DOCUMENTATION

Operate HallVPN from first node to incident response.

Documentation follows the actual system boundaries and avoids steps for products or client applications that do not exist.

01

Getting started

Create an account, verify its email address, create the organization, enroll one Ubuntu 24.04 gateway, create a VPN user and device, then issue the first single-use profile.

02

Install a server

Create the intended server record first. Run the reviewed node installer with its short-lived one-use registration token, unique VPN subnet, management CIDR, and node-specific mutual-TLS identity. Verify the agent, helper, firewall, OpenVPN, and heartbeat before issuing access.

03

Create a VPN user

Use a VPN identity separate from SaaS accounts. Set expiry, device, concurrent-session, bandwidth, and server-access limits before sharing credentials through an approved channel.

04

Windows and macOS

Install a maintained OpenVPN-compatible client, download the profile once from the device record, import it locally, and enter the separate VPN username and password when prompted.

05

Linux

Install OpenVPN from the maintained distribution repository, keep the downloaded profile owner-readable only, and connect using the distribution's supported OpenVPN service or command-line workflow.

06

Android and iOS

Install a maintained OpenVPN-compatible client from the official platform store and import the device-specific profile. Do not copy one device's profile to another device.

07

Security model

Review tenant isolation, SaaS authentication, device PKI, node mutual TLS, signed commands, profile encryption, audit retention, and the documented residual risks before production use.

08

Troubleshooting

Check node heartbeat, server access, user and device state, credential expiry or revocation, capacity and concurrent-session limits, then correlate the request, audit, command, and session identifiers without exposing secrets in logs.

09

Customer API

Create a scoped API key only for the operations an integration needs. The raw key is displayed once; store it in a secret manager, set an expiry, monitor last use, and revoke it immediately if exposed.

READY TO EVALUATE?

Start with one controlled deployment.

Create an organization →