The VPN your organization controls.

WireGuard-based tunnels with single sign-on, device management, and a gateway fleet you operate.

Gateway fleet
What operators see in the console.
Frankfurt312 / 800
healthy
Helsinki187 / 800
healthy
Singapore441 / 600
draining

Built for teams that run their own infrastructure.

Private keys never leave the device

Each client generates its own keypair locally. The server registers public keys only; it never sees, logs, or stores the private half.

pub: xTIBA5rboUvnH4htodjb6e697QjLERt1NAB4mZqp8Dg=

One identity

Sign in with Microsoft, Google, or Apple. Access ends the moment you revoke the account.

Organizations first

Members, roles, and devices are managed per organization, with immediate revocation.

A fleet you can see

Every gateway reports health, capacity, and active sessions. Drain one for maintenance without dropping the sessions already on it.

Native clients for iOS, macOS, Android, and Windows, all managed from one console.

Set up your organization in minutes.

Create an account
o3vpn

WireGuard is a registered trademark of Jason A. Donenfeld. o3vpn is an independent product, not sponsored or endorsed by the WireGuard project.