LRO (Link for Remote Operations) gives you secure access to machines that sit behind NAT, CGNAT, or a firewall — without a VPN, without port forwarding, and without changing any network rules.
The agent dials OUT from inside the closed network and holds an encrypted link to the LRO core. You open tunnels to it from anywhere and manage every device from a single panel. No inbound ports are ever exposed.
WHY LRO
• No VPN, no port forwarding — the agent connects outbound, so closed networks and mobile/CGNAT links just work.
• End-to-end encrypted between agents — traffic is sealed agent-to-agent; the server relays it but cannot read it.
• Strong authentication — agents authenticate with the Noise XK handshake (X25519 / ChaCha20-Poly1305 / BLAKE2s).
• One panel for everything — see which agents are online, open and close tunnels, manage endpoints and access grants.
• Built for teams — organizations, per-endpoint permissions, and shared access.
HOW IT WORKS
1. Register this device as an agent.
2. Pick a role — client (open tunnels out), support (serve endpoints), or dual.
3. Open a tunnel to a remote endpoint and connect as if it were local.
The app runs a lightweight foreground service to keep the agent connected and show live throughput. Tunnel management can be protected behind biometric unlock.
LRO is usage-based: you bring your own account and traffic plan. See lro.link for details and pricing.
Reach devices behind NAT & firewalls. No VPN, no port forwarding. E2E encrypted.