Encrypted transport, verifiable routing
Name resolution, traffic routing and the core’s runtime state are open to inspection layer by layer. The resolvers, the route and the routing rules are all set by you.
- DNS encrypted the whole way
- Three connection states side by side
- Routing rules you define yourself

What it is
Secure, transparent, under your control
Secure
Traffic travels over encrypted transport and DNS queries go out over an encrypted protocol. Whether resolution really enters the tunnel can be verified independently.
Transparent
The lookup path, the traffic exit and the core’s runtime state are open layer by layer, and every verdict expands to the reasoning behind it.
Under your control
The resolvers, the route and the routing rules are all set by you. A change is re-evaluated at once, and you can confirm it took effect.
Routing transparency
Resolution and routing under the three connection states
Not connected, smart routing, global proxy — the same domain takes a different lookup path and a different exit under each.
Reasoning
- Matched the direct list, so neither the lookup nor the traffic goes through the proxy.
Overview
Core capabilities
- Routing transparency
Domain route lookup
The lookup path and traffic exit under all three connection states, side by side. Each one expands to the reasoning behind it.
- Routing transparency
Live connections
Active connections grouped by domain, with the exit, the traffic so far and the rule that matched. The data stays in memory.
- Resolution security
DNS leak test
Tunnel takeover and resolver encryption are checked separately. When the preconditions are not met, the verdict is “cannot be confirmed”.
- Resolution security
Encrypted DNS, two resolvers
The direct and proxied resolvers are configured independently, over DoH or DoT, and you can enter an address of your own.
- Under your control
Custom routing rules
Pin a domain suffix, keyword or IP range to direct, proxy or blocked. Custom rules take priority over the built-in rule sets.
- Runtime transparency
Two independent log channels
Connection logs and DNS query logs switch on separately. Both are off by default, and switching one off clears it.
Privacy and data
Privacy and data handling
No record of what you visit
We do not log the domains you visit, and we do not log what you transmit.
No IP address, no device information
Passwords are stored only as a salted hash, which cannot be reversed.
Both log channels are off by default
Before you switch one on, the app states what is recorded, where it is kept and how to switch it off. Switching it off clears it.
Your account can be deleted permanently in the app
It takes effect immediately, with no need to contact support.
The app is free for its users
Guests can use it straight away, and a free account gets 10 GB every month, reset on the 1st.
Read on
The features page goes through the modules one by one. The support page has two ways to reach us — email and Telegram.