WireCanalby Qualiteg
shield_lock Relay servers in Japan · Verified with major AI services · Secure tunnel

No open ports.
Connect from anywhere.

Reach your local PC, in-house MCP servers and IoT devices securely from the outside.
WireCanal crosses NAT with a single outbound tunnel from inside your network — without opening a single inbound port. Its authenticated MCP tunnel mode lets you connect major AI services such as ChatGPT and Claude to your internal systems safely. It also supports HTTPS and TCP protocols (RDP, SSH, and more), so you can use it with confidence for a wide range of workloads.

Zero inbound ports Relay servers in Japan HTTP / TCP / MCP IoT devices Verified with major AI (Bestllam · Claude · ChatGPT · Grok) Custom domains*

* Publishing on your own custom domain is available on the Premium plan.

Connecting you safely! Canalun, the official WireCanal mascot
Two ways to use

Two ways to use it, one mechanism

WireCanal is both a secure tunnel and a gateway for AI / MCP integration. Both stand on the same mechanism: a single outbound tunnel.

Dashboard

Every canal, at a glance

Manage HTTPS, MCP, and TCP canals — all different kinds — in a single dashboard. Connection status, the AI services currently linked, and pause / resume are all one click away.

The WireCanal dashboard: a list of HTTPS, MCP, and TCP canals showing connection status, linked AI services (Claude, ChatGPT), and pause buttons
The actual dashboard. MCP canals show the linked AI services (such as Claude and ChatGPT) as badges.
Why WireCanal

Reach the outside world.
Keep your internal security intact.

You want to share localhost, or let outside SaaS and AI use your internal systems. WireCanal builds that pathway without opening a single inbound port.

The traditional choices

Open a hole, or carry the burden of VPNs and self-hosting

To let the outside reach your network, you used to open inbound ports on the router or stretch VPNs across sites. And if you wanted AI to use internal data, you also had to run your own GPU/LLM stack. Every option came with heavy setup and operations.

The WireCanal way

One outbound tunnel covers it all

An Agent placed inside your network opens a persistent tunnel outward, by itself. No inbound ports, no VPN — HTTP, TCP, and MCP all ride the same single tunnel. The allowed destinations, tools, and paths stay entirely in your hands. The relay infrastructure is operated on servers in Japan.

No more

Three things you no longer need

WireCanal removes the heavy prerequisites that used to be taken for granted when connecting to the outside.

shield

No inbound port openings

Not a single port to open. The Agent simply connects outward. No router configuration, no DMZ, no port-opening requests, no static IP. The entrance can be restricted to the fixed IPs of legitimate callers only.

lan

No VPN

No site-to-site VPNs, no leased lines. One authenticated tunnel passes only the endpoints you allow. It keeps working across dynamic IPs, multiple sites, and line changes — freeing you from building and operating VPNs.

memory

No on-prem LLM

No need to build and run your own GPU servers for AI integration. Connect leading cloud AI — GPT-5.5, Claude Opus 4.8, Gemini 3.1 Pro — directly to your internal systems.

How it works

Cross NAT with a single outbound tunnel

To callers, it looks like an ordinary remote URL or remote port. Behind that public entrance, requests travel through a persistent tunnel opened from your side, reach localhost or your internal systems, and the results come back along the same path. Because the Agent only makes outbound connections, no inbound hole is ever opened. HTTP, TCP (RDP, SSH, databases, and more), and MCP all ride this same single tunnel.

WireCanal architecture: users (browsers, smartphones, AI services such as Bestllam / claude.ai) → WireCanal (servers in Japan, Edge, 443/TLS, access protection) ⇐ a single outbound tunnel ⇐ Agent (fixed forwarding destination) → local web apps / RDP · SSH / in-house MCP servers
Security

Servers in Japan · defense in depth · fail-closed

WireCanal is designed around defense in depth centered on fixed forwarding destinations, with a fail-closed principle: when in doubt, shut it down. The keystones are the fixed forwarding destination and source-IP restriction that narrows the entrance.

Narrow the entrance

If your callers have fixed IPs, the entrance becomes a virtual leased line

WireCanal's public entrance (Edge) can be restricted to accept access only from the fixed IPs of legitimate callers. A public endpoint in form, effectively a leased line in practice. Caller token authentication adds a second layer on top. An entrance that is "public, yet as good as not public."

lock

Fixed forwarding destinations

The Agent never connects to destinations other than those you allow. We verify on every release, through regression tests, that the tunnel cannot become a pathway into your network.

key

Your credentials are never handed over

Entrance authentication is verified by WireCanal, and those credentials are never passed to the forwarding destination. Your internal systems can keep running locally without holding any authentication of their own.

receipt_long

Access logs

Incoming access is recorded per canal. You can trace who came, when, and from where — via the API or as CSV.

Use case

Ask your in-house sales data, in natural language

If you have an in-house MCP server that queries your sales database, one canal turns it into a remote MCP URL. Then just ask your AI.

WireCanal use case: AI services such as Bestllam and claude.ai query an in-house MCP server and sales database in natural language through the tunnel (exposing only the tools you allow)
Questions travel through the tunnel to your in-house sales data, and real data comes back. Leading AI answers with your company's own context.
Integrations

The infrastructure that connects the outside world with your local and internal systems

Clients and AI agents connect over HTTP, TCP, and MCP to localhost, internal web apps, databases, CRM, ERP, groupware, and in-house MCP servers. WireCanal provides the safe pathway that gets them there. The convenience of SaaS, with your internal security intact. In-house MCP servers can be registered as connectors in Bestllam, claude.ai, Claude Code, ChatGPT, and Gemini as they are.
Clients / SaaS / AI  →  Edge (servers in Japan)  ⟸ persistent outbound tunnel ⟸  Agent (local / in-house)  →  localhost / internal systems
Pricing

Start free. Pay only for what you need

Prices are in US dollars (USD); annual billing is about 2 months cheaper. Anyone can sign up for free. If you are located in Japan, you will be billed in Japanese yen at the yen prices shown on the Japanese page.

groups

Working as a team? Meet the Team Plan

200 canals shared across the team. $31.99 per seat per month, from 10 seats ($319.90/month for 10 people; $319 per seat per year with annual billing). Premium-grade features for every member. From sign-up to member invitations, everything is completed on the web.

See the Team Plan
FAQ

Frequently asked questions

Does it really work without opening any inbound ports?

Yes. The Agent simply opens an outbound tunnel from your local machine or internal network, so there is no need to open inbound ports on your router or firewall. Proxy-only environments are supported with a single configuration entry.

Can I limit which tools the AI sees?

Yes. Even if your in-house MCP server has 20 tools, only the few you allow are shown to the outside AI. The allowlist lives in your own configuration file, so it can never be widened from the cloud side.

I want to try it

The Free plan has no time limit and lets you try the core features: 1 canal, MCP integration, and access protection.

No open ports. Connect from anywhere.

Sign-up is free. No credit card required — create your first canal right now.

Sign up free and get started