publicly reachable cloud, your devices connect through an encrypted VPN tunnel (WireGuard) to a hardened gateway – the only component reachable from outside.
How do my employees connect?
Via a VPN app with device authentication. After one-time setup, the device connects automatically – daily work remains unchanged for users.
Do mobile apps work with Private Access?
Yes. The connection is established at device level, so mobile apps, desktop clients and browsers all work – as if the workspace were locally reachable.
What is the impact on performance?
WireGuard is one of the fastest VPN protocols. In practice, the overhead is in the low single-digit percentage range – imperceptible for normal office work.
Is Private Access already available?
Private Access is in active development and is being implemented with WireGuard. You can already register for early access.
Who is Private Access particularly suitable for?
For companies with particularly sensitive data, law firms, public bodies and critical-infrastructure organizations – wherever a minimal attack surface is essential.
Interested in a cloud that does not exist for the internet?
Register for early access – we will notify you as soon as Private Access is available.