๐Ÿ‡ต๐Ÿ‡ฐ Network ยท IaaS ยท Virtual Private Cloud

Your own private network.
Inside Pakistan's cloud.

QCloud Virtual Private Cloud (VPC) gives you a logically isolated section of the cloud with full control over IP ranges, subnets, route tables, gateways, and security policies โ€” hosted entirely inside KHI-1 and ISB-1, billed in PKR, and ready in under 5 minutes.

๐Ÿ›ก๏ธ Tier-3 Certified โšก 99.999% SLA ๐Ÿ‡ต๐Ÿ‡ฐ 100% Data Residency
VPC Designer Live
IGW VPC ยท 10.0.0.0/16 ยท KHI-1 ๐ŸŒ Public ยท 10.0.1.0/24 ecs-web-01 ๐Ÿ”’ Private ยท 10.0.2.0/24 ecs-db-01 ecs-cache-01 NAT
HEALTHY ยท 0.4MS khi-1a
route added 10.0.1.0/24 โ†’ IGW  ยท  NACL allow tcp/443  ยท  peering KHI-1 โ†” ISB-1 active  ยท  vpc-prod created in 4.2s  ยท  SG sg-web-01 attached  ยท   route added 10.0.1.0/24 โ†’ IGW  ยท  NACL allow tcp/443  ยท  peering KHI-1 โ†” ISB-1 active  ยท  vpc-prod created in 4.2s  ยท  SG sg-web-01 attached  ยท  
02
Regions inside Pakistan
< 5 min
to provision a VPC
99.999%
Control-plane SLA
Unlimited
Subnets per VPC

Trusted across Pakistan's enterprise networks

PTCL Jubilee Life TPL Insurance Servis Group CDC Al Badr Reon Future Matrix Abhi BCRA Apollo Premier Commtel National Engineering PTCL Jubilee Life TPL Insurance Servis Group CDC Al Badr Reon Future Matrix Abhi BCRA Apollo Premier Commtel National Engineering

Three patterns we see in every Pakistani VPC.

Compliance-grade isolation. Cross-region replication. Zero offshore exposure.

๐Ÿฆ
Banking & Fintech

Core banking in an air-gapped subnet

Payment processing, KYC, and core ledger workloads sit behind private subnets with explicit-allow NACLs. State Bank residency rules met by design.

4 of Pakistan's top 12 banks
๐Ÿ“ก
Telecom & ISPs

BSS islands with peering across KHI โ†” ISB

Billing, OSS, and IVR workloads in dedicated VPCs, peered across regions over QCloud's private fabric โ€” no public internet hop.

3 national telcos ยท 14 peered VPCs
๐Ÿ›๏ธ
Public Sector

PECA-aligned sovereign network islands

Federal and provincial workloads inside fully air-gapped VPCs with zero internet gateway, accessed only via Direct Connect from government data centers.

7 federal agencies ยท 0 offshore bytes
The architecture

One service. Every layer of your network โ€” yours to design.

QCloud VPC is a logically isolated, software-defined network you control end-to-end. Bring your own IP ranges, carve subnets, attach gateways, apply firewalls, and connect to your on-prem data center over secure tunnels โ€” all from a single console, all inside Pakistan.

Your Data Center ๐Ÿข VPN / Direct Connect VPGW ๐Ÿ‡ต๐Ÿ‡ฐ VPC ยท 10.0.0.0/16 ยท KHI-1 IGW Public ยท 10.0.1.0/24 web-01 web-02 alb App ยท 10.0.2.0/24 app-01 app-02 app-03 Private ยท 10.0.3.0/24 db-pri db-rep NAT GW peering VPC-2 ยท ISB-1 10.1.0.0/16 dr-app
๐Ÿงฑ
Logically isolated
your own network slice
๐ŸŽ›๏ธ
Full control
IPs, subnets, routes, gateways
๐Ÿ”
Defense in depth
NACLs + Security Groups + WAF
๐Ÿ‡ต๐Ÿ‡ฐ
100% in-country
every byte stays in Pakistan
Four promises

Four promises behind every QCloud VPC.

What you get by default โ€” no checkbox, no extra cost, no asterisk.

๐Ÿงฑ

Granular Isolation

Every VPC is a software-defined slice of the cloud โ€” invisible to other tenants, defended by VLAN, VXLAN, and access controls applied at every hop.

Single-tenant by design
๐Ÿ”—

Hybrid by Default

Extend your on-prem data center into QCloud with IPsec VPN or Direct Connect. Bring your routes, your DNS, your security policies โ€” they all carry over.

IPsec ยท Direct Connect ยท BGP
๐Ÿ›ก๏ธ

Defense in Depth

Stateless NACLs at the subnet level, stateful Security Groups at the instance level, optional WAF at the edge โ€” three independent layers, all auditable.

NACL ยท SG ยท WAF
๐Ÿ‡ต๐Ÿ‡ฐ

Sovereign Networking

Every packet, every route, every replication hop stays inside PTCL's Tier-3 / Rated-3 data centers in Pakistan. PECA-aligned. SBP-aligned. No offshore exposure.

100% data residency
Building blocks

Eleven primitives. Compose any network topology.

Every VPC is built from the same well-understood building blocks. Click any one to see what it does.

Connectivity

Connect your VPC to anything. Securely.

Four connectivity patterns, one console. Pick the one that fits your topology โ€” switch later if your topology changes.

Provisioning

From CIDR to running workloads โ€” in six clicks.

Watch a VPC come together. Each step takes seconds.

< 60s
median VPC creation time
Up to 5
VPCs per region (default ยท raise on request)
200
Subnets per VPC (default)
What you can build

Six topology patterns we deploy every month.

Each one tuned for a specific industry, regulator, and SLA target.

Security by design

Three rings of defense. All on by default.

Your VPC is hardened from the perimeter to the instance. Every ring is independently configurable, independently auditable.

NACL ยท subnet ยท stateless Security Group ยท instance ยท stateful WAF + DDoS ยท application Your Workload

Network ACL

Stateless firewall at the subnet boundary. Explicit allow/deny on inbound + outbound, evaluated by rule priority. Default-deny on custom NACLs.

Security Group

Stateful firewall at the instance level. Connection tracking, automatic return-traffic allowance, source group references, instance-specific rules.

WAF + DDoS

Optional managed Web Application Firewall and DDoS mitigation in front of public-facing workloads. OWASP Top 10 + bot management + geo-blocking.

SBP-aligned PECA-aligned PTA-compliant ISO 27001 CSA STAR Tier-3 Certified 100% data residency

The old way needed a network engineer.
QCloud VPC needs a console tab.

The old way
๐Ÿ—„๏ธ๐Ÿ”Œ๐Ÿ“‹
  • โœ•Procure firewall hardware ยท 4โ€“6 weeks
  • โœ•Cable, rack, and label every switch port
  • โœ•Maintain network engineer payroll: $$$
  • โœ•Manual VLAN tagging across 12 switches
  • โœ•Audit logs scattered across 4 vendors
  • โœ•Add a subnet? Submit a change ticket. Wait.
QCloud VPC
$ qcloud vpc create --name vpc-prod-01 --cidr 10.0.0.0/16
โœ“ vpc-prod-01 created ยท 4.2s
$ qcloud vpc subnet create --cidr 10.0.1.0/24 --type public
โœ“ subnet-pub-1a ยท 251 IPs
$ qcloud vpc igw attach --vpc vpc-prod-01
โœ“ igw-01 attached
โ— Available _
  • โœ“Provision a full VPC in < 5 minutes
  • โœ“Software-defined: change topology with one click
  • โœ“Pay only for gateways and IPs, not boxes
  • โœ“Centralized audit logs ยท immutable ยท 7-year retention
  • โœ“Terraform / API / Console โ€” pick your tool
  • โœ“Add a subnet? CIDR field. Done.

Most teams retire their on-prem network gear within 6 months.

Pricing

Pay for what you use. In rupees. No surprises.

VPC itself is free. You only pay for the gateways and IPs you actually provision. Egress inside QCloud is free.

console โ€บ pricing โ€บ estimator
    Estimated monthly
    PKR 0
    // assumes 730 hrs/mo ยท volume discounts available
    ๐Ÿ‡ต๐Ÿ‡ฐ Billed in PKR ยท no FX exposure ยท no egress fees inside VPC
    Open Full Pricing Calculator โ†’
    Ecosystem

    VPC is the network. Everything else plugs in.

    Once your VPC is provisioned, every QCloud service launches inside it โ€” by default, with zero extra config.

    Every QCloud service launches inside your VPC by default. No bolt-ons. No bridges. No proxies.

    FAQ

    Everything you wanted to know before you carve your first subnet.

    Design Pakistan's most secure network โ€” on the house.

    $100 in QCloud credit ยท 1-month free trial of VPC, ECS, and EVS ยท a real network architect on the call from day one ยท migration support from on-prem or hyperscalers โ€” all included.

    No credit card required ยท Production workloads welcome ยท PKR billing

    console โ€บ vpc โ€บ create
    Name:       vpc-prod-01
    Region:     KHI-1 โ–พ
    CIDR:       10.0.0.0/16
    Subnets:    3 (auto)
    Gateways:   IGW + 1 NAT
    Estimated:  PKR ~32 / hr
    provisioning in < 5 min
    Live ยท 14 VPCs provisioned across QCloud this week
    Scroll to Top