NAT Gateways. Reinvented.

Your NAT gateway moves terabytes every month and tells you almost nothing about them. Outbound replaces it with managed gateways in your own networks — on any cloud — full visibility into every outbound flow, static egress IPs, and a fixed monthly price instead of a metered bill.

See every byte. Source and destination.

Outbound is a drop-in replacement for your cloud provider's managed NAT gateway. Your workloads, subnets, and security groups don't change — only the default route of your private subnets is repointed at your new gateway.

AWS Azure Google Cloud Private Cloud
TOP FLOWS · TODAY
checkout-apiapi.stripe.com412 GB
analytics-etls3.amazonaws.com307 GB
ml-inferencehuggingface.co128 GB
backup-agentstorage.googleapis.com96 GB
EGRESS SPEND · THIS MONTH
€1,000 ▼ 61% vs NAT Gateway
Improve your egress visibility

The answers your cloud never gave you

Your cloud's built-in metrics tell you how many bytes went through your NAT gateway. They can't tell you which workload sent them or where they went. Outbound attributes every flow to the virtual machine, container task, or Kubernetes pod that made it — and to the destination domain, extracted from TLS SNI and HTTP Host headers.

  • Which application is behind that traffic spike? Now you know.
  • Domains, not just IPs — even for encrypted traffic, without TLS interception.
  • Spot data exfiltration and unapproved destinations before they become incidents.
Explore Features
100%
Flows attributed
−60%
Egress spend
0
Workload changes
Turn your egress into an open book

The NAT Gateway blind spot

Provider-managed NAT gateways move your traffic just fine. But they come with three problems — and built-in metrics can't fix any of them.

Zero visibility

0%
of flows attributed to a source

Infrastructure-level metrics show bytes in and bytes out — and nothing else. Which workload generated the traffic? Where did it go? With a provider-managed NAT gateway, those questions have no answer.

Metered pricing

$/GB
every gigabyte, metered

Per-GB processing charges, hourly charges per gateway, and data-transfer-out fees on top — whichever cloud you're on. A busy month means a bigger bill, with no way to see where it came from.

Security risks

?
is your data in the wrong hands

Are you certain data only flows to approved destinations? Would you notice an exfiltration attack in progress? Without per-flow visibility, these questions remain open — indefinitely.

Improve your security & cost posture

Egress management that actually works

Outbound gateways slot into your existing network topology — on any cloud — and light up everything that used to be dark. Managed by us, running in your account, auditable by you.

Every flow, attributed to a workload

Every outbound connection is attributed to the virtual machine, container task, or Kubernetes pod that made it. New workloads are registered within seconds of entering the running state — a discovery service registers VMs and container tasks, and a lightweight in-cluster sensor attributes egress to individual pods.

  • Source, destination, protocol, ports, bytes, and packets — per flow
  • eBPF sensor observes packets without ever touching them
  • TCP, UDP, and ICMP tracked and attributed

Domains, not just IP addresses

Destination IPs are nearly meaningless behind CDNs and cloud load balancers. Outbound extracts the destination domain from the TLS SNI extension or the HTTP Host header — inspecting at most the first three packets of a connection, in memory, with no TLS interception and no payload ever stored or transmitted.

  • Works for encrypted traffic — encrypted content stays encrypted and unread
  • Only flow metadata leaves your account, over TLS
  • See exactly which SaaS, API, and CDN your workloads depend on

Egress IPs your partners can trust

Each gateway keeps a stable static IP that is preserved across upgrades, resizes, and even instance replacements — Outbound aborts an operation rather than complete it with a different IP. Your partners' allowlists never break.

  • Spare-IP pool guarantees continuity during replacements
  • Your IP changes only if you offboard
  • Multi-AZ layouts contain any failure to one zone's subnets

Capacity that fits your traffic

Gateway instance sizes aren't guesses. Recommendations are computed from two weeks of your actual NAT gateway traffic metrics before cutover — and gateways can be resized at any time without changing your egress IP.

  • Sized from real traffic, per network
  • Resize without an IP change or workload impact
  • Host metrics for every gateway, visible in your dashboard

Your traffic never depends on us

The data plane is fully decoupled from Outbound's control plane. The forwarding path — route, forward, NAT — is plain Linux networking with no runtime dependency on our backend. If our platform were down, you'd see stale dashboards; your egress keeps flowing.

  • Telemetry is fail-open: buffers full means lost visibility, never lost packets
  • The sensor's only verdict is "pass" — no code path can drop or modify traffic
  • Failed instances auto-recover via systemd or are replaced with the same IP

Scoped access. Full audit trail.

All control-plane access goes through a single scoped role you create in your own cloud account, with every permission enumerated and justified. Every action we take appears in your cloud's audit log — and you can revoke us at any time by deleting the role.

  • Destructive permissions scoped to resources tagged cloudphilos-gateway
  • Hardened minimal image, no SSH, no inbound internet access
  • MFA, role-based access, and audit-logged administration in the dashboard

Managed NAT. But better.

Outbound gateway compared with a cloud provider's managed NAT gateway, capability by capability.
CapabilityCloud NAT gatewayOutbound gateway
Egress NAT for private subnetsYesYes
Static egress IPYesYespreserved across upgrades
Per-application traffic attributionNoYes
Destination domain visibility (SNI / Host)NoYes
Runs in your accountYesYesan instance you can see and audit
Pricing modelmetered, $/GBfixed, per month
Managed lifecycleby your cloud providerby us, via a scoped role in your account
Fixed pricing built for predictable egress

Pricing

One price per month, based on the traffic tier you choose. No per-GB metering, no surprise bills — and typically 50–60% below the equivalent provider-managed NAT gateway spend.

Outbound's fixed monthly price per traffic tier, against the estimated cost of an equivalent provider-managed NAT gateway.
Monthly trafficPrice / monthProvider NAT gateway (est.)You save
Up to 20 TB€500~$1,060/mo~50%
Up to 50 TB€1,000~$2,500/mo~57%
Up to 100 TB€1,850~$4,900/mo~59%
Up to 250 TB€4,000~$12,100/mo~64%
Up to 500 TB€7,500~$24,100/mo~66%
Up to 1 PB€13,500~$48,100/mo~69%
Up to 5 PB€50,000~$240,100/mo~77%
Contact Sales

Not sure how much traffic you push? Ask our experts for a free egress assessment — we'll size it from your real NAT gateway metrics.

The gateway is a virtual machine in your cloud account — visible in your console, your audit logs, your flow logs, and subject to every security control you already run. There's no traffic hair-pinning through a third party: your data takes the same path it always did, just through a gateway that finally tells you what's in it.
Outbound is built so that the worst case is losing visibility, never losing traffic. The eBPF sensor's only verdict is "pass" — it has no code path to drop or modify packets. Telemetry buffers fail open. The forwarding path has zero runtime dependency on our backend. A control-plane outage means stale dashboards, not a broken internet connection.
Teams that manage their networks with Terraform get first-class guidance: after cutover, Outbound owns your private subnets' default routes and gateway IPs, and our docs include copy-paste state migrations so terraform apply never fights the platform. Multi-account and multi-region rollouts are one template away.
Onboarding without the drama

Connect. Scan. Cut over.

From a single template to full egress visibility — with you approving every step, and your traffic never at risk.

Step 1 — Connect

One template, fully scoped

Deploy a single infrastructure template that creates a scoped role in your own cloud account. Every permission we request is documented, with its purpose, in the docs.

  • No agents on your workloads, no image changes, no security-group edits
  • Revocable at any time by deleting the role
Step 2 — Scan

We map your networks, read-only

Outbound discovers your networks, subnets, route tables, and existing NAT gateways, then recommends a gateway size per network — computed from two weeks of your real traffic metrics, not a guess.

  • Networks are managed one by one, and only after you enable them
  • Unmanaged networks and public subnets are never touched
Step 3 — Cut over

You approve. We flip the route.

Outbound launches the gateway, associates a static public IP, and repoints the default route of your private subnets. The old NAT gateway can then be removed — and flow data starts appearing in your dashboard, attributed to applications and destination domains.

  • The only change in your network: one route, per private subnet
  • Optional Kubernetes sensor adds pod-level attribution

Frequently asked questions

The questions every platform and security team asks before putting something new in the egress path.

Does Outbound add latency to my traffic?+
Negligibly. The gateway is a straight Linux forwarding path (route → forward → NAT) in the same network as your workloads, and the eBPF sensor observes packets without touching them. You're replacing one NAT hop with another — not adding one.
Can the sensor drop or block my traffic?+
No, by construction. The XDP program's only verdict is "pass"; it has no code path to drop, modify, or redirect a packet. If telemetry buffers fill up, Outbound loses visibility data — never your packets.
Does Outbound see my packet payloads?+
The sensor inspects at most the first 3 packets of each new TCP connection, solely to extract the destination domain from the TLS SNI or HTTP Host header. There is no TLS interception — encrypted content stays encrypted and unread. Payload bytes are never stored or transmitted; only flow metadata (IPs, ports, domain, byte/packet counts) leaves your account.
Will my egress IP change?+
Not during normal operation. Gateway upgrades, resizes, and replacements all preserve the static IP.
Do I need to change my workloads, images, or security groups?+
No. Workloads keep their subnets, security groups, and configuration. The only change in your network is the private subnets' default route.
Can I choose which networks Outbound manages?+
Yes. Networks are managed one by one, and only after you enable them — the initial scan is read-only. Public subnets' routing is never touched, and unmanaged networks are never modified.
Can I inspect the gateway instance?+
Yes — it's a virtual machine in your account, visible in your console, your audit logs, and your flow logs. There's no SSH and no inbound access from the internet.
Does Outbound work across multiple clouds, accounts, and regions?+
Yes. Deploy the onboarding template per region and register each account in the dashboard — everything comes together in one view. Gateways and their telemetry are managed per region.
Assume or know?

Take back your egress

Talk to our team for a demo and a free egress assessment based on your real NAT gateway metrics.

Onboarding is guided end-to-end by our engineers — there's no self-service signup, and no risky big-bang migration. You approve every cutover, network by network.