Keys and peers
Create separate key pairs for each device. Share only public keys and revoke a device when it no longer belongs on the tunnel.
Install WireGuard on a VPS you administer, choose the peers and review the logs yourself. A personal endpoint offers control, a stable address and an encrypted path through untrusted local networks.
A self-hosted WireGuard endpoint encrypts traffic between your device and VPS and gives you control over VPN configuration. It does not hide all activity from every observer. Protect peer keys, configure the firewall and review host, operating-system and application records separately.
A commercial VPN normally manages the endpoint and its policy for you. On your own VPS, you install the packages, hold the keys, define peers and decide which supporting services record events. WireGuard’s design is small; the surrounding operating system still deserves a log review.
A dedicated IP is convenient but does not blend you into a large shared exit pool. A VPN reduces exposure on your local network and changes the address seen by destinations; it is not a general anonymity system or protection from every observer.
Create separate key pairs for each device. Share only public keys and revoke a device when it no longer belongs on the tunnel.
Choose full-tunnel or split-tunnel behavior, route IPv6 deliberately and verify DNS traffic follows the intended path.
Open only the required UDP port and administration access. Confirm forwarding and NAT rules match your interface names.
Review firewall, DNS and service logging, plus retention and backups. A no-logs intention is only useful when the whole guest configuration supports it.
WireGuard uses UDP and does not run through an ordinary Tor circuit. You can keep SSH administration behind an onion endpoint while WireGuard remains reachable on its regular UDP port. That separates the management path from daily VPN traffic.
Use Tor-aware browsing and a separate account alias if your provisioning path needs less identity exposure. The supported cryptocurrency networks have public transaction ledgers, so account minimization does not remove payment history. None of those choices replaces secure client devices.
A personal tunnel is often a light compute workload. Start by estimating monthly transfer across all devices. Veil has 2 TB, Shade 4 TB, Eclipse 8 TB and Obsidian 16 TB, while the larger plans also add resources for other applications.
The same machine can become a private gateway to a password vault, dashboard, DNS resolver or cloud service. Keep the public attack surface small and document recovery before the VPN becomes your only way into the server.
Monthly or annual billing, with 30% off the twelve-month total when you pay yearly. Prices are in USD; cryptocurrency amounts depend on the invoice exchange rate. Full root, KVM virtualization, NVMe, IPv4 and IPv6 are part of the target specification for every tier.
$13/month · $109.20/year. 1 vCPU, 2 GB RAM, 30 GB NVMe and 2 TB monthly transfer. A compact starting point for one lightweight service.
$33/month · $277.20/year. 2 vCPU, 4 GB RAM, 80 GB NVMe and 4 TB monthly transfer. More room for applications and everyday self-hosting.
$63/month · $529.20/year. 4 vCPU, 8 GB RAM, 160 GB NVMe and 8 TB monthly transfer. Space for a larger stack or transfer-intensive workload.
$118/month · $991.20/year. 8 vCPU, 16 GB RAM, 320 GB NVMe and 16 TB monthly transfer. The largest configuration for dense services and heavier compute.
Choose the resources you need. Keep the personal details you don’t need to share.