🔐

Corporate gateway on Xray and nginx for an IT team

for an IT company: work tools available again, on its own servers

CompletedNDA
100%
of the team's tools accessible again
0 leaks
corporate data stays inside the perimeter
1 click
to connect to the secure gateway, for any employee

The task

Because of regional restrictions, an entire IT company's team lost access to Canva, Notion, Jira and AI tools at once. Work stopped and deadlines were burning. Public workarounds risked leaking corporate data and violated the company's security policy.

The solution

We deployed a sovereign corporate routing infrastructure on the company's own servers. Routing means directing traffic to the right resources by set rules. Sovereign here means the servers and data stay under the company's control, with no intermediaries.

  • End-to-end traffic encryption.
  • Role-based access control for employees.
  • A single entry point: stable, transparent one-click access to all work resources.

How it works

A single entry point for employees

An employee connects to the corporate gateway, and work traffic then flows through it to the required services. The gateway runs on the company's Linux servers; the stack includes Xray (a proxy-protocol core) and nginx (a web server at the entrance). Access rights depend on the employee's role.

Results

  • The team's tools are accessible again.
  • Corporate data stays inside the company's perimeter.
  • Connecting takes an employee one click.

Technologies and why

  • Self-hosted — everything on the company's servers, no third-party cloud.
  • Linux — the server foundation.
  • Xray — traffic routing and encryption.
  • nginx — the gateway's entry point.

Status

Completed. The client asked us not to disclose the company name. Other details about the client are not disclosed.

Questions about this project

What problem does the corporate gateway solve?
Because of regional restrictions the team lost access to Canva, Notion, Jira and AI tools. The gateway restores access to all work resources through a single entry point.
Where does the gateway run and who owns the data?
The infrastructure is deployed on the company's own servers. Corporate data stays inside the perimeter instead of passing through public services.
How is employee traffic protected?
End-to-end traffic encryption and role-based access control are configured.
Is it hard for an employee to connect to the gateway?
No. Each employee gets a single entry point and connects with one click.
Why not use public services for bypassing restrictions?
Public workarounds risked leaking corporate data and violated the company's security policy.

Need something similar?

Tell us about the task — we'll show how we solved it and estimate the scope.