NAT Gateways. Reinvented.
Your NAT gateway moves terabytes every month and tells you almost nothing about them. Outbound replaces it with managed gateways in your own networks — on any cloud — full visibility into every outbound flow, static egress IPs, and a fixed monthly price instead of a metered bill.
See every byte. Source and destination.
Outbound is a drop-in replacement for your cloud provider's managed NAT gateway. Your workloads, subnets, and security groups don't change — only the default route of your private subnets is repointed at your new gateway.
The answers your cloud never gave you
Your cloud's built-in metrics tell you how many bytes went through your NAT gateway. They can't tell you which workload sent them or where they went. Outbound attributes every flow to the virtual machine, container task, or Kubernetes pod that made it — and to the destination domain, extracted from TLS SNI and HTTP Host headers.
- Which application is behind that traffic spike? Now you know.
- Domains, not just IPs — even for encrypted traffic, without TLS interception.
- Spot data exfiltration and unapproved destinations before they become incidents.
The NAT Gateway blind spot
Provider-managed NAT gateways move your traffic just fine. But they come with three problems — and built-in metrics can't fix any of them.
Zero visibility
Infrastructure-level metrics show bytes in and bytes out — and nothing else. Which workload generated the traffic? Where did it go? With a provider-managed NAT gateway, those questions have no answer.
Metered pricing
Per-GB processing charges, hourly charges per gateway, and data-transfer-out fees on top — whichever cloud you're on. A busy month means a bigger bill, with no way to see where it came from.
Security risks
Are you certain data only flows to approved destinations? Would you notice an exfiltration attack in progress? Without per-flow visibility, these questions remain open — indefinitely.
Egress management that actually works
Outbound gateways slot into your existing network topology — on any cloud — and light up everything that used to be dark. Managed by us, running in your account, auditable by you.
Every flow, attributed to a workload
Every outbound connection is attributed to the virtual machine, container task, or Kubernetes pod that made it. New workloads are registered within seconds of entering the running state — a discovery service registers VMs and container tasks, and a lightweight in-cluster sensor attributes egress to individual pods.
- Source, destination, protocol, ports, bytes, and packets — per flow
- eBPF sensor observes packets without ever touching them
- TCP, UDP, and ICMP tracked and attributed
Domains, not just IP addresses
Destination IPs are nearly meaningless behind CDNs and cloud load balancers. Outbound extracts the destination domain from the TLS SNI extension or the HTTP Host header — inspecting at most the first three packets of a connection, in memory, with no TLS interception and no payload ever stored or transmitted.
- Works for encrypted traffic — encrypted content stays encrypted and unread
- Only flow metadata leaves your account, over TLS
- See exactly which SaaS, API, and CDN your workloads depend on
Egress IPs your partners can trust
Each gateway keeps a stable static IP that is preserved across upgrades, resizes, and even instance replacements — Outbound aborts an operation rather than complete it with a different IP. Your partners' allowlists never break.
- Spare-IP pool guarantees continuity during replacements
- Your IP changes only if you offboard
- Multi-AZ layouts contain any failure to one zone's subnets
Capacity that fits your traffic
Gateway instance sizes aren't guesses. Recommendations are computed from two weeks of your actual NAT gateway traffic metrics before cutover — and gateways can be resized at any time without changing your egress IP.
- Sized from real traffic, per network
- Resize without an IP change or workload impact
- Host metrics for every gateway, visible in your dashboard
Your traffic never depends on us
The data plane is fully decoupled from Outbound's control plane. The forwarding path — route, forward, NAT — is plain Linux networking with no runtime dependency on our backend. If our platform were down, you'd see stale dashboards; your egress keeps flowing.
- Telemetry is fail-open: buffers full means lost visibility, never lost packets
- The sensor's only verdict is "pass" — no code path can drop or modify traffic
- Failed instances auto-recover via systemd or are replaced with the same IP
Scoped access. Full audit trail.
All control-plane access goes through a single scoped role you create in your own cloud account, with every permission enumerated and justified. Every action we take appears in your cloud's audit log — and you can revoke us at any time by deleting the role.
- Destructive permissions scoped to resources tagged
cloudphilos-gateway - Hardened minimal image, no SSH, no inbound internet access
- MFA, role-based access, and audit-logged administration in the dashboard
Managed NAT. But better.
| Capability | Cloud NAT gateway | Outbound gateway |
|---|---|---|
| Egress NAT for private subnets | Yes | Yes |
| Static egress IP | Yes | Yespreserved across upgrades |
| Per-application traffic attribution | No | Yes |
| Destination domain visibility (SNI / Host) | No | Yes |
| Runs in your account | Yes | Yesan instance you can see and audit |
| Pricing model | metered, $/GB | fixed, per month |
| Managed lifecycle | by your cloud provider | by us, via a scoped role in your account |
Pricing
One price per month, based on the traffic tier you choose. No per-GB metering, no surprise bills — and typically 50–60% below the equivalent provider-managed NAT gateway spend.
| Monthly traffic | Price / month | Provider NAT gateway (est.) | You save |
|---|---|---|---|
| Up to 20 TB | €500 | ~$1,060/mo | ~50% |
| Up to 50 TB | €1,000 | ~$2,500/mo | ~57% |
| Up to 100 TB | €1,850 | ~$4,900/mo | ~59% |
| Up to 250 TB | €4,000 | ~$12,100/mo | ~64% |
| Up to 500 TB | €7,500 | ~$24,100/mo | ~66% |
| Up to 1 PB | €13,500 | ~$48,100/mo | ~69% |
| Up to 5 PB | €50,000 | ~$240,100/mo | ~77% |
Not sure how much traffic you push? Ask our experts for a free egress assessment — we'll size it from your real NAT gateway metrics.
Connect. Scan. Cut over.
From a single template to full egress visibility — with you approving every step, and your traffic never at risk.
One template, fully scoped
Deploy a single infrastructure template that creates a scoped role in your own cloud account. Every permission we request is documented, with its purpose, in the docs.
- No agents on your workloads, no image changes, no security-group edits
- Revocable at any time by deleting the role
We map your networks, read-only
Outbound discovers your networks, subnets, route tables, and existing NAT gateways, then recommends a gateway size per network — computed from two weeks of your real traffic metrics, not a guess.
- Networks are managed one by one, and only after you enable them
- Unmanaged networks and public subnets are never touched
You approve. We flip the route.
Outbound launches the gateway, associates a static public IP, and repoints the default route of your private subnets. The old NAT gateway can then be removed — and flow data starts appearing in your dashboard, attributed to applications and destination domains.
- The only change in your network: one route, per private subnet
- Optional Kubernetes sensor adds pod-level attribution
Frequently asked questions
The questions every platform and security team asks before putting something new in the egress path.
Does Outbound add latency to my traffic?+
Can the sensor drop or block my traffic?+
Does Outbound see my packet payloads?+
Will my egress IP change?+
Do I need to change my workloads, images, or security groups?+
Can I choose which networks Outbound manages?+
Can I inspect the gateway instance?+
Does Outbound work across multiple clouds, accounts, and regions?+
Take back your egress
Talk to our team for a demo and a free egress assessment based on your real NAT gateway metrics.
Onboarding is guided end-to-end by our engineers — there's no self-service signup, and no risky big-bang migration. You approve every cutover, network by network.