Cloud VPN
Private tunnels on machines you own.
Issue a WireGuard config per device, watch which ones are actually carrying traffic, and cut access the moment you need to. No per-seat pricing, and nobody else holding your keys.
Phone
VPN-1 · Stockholm · 10.8.0.5
[Interface] Address = 10.8.0.5/32 DNS = 1.1.1.1 [Peer] Endpoint = 80.78.31.19:51820 AllowedIPs = 0.0.0.0/0 PersistentKeepalive = 25
What you get
One key per device
Every device gets its own config and its own address. Revoke a laptop without disturbing a phone.
See what is live
Connection state is read from the nodes themselves as the page loads, not guessed from a column in a database.
Cut access in one click
Disabling pulls the peer off the node immediately. Re-enabling puts it back on the same address.
Every key retrieval is logged
Private keys are encrypted before they are stored, only admins can read them, and each read lands in the audit log.
Your machines, your keys
Nodes run WireGuard wherever you put them. Enrolment is one command, and the node never phones home.
Provider configs too
Store a Proton config beside the managed ones and hand it out the same way — labelled honestly, since we cannot see inside it.
Services
Accounts are created by an admin — there is no public sign-up. Once you are in, your configs sit on one page with a download and a QR code for each device.