GHOSTPORT
← Back to Dev Log

Why I built GhostPort

A letter from the founder.
May 13, 2026 • Thomas, Founder & CEO
Thomas (right) with fellow Marines
USMC • with the guys I served with. Some of the lessons that go into GhostPort started here.

If you're reading this, you've probably already found one of our articles about routers spying on you, or DNS leaking everything, or your ISP selling browsing history that it's legally allowed to sell. Those posts are the technical side of what we do.

This one's the other side. Who I am, why I started this, and what I'm trying to build.

Who I am

I'm Thomas, the founder and — for now — the only full-time engineer behind GhostPort Technologies. I'm a United States Marine Corps veteran. My MOS was 0671 — Data Systems Administrator. Which is a clean way of saying that for the years I wore the uniform, my job was to keep secure communications running and keep adversarial network traffic out of places it didn't belong.

I trained on NIST cybersecurity controls. I deployed on field operations where the comms had to work, and had to stay private, and had to keep working when someone was actively trying to break them. I came home with two things that turned out to matter later: a deep instinct for what "secure by design" actually means at a technical level, and a habit of expecting the people responsible for protecting communications to take the job seriously.

Background

The question that became GhostPort

After I came home, I worked in enterprise IT. The kind of environment where the security budget has a comma in it, the firewalls cost more than my first car, and there's a whole team whose entire job is incident response.

And I watched it get hit anyway. By foreign threat actors. By misconfigurations the vendor manuals warned about. By things that should not have worked, working — because no one had the time or the mandate to close the gap.

What I kept thinking, sitting in those rooms, was the same thing over and over:

"If billion-dollar companies, with whole security teams, can barely protect themselves — who is protecting regular households?"

Because regular households are running consumer routers. From the cable company. With factory defaults nobody changed. Phoning home to a vendor cloud that nobody audited. Broadcasting hidden BSSIDs they didn't know existed. Leaking DNS in plaintext. Selling browsing history that they were legally allowed to sell after 2017. And nobody — not the ISP, not the router vendor, not the manufacturer of half the devices in the house — was on their side.

That's the gap I decided to close.

What I'm building

GhostPort is a privacy-first router built on a Raspberry Pi 5, running an operating system I wrote (mostly) from scratch — GhostPort Phantom OS — with a fleet management plane, a tunnel infrastructure across multiple AWS regions, a public bug bounty, a passed independent penetration test, and source code that's publicly readable under Elastic License v2. If you don't like what we wrote, you can audit it. If you want to fork it for your own household use, you can. We didn't put the code behind a wall.

I built the hardware. I wrote the firewall profiles. I wrote the dashboard. I wrote the fleet API. I wrote the activation flow and the Stripe integration. I wrote the watchdogs that catch things when they break at 3am. I did the security audits — sixteen rounds of them, 311+ bugs found and published in the dev log. Then I hired an external pen tester and we did it again until he couldn't break it.

Solo. Self-funded. No VCs telling me to grow at any cost or sell user data to make the numbers work. The thing I'm building is the thing I'd be willing to put in my own house with my own family on the other end of it — because that's exactly what I do.

What I'm trying to do here

The short version of the goal:

Protect Regular Families The Marine Corps protected military comms. GhostPort is supposed to do the equivalent thing for the people back home — without requiring them to be engineers themselves.
Earn the Trust, Don't Demand It Source-available code. Public bug bounty. Independent pen testing. Every patch documented. You shouldn't have to take my word for any of it.
Build It to Last This is not a side project I'll abandon when the next thing comes along. GhostPort is a real company, with a real product line, and I plan to be here for the long version.
Stay Honest If we ship a bug, we tell you. If a test fails, we tell you. If a feature we promised slipped, we tell you. The privacy industry is full of people who don't — and that's part of why the industry has the trust problem it has.

The road ahead

The product line is live. The first dual-tunnel architecture is in production. The first customer is onboarded. We have a west-coast data plane in San Jose and an east-coast control plane in Virginia. Post-quantum WireGuard (Rosenpass) is queued for when our test fiber gets installed. The blog you're reading is hosted on infrastructure I'm running myself, behind certificates I renew myself, with code I can recite in my sleep.

From here, the plan is to keep going. More devices, more regions, more honest engineering write-ups, more transparency. If you want to follow along, the dev log on this blog is the place — everything I ship lands there, including the things that don't go well the first time.

And if any of this resonates with you — whether you're a customer, a fellow vet, a fellow builder, or just someone tired of being the product — the door is open.

Semper Fi, and thanks for reading.

— Thomas
Founder & CEO, GhostPort Technologies

If you want to put one of these in your own house.

ghostporttechnologies.com
Your network. Your rules.
🎨
ACCENT COLOR
A+
TEXT SIZE