Live privacy infrastructure Paraguay

VeritasVPN

The truth about online privacy.

A real WireGuard route from Paraguay, private Account IDs, and DNS security in the tunnel. One live node today—shown exactly as it is.

Inspect the network
  • 01WireGuardModern encrypted tunnel
  • 02Veritas ShieldIn-tunnel DNS security
  • 03Open evidenceNetwork and source to inspect
Network

Where traffic exits today

A single WireGuard egress in Paraguay. When we add regions, they appear here — not before.

1 location live
Live — Paraguay (Asunción metro)
Protocol — WireGuard + Veritas Shield
Roadmap — more regions when nodes ship
What you get

Real protection.
Zero inflated claims.

One working Paraguay node, modern encryption, Veritas Shield, private payments, and source you can inspect. We show what exists today—not a fictional network map.

Protocol

WireGuard tunnels

Linux and Android establish real encrypted WireGuard peers on the live Paraguay node today. A Chrome extension for authenticated browser-proxy protection is in final gateway validation—not a download yet. Full-device Veritas Shield applies to WireGuard clients—see Veritas Shield.

Identity

Minimal identity

Create a private Account ID without an email, or choose verified email access. An Account ID reduces required disclosure; it does not by itself make all activity anonymous, and it cannot be recovered if lost.

Plan

One honest price

$3 per month gives you the complete service on up to five devices. No feature maze and no artificially limited free tier.

Privacy

No browsing history

We do not retain destinations, DNS contents, or browsing activity. Operational account, billing, and peer metadata is documented in our Privacy Policy.

Source

Code you can inspect

Clients, agent, and infrastructure are published under Business Source License 1.1. Read the implementation and follow every change.

Roadmap

Expanding transparently

New locations and features appear only after they ship. Follow our warrant canary and public repository for current status.

Live infrastructureParaguay egressVeritas ShieldKill switch (Android and Linux)Stealth (Linux)Split tunnelUp to 5 devicesBitcoin
Veritas Shield

VPN + DNS security in the tunnel

While connected on Android and Linux, DNS goes through our gateway. Veritas Shield blocks malware, phishing, scam, cryptomining, and trackers by default. Ads stay off unless you choose Aggressive. We do not retain query names.

01Encrypted upstream

In-tunnel DNS gateway

WireGuard clients resolve via 10.0.0.1. Allowed lookups leave over DNS-over-HTTPS—not plain DNS from your device to the café Wi‑Fi resolver.

02Presets

Security · Standard · Aggressive

Security — threats only. Standard (default) — + trackers. Aggressive — + ads. Matched names return NXDOMAIN. Pick a preset in the Android or Linux app.

03Honest limits

No query logs

We keep aggregate block counts and list freshness—never query names. Upstream DoH resolvers still see hostnames we forward. Custom DoH remains a residual bypass. Details in the Privacy Policy and Learn.

Android & LinuxVeritas ShieldIncluded with Premium
How it works

Private in three simple steps

From download to an encrypted Paraguay connection in minutes. No complicated network setup required.

01Choose your app

Download VeritasVPN

Get the app for Android or Linux. Chrome, Windows, and macOS remain in active development.

Explore downloads
02Secure your access

Create your account

Use a verified email or create an anonymous Account ID. Anonymous credentials stay entirely in your hands.

03One tap to protect

Connect securely

Tap Connect to create an encrypted route to the live VeritasVPN server in Paraguay. On Android and Linux, DNS goes through Veritas Shield automatically.

WireGuard + Veritas Shield
Your deviceEncrypted tunnelParaguay server
Simple pricing

Privacy without the pricing games.

One plan. Every available feature. Pay privately with cryptocurrency and protect up to five devices.

No free-tier trackingNo card requiredCancel anytime
Transparency

Trust should be verifiable.

We publish the evidence you can inspect today and state clearly what has not happened yet.

01
Published

Warrant canary

A public statement for legal-request transparency. Read its current status directly—silence or unexplained changes should be treated seriously.

View canary →
02
Public repository

Source under BSL 1.1

Inspect the clients, server agent, and infrastructure. Commercial competing use is restricted until the license Change Date.

Browse GitHub →
03
Audit pending

Open issues and reviews

No independent audit report is published yet. Review the code, report problems publicly, and track the work without marketing spin.

Open issues →

One live WireGuard egress in Paraguay today. We add locations to the network map only after they are online and tested.

WireGuard connections with Veritas Shield, anonymous Account IDs, private Bitcoin payments, and public source under BSL 1.1. We do not advertise infrastructure or audits that do not exist.

We do not store browsing history, DNS query names, or destination traffic. We retain the limited account, billing, and WireGuard peer metadata needed to operate the service. Veritas Shield keeps aggregate and tunnel-IP blocked counts—not query names. Upstream DoH resolvers see hostnames we forward. See the Privacy Policy.

Veritas Shield is our in-tunnel DNS security layer (always on while connected on Android and Linux). Lookups go to 10.0.0.1, then over DNS-over-HTTPS for names we allow. Refreshed feeds can NXDOMAIN malware, phishing, scam, cryptomining, and tracker hostnames; ads stay off unless you pick the Aggressive preset (Security / Standard / Aggressive in the app). Ordinary DNS, DNS-over-TLS, and well-known public DoH resolvers are blocked so apps cannot easily bypass Shield; uncommon custom DoH remains a residual risk. Upstream resolvers still see hostnames we forward. Blocked counts in the app are per tunnel IP for the session—not your public WAN IP. This is DNS filtering, not antivirus. Probe with https://dns-protection-test.veritasvpn.invalid while connected, read What is Veritas Shield?, or try our free DNS leak test.

The source is public under Business Source License 1.1. It is source-available rather than OSI open source, with competing commercial use restricted until the Change Date.

Android and Linux are available now. Chrome, Windows, and macOS remain marked Coming soon until their production clients are ready.

A kill switch blocks clear-network traffic if protection fails. Linux uses firewall and fail-closed routes while connected. Android uses a full-device WireGuard tunnel while connected (always on; no in-app off option). Auto-reconnect is always on for Android and Linux. When the Chrome extension ships, it will block browser traffic if its authenticated proxy fails (browser-only, not full-device). The current VPN egress is IPv4-only, so managed full-device clients route or block IPv6 while connected instead of allowing an IPv6 bypass. Coverage is platform-specific.

Yes on Android and Linux. You can use full-tunnel mode, or exclude private LAN ranges so local devices (printers, NAS) stay reachable. Android also supports bypassing selected apps. Reconnect after changing split-tunnel settings.

Stealth wraps WireGuard inside a TLS WebSocket so it looks more like ordinary HTTPS. Use it on networks that block or throttle plain WireGuard UDP. Enable it in the Linux desktop app (Settings → Stealth mode), then reconnect. Direct UDP remains the default when Stealth is off. This helps on restrictive networks; it is not a claim of undetectability.

Ready when you are

Early-stage WireGuard VPN from Paraguay plus Veritas Shield DNS security. Honest docs. Source on GitHub.

View on GitHub