Distributed, not exposed
Meshive runs your workload on machines it does not own. Every consequence of that — the network between nodes, the boundary around a pod, the disk under your data — is closed on purpose rather than assumed away.

Five boundaries, closed deliberately
- 01
Nothing between nodes travels in the clear
Every link between cluster nodes runs over a WireGuard VPN, and the control plane between a host agent and Meshive is HTTPS. Client traffic terminates at TLS 1.3.
- 02
A pod cannot see the machine under it
Pods get their own namespace with the permissions they need and nothing more. A client renting a pod cannot read the host filesystem, other tenants, or anything outside its own sandbox.
- 03
The encryption key is kept away from the disk
Any volume can be encrypted at creation, at no charge, and the key is never stored on the host machine. A powered-off or locked volume exposes nothing, even with the drive in hand.
- 04
Four open ports on a host, not four hundred
22 for managed host SSH, 2222 for the pod SSH proxy, 443 for the agent, 41641/udp for the VPN. Everything else is firewalled at the agent, SSH and IPMI credentials rotate monthly, and repeated failed logins block the source automatically.
- 05
Hardware is re-verified, not trusted once
A changed GPU, CPU or motherboard — or a boot that followed an unclean shutdown — automatically triggers a stress test before the machine takes work again, and it is unlisted while that runs.
Layer by layer
| Layer | Protection |
|---|---|
| Client → Meshive | HTTPS, TLS 1.3 |
| Node ↔ node | WireGuard VPN |
| Host agent → control plane | HTTPS on 443 |
| Pod → host OS | Namespaced isolation, no host access |
| Volume at rest | Opt-in encryption, key never on the host |
| Compliance | SOC 2 Type II in progress |
What this does not claim
- Does encryption at rest protect a running pod?
- No, and it is worth being precise. While a pod is actively using a volume the data is necessarily unlocked for that pod. At-rest encryption covers the volume's disk footprint — it is not a substitute for securing what you run inside your own pod.
- What does encryption cost in throughput?
- Roughly 3–5%. Unnoticeable for most workloads; worth weighing for maximum-throughput scratch space.
- Is Meshive SOC 2 certified?
- Not yet. SOC 2 Type II is in progress, and we would rather say that plainly than imply a certificate that does not exist. The architecture below it was built security-first from the start.

Pick a card and start the pod
Sign up, choose the GPU, and the pod is yours in under two minutes. It bills by the hour and stops when you stop it.
Already a user? Invite friends and earn 15% of their first top-up.
