A free, post-quantum-ready VPN built on WireGuard. Hybrid ML-KEM-768 + X25519 mixed into the WireGuard PSK. No closed components — every claim links to a file in the open repo.
FIPS 203 (ML-KEM) · FIPS 204 (ML-DSA) · FIPS 205 (SLH-DSA) published. Hybrid PQC becomes deployable.
Control plane · exit agent · co-located test exit · peer isolation · DNS-leak end-to-end tests.
10/10 audit findings fixed. 4-exit Windows smoke matrix all-pass. Stage-1 free tier ready for private beta.
Service Recovery · auto-reconnect · sleep/resume · MTU fallback. 3rd-party audit + EV code-signing cert.
RSA-2048 expected break at scale. Anything not encrypted with PQC becomes effectively plain text.
Two internal audit passes (server-side and client-side) drove the Phase α blocker bundle. Every finding is tracked through to a commit, with a regression test where applicable.
No third-party crypto audit yet — that's a Phase γ milestone. We won't claim Cure53 / Trail of Bits / SOC 2 / ISO until they have actually happened. Same for the warrant canary.