A SecuryTik product · self-hosted

Every branch. Every remote user.
One routed network.

SecuryTik Overlay & VPN Automation

Sova turns one VPS into the hub of your company network. MikroTik branches — even behind NAT — dial in over WireGuard, learn each other's routes with OSPF and fall back to L2TP/IPsec on their own. Remote employees connect the same way. No NAT inside the fleet, no address planning by hand, no router config written from scratch.

Ubuntu 24.04 / 26.04 · RouterOS 7 branches · WireGuard & L2TP/IPsec · Free for 2 sites
Install

One line. One VPS. One network.

Run it as root on a fresh Ubuntu VPS with a public IP. The installer sets up the hub (WireGuard, L2TP/IPsec, FRR, DNS, nginx and the panel), then open the server in a browser and sign in as admin with the password the installer prints at the end.

Ubuntu VPS

Ubuntu 24.04 or 26.04 with a public IP — run as root.

install.sh — bash
curl -fsSL https://sova.securytik.com/install.sh | sudo bash
How it works

A hub, spokes, and routes that find themselves.

1 · Add a site

Name the branch. Sova gives it its own block, 10.N.0.0/16, its networks and its tunnel addresses — derived, never typed.

2 · Paste the script

Copy the generated RouterOS 7 script into the branch terminal. It checks first, never touches the WAN or default route, and can be re-run safely.

3 · It routes

The branch dials the hub over WireGuard, OSPF shares the routes, and L2TP/IPsec takes over within about 20 seconds if WireGuard is blocked.

What you get

Everything a multi-branch network needs

Sova · Dashboard
Sova dashboard

See every feature

Free for two sites. Upgrade per install.

Plans by sites and remote users, monthly or yearly. Every paid plan starts with a free month.