The VPN your organization controls.

WireGuard-based tunnels with single sign-on, device management, and a gateway fleet you operate.

Gateway fleet
What operators see in the console.
Frankfurt312 / 800healthy
Helsinki187 / 800healthy
Singapore441 / 600draining

Built for teams that run their own infrastructure.

Private keys never leave the device

Each client generates its own keypair locally. The server registers public keys only; it never sees, logs, or stores the private half.

One identity

Sign in with Microsoft, Google, or Apple. Access ends the moment you revoke the account.

Organizations first

Members, roles, and devices are managed per organization, with immediate revocation.

A fleet you can see

Every gateway reports health, capacity, and active sessions. Drain one for maintenance without dropping the sessions already on it.

Native clients for every platform your team uses, managed from one console.

  • iOS
  • macOS
  • Android
  • Windows

Not set up yet? Request access.

No account needed — tell us about your team and we'll set it up.

Platforms in use

Select every client your team needs.

What do you need?

Select everything that applies.

Optional. E.g. a MikroTik router already on site.

Optional. Anything else we should know.

Set up your organization in minutes.

Create an account
o3vpn © 2026 O3Studios by ExecutablePrivacy PolicyTerms & Conditions

WireGuard is a registered trademark of Jason A. Donenfeld. o3vpn is an independent product, not sponsored or endorsed by the WireGuard project.