Enterprise Gateway -- 4.0x Premium

One Gateway. 100 Accounts.
Zero Per-GB Fees.

Replace $14,000/month in AWS managed networking across your entire organization. Cross-account VPC peering mesh, multi-account Kubernetes, hub-spoke agent for remote VPCs, and Suricata IDS/IPS -- all at flat cost.

$0/GB
Data fees
100+
Accounts supported
3 / 8
Regions / VPCs for K8s
97%
Cost savings
The Enterprise Networking Bill at Scale
At 100 TB/month across a multi-account AWS organization. These are real AWS list prices -- no discounts applied.

AWS Managed Services at 100 TB/mo

NAT Gateway (data + hours)$4,533/mo
AWS Network Firewall (data + endpoints)$6,788/mo
Network Load Balancer$616/mo
Transit Gateway (attachments + data)$2,000/mo
Monthly total $13,937/mo
x 12 months =  $167,244/year

Camphor Enterprise flat rate, any traffic volume

EC2 instance (c6in.xlarge)$397/mo
Camphor Enterprise subscription$100/mo
Data transfer (NAT, peering, tunnels)$0/GB
Suricata IDS/IPS, VPC mesh, K8sIncluded
Monthly total $497/mo
x 12 months =  $5,964/year
$161,280
Saved per year at 100 TB/mo
97%
Total cost reduction
~$70,000
AWS cost at 500 TB/mo
$497
Camphor cost at 500 TB/mo
Camphor cost stays flat regardless of traffic volume. AWS costs grow linearly. The gap widens every month.
Everything Enterprise Teams Need
A single CloudFormation deploy unlocks the full feature set. Manage everything via Terraform provider or REST API.

Cross-Account Transit Manager

Auto-discovers VPCs across all your AWS accounts and regions. Maintains a live inventory with real-time state. Creates and manages VPC peering connections automatically -- no manual click-ops or scripting.

Enterprise
▶▶

Full-Mesh VPC Peering

Auto-creates full-mesh peering topology with route propagation across all enrolled VPCs. Free VPC peering replaces Transit Gateway at $0/GB vs $0.02/GB. Supports 100+ VPCs across 3+ regions with zero manual route management.

Enterprise
●—●

Hub-Spoke Agent (ECMP + VPN)

Lightweight agent in spoke VPCs establishes GRE tunnels to the hub gateway. ECMP load balancing across multiple gateways for active-active throughput. WireGuard VPN for remote clients and contractors requiring encrypted overlay.

Enterprise

Multi-Account Kubernetes

K8s control plane in hub VPC. Worker nodes in spoke VPCs across 3 accounts, 3 regions, 8 VPCs -- joined via Calico IPIP overlay over VPC peering. Camphor Karpenter provider handles cross-account node provisioning automatically.

Enterprise
🛡

Suricata IDS/IPS

30,000+ ET Open threat intelligence rules pre-cached in the AMI -- no download delay on boot. Syncs rules from your AWS Network Firewall policy with no $700/mo endpoint fees. Domain filtering, 5-tuple rules, and nftables stateless chain for high-throughput packet inspection.

Enterprise

AI Semantic Cache

Enterprise tier adds embedding-similarity caching on top of exact-match. Similar-but-not-identical prompts hit the cache -- achieving 50-70% hit rates across teams sharing the gateway. Cost attribution per team for chargeback. Prompt audit log with metadata only (content never stored).

AI Gateway

Terraform Provider

Complete IaC coverage via custom Terraform provider. Every feature -- peering groups, firewall rules, Kubernetes config, AI proxy routes, ACL policies -- managed declaratively. The same REST API powers both the dashboard and the provider, so nothing is hidden.

Enterprise
🔒

Compliance & Audit

All configuration lives in your SSM Parameter Store. All logs write to your CloudWatch -- never ours. IAM policy is least-privilege, scoped to the stack by tag and ARN. Full prompt audit log with metadata (model, tokens, source IP, latency) with no prompt content stored. Full policy at trust.html.

Enterprise
Centralized Control, Distributed Data Plane
The hub gateway owns the control plane -- transit manager, K8s control plane, Suricata, AI proxy. Spoke VPCs handle local traffic and join via peering or GRE tunnel. No cross-AZ tromboning, no managed service endpoints.
                        +---------------------------------+
                        |  Hub VPC (Camphor Gateway)        |
                        |                                 |
                        |  +---------------------------+    |
                        |  | Camphor EC2 (c6in.xlarge) |    |
                        |  |                           |    |
                        |  |  Transit Manager          |    |
                        |  |  K8s Control Plane        |    |
                        |  |  Suricata IDS/IPS         |    |
                        |  |  AI Proxy + Semantic Cache|    |
                        |  |  sNAT / dNAT (nftables)   |    |
                        |  +---------------------------+    |
                        |         |         |             |
                        +---------|---------|-------------+
                                  |         |
        +-------------------------+         +---------------------------+
        |  VPC peering / GRE tunnel          VPC peering / GRE tunnel |
        |                                                              |
+-------+------------------+                      +-------------------+-------+
|  Spoke VPC A (Account 1)  |                      |  Spoke VPC B (Account 2)  |
|                          |                      |                           |
|  K8s workers (Karpenter)  |                      |  K8s workers (Karpenter)  |
|  App pods (Calico IPIP)   |                      |  App pods (Calico IPIP)   |
|                          |                      |                           |
+--------------------------+                      +---------------------------+
                                  |
                  +---------------+------------------+
                  |  Spoke VPC C (Account 3, us-west-2)  |
                  |                                   |
                  |  Hub-Spoke Agent (GRE/WireGuard)    |
                  |  No VPC peering required             |
                  +-----------------------------------+
Hub control plane    Spoke VPCs    K8s overlay    Suricata IDS/IPS    Data plane (free)
Built for Enterprise Security
🔒
Least-Privilege IAM
Every action scoped to your stack by tag and ARN. No wildcard permissions.
🚫
No Telemetry
Zero data sent to Camphor. Traffic, prompts, and logs stay in your account.
📊
Logs in Your CloudWatch
All operational and audit logs write to your CloudWatch Logs -- not ours.
🔐
Open-Source Data Plane
nftables, Suricata, IPVS, WireGuard. Auditable, battle-tested open-source components.
Read the full Trust Center →

Replace your managed networking contracts.

One appliance, all accounts. Flat cost regardless of traffic volume. Deploy in 10 minutes from AWS Marketplace.