21PacketsContact Us
Technical FAQ

Technical answers for evaluating the 21Packets network fabric.

Understand how Endlets, the Elastic Network Fabric, adaptive transport, and quantum-safe controls fit together—then use the implementation and procurement answers to plan a practical architecture review.

Available in 247+ Countries
450+ POPs

The operating model

A software fabric built around continuously governed endpoints.

21Packets places lightweight software endpoints—Endlets—where connectivity, services, and protected workloads need to operate. Each participating Endlet receives a cryptographic identity, must satisfy machine-validation and authorization policy, and then joins policy-approved fabric paths.

01

Deploy

Place Endlets where connectivity and services need to operate.

02

Validate

Confirm cryptographic identity, authorization, and machine state.

03

Admit

Release fabric relationships, policy, and authority only after approval.

04

Adapt

Preserve protected paths as underlay conditions change.

Proprietary concepts

Start with the terms that define the architecture.

These concepts describe where control lives, how participation is governed, and how protected paths remain useful as conditions change.

What is an Endlet?

An Endlet is a lightweight 21Packets software endpoint. It can provide routing, connectivity, or an approved service function while remaining governed by cryptographic identity, machine validation, policy, and lifecycle controls. Endlets can be deployed as virtual machines, containers, Kubernetes workloads, bare-metal processes, or approved edge deployments.

What is the difference between a Route Endlet and a Service Endlet?

A Route Endlet participates in the fabric’s logical connectivity and protected path relationships. A Service Endlet activates an approved function—such as segmentation, firewalling, DNS, proxy, telemetry, controlled access, confidential execution, or edge intelligence—close to the systems and data it serves.

What is the Elastic Network Fabric?

The Elastic Network Fabric is the software fabric formed by authorized Endlets across sites, data centers, clouds, workloads, provider edges, and operational environments. “Elastic” describes the ability to place and scale software functions across approved infrastructure while preserving one identity, policy, and lifecycle model. It does not require one carrier, cloud, or proprietary appliance stack.

What is EdgeControl?

EdgeControl is the lifecycle and control plane for Endlets. It coordinates onboarding, identity, machine validation, admission, policy, re-attestation, replacement, retirement, and revocation so network participation remains an ongoing governed state rather than a one-time enrollment event.

How do Slip-Routing, Route Ledger, DEFT, and NOAN work together?

Route Ledger maintains path awareness. Slip-Routing uses current conditions and policy to move protected traffic toward viable routes. DEFT provides the protected fabric tunnel relationship during path transitions. NOAN contributes optimization context. Together, they are designed to preserve logical service relationships while underlay performance, congestion, routes, or site conditions change.

Cryptographic architecture

Post-quantum protection extends beyond the tunnel.

21Packets applies a crypto-agile model across identity, admission, authority, sessions, policy, and protected transport.

What does “quantum-safe” mean in the 21Packets architecture?

21Packets applies a crypto-agile post-quantum model to Endlet enrollment, identity, key establishment, attestation, control policy, sessions, and protected DEFT transport. The objective is to reduce Harvest Now, Decrypt Later exposure while keeping algorithms and key policies evolvable as standards and approved profiles change.

Does quantum-safe encryption only protect data in transit?

No. Protected transport is one layer. The model also governs which identity-bound, machine-validated Endlets may receive route state, policy, session authority, and key material. Selected confidential-execution capabilities can extend protection to approved data and code in use where supported.

Will adopting new algorithms require replacing every Endlet?

The architecture is designed for crypto agility: approved algorithms and key policies can evolve while the Endlet identity and operating model remain consistent. The exact migration and validation plan depends on the organization’s approved cryptographic profile and deployment requirements.

Implementation questions

Fit the fabric to the environment you already operate.

Deployment choices should follow application dependencies, approved infrastructure, continuity criteria, and the organization’s operating model.

Is 21Packets cloud agnostic?

Yes. The fabric is designed to span approved cloud, on-premises, branch, provider-edge, industrial, workload, and edge environments. Endlets abstract the transport beneath them, allowing one operating model across infrastructure without binding operations to a single cloud or carrier.

Does 21Packets require proprietary hardware?

Not by default. Endlets are software runtimes that can operate on commodity compute and approved edge hardware in multiple packaging formats. Hardware-backed confidential execution may require supported processor capabilities for the selected workload, but it is not required for every fabric deployment.

What topologies can the fabric support?

Current product architecture supports point-to-point, hub-and-spoke, and full-mesh relationships. The right topology depends on application dependencies, segmentation policy, provider diversity, locality, and continuity requirements.

How does zero-downtime failover work?

21Packets continuously evaluates transport health and policy-approved alternatives. Slip-Routing and DEFT are designed to transition protected traffic away from degraded paths while preserving the logical fabric relationship, rather than waiting for a static route to fail completely. During procurement, validate continuity against the actual applications, underlays, session behavior, and recovery criteria in scope.

Can 21Packets be introduced without a single cutover event?

The software deployment model supports placing Endlets into selected environments and expanding the governed fabric from there. The rollout sequence, coexistence period, and migration boundaries should be defined during architecture review; no universal implementation timeline or cutover pattern is assumed.

Evaluation criteria

Turn product claims into testable acceptance criteria.

Scope the architecture around the operating environment, then test the behaviors that matter to procurement, security, and application owners.

What should a proof of value validate?

Validate Endlet deployment, identity and machine-state admission, policy distribution, path adaptation under controlled degradation, visibility into Endlet and transport state, and the approved cryptographic profile. Use priority workloads and continuity requirements—not a generic lab topology.

What information is needed to scope an implementation?

Bring the current topology, cloud and carrier relationships, deployment environments, application dependencies, segmentation requirements, continuity targets, cryptographic policy, and operational ownership model.

How are Endlets operated over time?

EdgeControl governs admission and lifecycle actions; WanAware and Endlet telemetry provide context across path health, availability, assets, services, and fabric state. Procedures should cover re-attestation, policy changes, replacement, retirement, and revocation.

Are pricing, implementation duration, and support terms fixed?

No public fixed pricing, implementation duration, minimum footprint, or universal support package is stated in the current product material. These items should be scoped against the deployment footprint, service requirements, validation plan, and operating model.

Architecture comparison

21Packets, SASE, and SD-WAN solve different layers of the problem.

SASE generally centralizes cloud-delivered security and access services. SD-WAN primarily manages WAN connectivity and path selection. 21Packets combines endpoint governance, adaptive transport, distributed services, and crypto-agile post-quantum protection in one fabric model.

Requirement
21Packets
SASE
SD-WAN
Quantum-safe security
Yes
No
No
Zero-downtime failover
Yes — validate against target workloads
No
Partial
Commodity hardware
Yes
Yes — cloud or agent model
Partial — vendor CPE is common
ISP and cloud agnostic
Yes
Partial — provider dependent
Yes
Global secure networking
Yes
Yes
Partial — security is typically additive
Identity and machine validation at the software endpoint
Yes
Partial
No
Distributed service execution at the endpoint
Yes
Partial
No

Does 21Packets replace SASE or SD-WAN?

The answer depends on scope. 21Packets overlaps with connectivity, path adaptation, identity, segmentation, and distributed security functions, but an evaluation should map existing SASE and SD-WAN services to required controls before deciding what remains, integrates, or is retired. Category labels are not a migration plan.

Design your fabric

Start with the operating constraint you cannot compromise.

Bring your current topology, providers, workloads and continuity requirements. We’ll map the 21Packets capabilities that fit.

Book a working session