Ghalixy Connect · Early access

Your server,
reachable anywhere.

Ghalixy Connect gives a Ghalixy server one address, like yourname.ghalixy.app, and one way in. Your server calls out to our relay, people reach it by name, and every connection stays encrypted from their browser to your server. No router settings, no fixed IP address, no VPN app.

A browser or the appasks for yourname.ghalixy.app
The relayrelay.ghalixy.app · reads the name only
Your serverin your office or home
Encrypted end to end: the connection is only unlocked on your server.

Sign in

Go to your server.

Every server set up with Connect is at its own name. Type it and your browser goes straight there, where you sign in with your passkey. This page sends nothing anywhere.

Forgot it? Ask whoever set up your server, or write to admin@ghalixy.com.

Where it stands

Early access, said plainly.

Works today

  • Websites a Ghalixy server hosts reach the internet through the relay. This page and ghalixy.com are served that way.
  • A server joins the relay with a one-time code, and can be cut off at once.
  • A domain is carried for a server only after its DNS shows it belongs to that server.

Coming next

  • Signing in to your server through Connect, once its sign-in has passed our internet security review.
  • Adding a phone or a laptop with an invite link (the Private level, below).
  • Your own domain for your server's own address.

How it works

Your server calls out. Visitors come in by name.

A home or an office usually can't take incoming connections, and shouldn't have to. So your server reaches out instead, and the relay is the fixed address the world can find.

  1. 01

    Your server calls out

    It keeps one encrypted connection open to relay.ghalixy.app, checked against the relay's own certificate. Nothing is opened on your router, and it works behind any internet connection.

    Outbound onlyNo port forwardingNo fixed IP
  2. 02

    Visitors ask for your name

    A browser asks for yourname.ghalixy.app. The relay looks only at the name being asked for, and hands the connection, still encrypted, to your server. It holds no key that could open it.

    Routed by nameNever decrypted
  3. 03

    Your server answers

    The encryption ends on your own server, with its own certificate from Let's Encrypt. Signing in is by passkey, and your server checks every request itself.

    Your certificatePasskeysYour rules

Addresses

One name, everything under it.

yourname.ghalixy.app

Your server. The name is chosen when it's installed, and it's yours alone.

*.yourname.ghalixy.app

Its parts, such as sign-in, all under your name.

yourbusiness.com

A website your server hosts, on your own domain: two DNS records (below).

relay.ghalixy.app

The relay itself. Servers connect to it; you'll never need to open it.

Kept for Ghalixy, never a server's name: relay, www, mail, api, app, admin, auth, get, connect, status, support, help, docs, blog, updates and downloads.

Security levels

You choose how open the door is.

Chosen for each server when it's installed, and changeable later. Every server and its data are its own at every level: nothing is shared between servers.

Private

Only devices you've added reach the sign-in page at all. Each gets its own certificate when it joins, and removing one shuts it out at once.

  • The default for offices
  • Arrives with invite links

Standard

Anyone who opens the address sees the sign-in page, and a passkey is the lock. Easiest when a family adds devices often.

  • The default for homes
  • Passkeys, never passwords alone

Closed

No internet door: the server is reached only through its own VPN, for a firm whose policy needs it.

  • WireGuard
  • Nothing through the relay

Your own domain

Put a website on your own domain.

A website your server hosts can live at your own domain, reached through the relay like everything else. Two records at your domain's DNS host, and we do the rest.

  1. 1

    Point it at the relay

    A CNAME to relay.ghalixy.app for a name like www, or for the bare domain an A record to the address relay.ghalixy.app has.

  2. 2

    Prove it's yours

    A TXT record, _ghalixy. in front of the name, holding your server's id. Your server's Websites page shows both records.

  3. 3

    Tell us

    We check both records and add the domain for your server. It gets its own certificate, and it's live.

example: yourbusiness.com's DNS
CNAMEwwwrelay.ghalixy.app
A@relay.ghalixy.app's address
TXT_ghalixygxc-… (your server's id)
TXT_ghalixy.wwwgxc-… (the same id)

Privacy

What the relay sees, and what it never does.

It sees

  • The name a visitor asked for.
  • The visitor's internet address, which it passes on to your server so your server can limit sign-in attempts.
  • How much traffic goes through. Each site is capped at 20 MB/s, so one busy site can't slow the others.

It never sees

  • Pages, passwords, files, mail or messages: the connection is encrypted from the browser to your server.
  • Your data at rest. Everything stays on your server; the relay stores nothing that passes through it.

Questions

Straight answers.

Do I need to change my router, or get a fixed IP address?

No. Your server only makes an outgoing connection, the kind every computer makes to visit a website.

What happens if the relay is down?

Your server keeps working: its mail, reminders and routines carry on, and nothing is lost. Only reaching it from a browser waits until the relay is back.

Where is the relay?

Today it runs on Ghalixy's own server in Ontario, Canada. It will move to a data centre in Canada as more servers join; your server's address doesn't change when it does.

Can Ghalixy read what goes through it?

The relay can't: it hands on encrypted connections and holds no key that opens them. Because ghalixy.app is our domain, a server that wants to depend on no one can use its own domain, or the Closed level.

Why ghalixy.app?

Browsers only ever open .app addresses over HTTPS, so nothing on them can be read or changed on the way.

I'd rather have a VPN.

Choose the Closed level: no internet door, only your server's own WireGuard VPN.

What's /relay?

This page. ghalixy.app/relay brings you here: the relay is the part of Connect that routes, and relay.ghalixy.app is its address for servers, not a page.

How do I get it?

Connect is in early access. Write to admin@ghalixy.com and we'll set your server up.

Get connected

Questions about Connect?

Write to us, in English or Arabic. You'll hear back from Karter, who builds it.