> RED_PILL // VPN.SPEC

The VPN they
don't want
you to have.

Built for the users the internet is being renovated against: EU citizens under age gates, users behind the Great Firewall, Iranians and Russians whose network is a hostile environment. Not built for corporate remote workers.

12
Live exits
3
Protocols
0
Logs kept
Devices
// exits.map

Pick your exit

Real servers. Real jurisdictions. No fake counts.

// frontline
Iceland flag
LIVE
Iceland
2 cities
Switzerland flag
LIVE
Switzerland
3 cities
Netherlands flag
LIVE
Netherlands
4 cities
Sweden flag
LIVE
Sweden
3 cities
Romania flag
LIVE
Romania
2 cities
Bulgaria flag
LIVE
Bulgaria
2 cities
Panama flag
LIVE
Panama
1 city
Germany flag
LIVE
Germany
3 cities
Finland flag
LIVE
Finland
2 cities
Hong Kong flag
LIVE
Hong Kong
1 city
Japan flag
LIVE
Japan
2 cities
United States flag
LIVE
United States
6 cities
// coming online
Mexico flag
QUEUED
Mexico
Argentina flag
QUEUED
Argentina
Singapore flag
QUEUED
Singapore
Taiwan flag
QUEUED
Taiwan
Georgia flag
QUEUED
Georgia
Albania flag
QUEUED
Albania
// tunnel.spec

How we tunnel

Eight protocols on board. The app picks. You can override.

WireGuard
DEFAULT

Fast, modern, boring in the good way.

Small kernel-level codebase, state-of-the-art crypto. Default whenever the network lets us out clean.

TRANSPORT
UDP
PORT
51820
BEST FOR
SPEED
OpenVPN
FALLBACK

TLS on 443. Looks like HTTPS.

The workhorse. Kicks in when UDP is throttled or WireGuard is blocked outright.

TRANSPORT
TCP/TLS
PORT
443
BEST FOR
COMPATIBILITY
V2Ray
FRAMEWORK

The framework the great firewall is scared of.

Not a protocol, a platform. Everything below rides on it: transport swapping, TLS masking, multiplexing.

TRANSPORT
MULTI
PORT
ANY
BEST FOR
CN / IR / RU
VMess
STEALTH

Encrypted, header-scrambled. Old faithful.

Random headers, timestamp auth, no plaintext fingerprint. What kept people online through the last decade of blocks.

TRANSPORT
TCP + WS
PORT
443
BEST FOR
HOSTILE NETS
VLESS
LIGHT

Leaner than VMess. Harder to fingerprint.

No built-in crypto overhead. Pairs with XTLS/Reality to look identical to a real TLS site the censor doesn't want to break.

TRANSPORT
TCP + XTLS
PORT
443
BEST FOR
DEEP DPI
Trojan
MASQUERADE

Pretends to be a normal HTTPS website.

If probed, it serves a real website. Deep packet inspection shrugs and moves on. That's the whole trick.

TRANSPORT
TCP/TLS
PORT
443
BEST FOR
ACTIVE PROBING
Shadowsocks
CLASSIC

The classic that got a billion people out.

SOCKS5 with a cipher on top. Still works, still fast, still the fallback of fallbacks in a pinch.

TRANSPORT
TCP/UDP
PORT
ANY
BEST FOR
LOW-END DEVICES
Built by us
Shadow
IN-HOUSE

Ours. Trained on the traffic they actually block.

Built from watching the censors up close. Ships when nothing else survives the wire. Auto-selected in China, Iran, Russia.

TRANSPORT
OBFUSCATED
PORT
ROTATING
BEST FOR
WHEN ALL ELSE DIES
// ships with
  • +Kill switch (hard)
  • +DNS routed through the tunnel
  • +Split tunneling (desktop)
  • +Multi-hop on frontline exits
  • +Unlimited devices, one account
  • +WireGuard + OpenVPN + Shadow
  • +Pay in Bitcoin, Monero, Ethereum
  • +Open-source clients, reproducible builds
// will never ship
  • -Activity logs
  • -Connection logs
  • -Email required to sign up
  • -KYC of any kind
  • -Ads. Ever.
  • -Telemetry beacons
  • -"Family-safe" content filters
  • -Government backdoors
// questions.log

Frequently interrogated

01Do you keep logs?+
No activity logs. No connection logs. Nothing that ties a session to a user. We can prove it because our infra is diskless where it matters and the parts that hit disk are open for audit. If a court asks us for your traffic, we hand over an empty envelope. That's the whole design.
02Does this actually work in China, Iran, Russia?+
Yes. Our Shadow protocol is what we were building before this was a company - the founding team spent years bypassing the Great Firewall and Iran's DPI stack. It works today. Honest caveat: no VPN works 100% of the time on those networks. When one path dies we ship a new one, usually within hours.
03How many devices?+
Unlimited. One account, every phone, laptop, and router in your household. We don't count seats because charging you per device is a scam.
04How do I pay?+
Crypto: Bitcoin, Monero, Ethereum. Monero is what we recommend. Cards are on the roadmap but not the priority - the whole point is that you shouldn't have to identify yourself to speak.
05Is there a refund?+
30 day, no questions. If you paid in Monero the refund goes to a Monero address you give us. See /legal/refunds for the fine print.
06Do you support port forwarding?+
Not yet. It's on the roadmap for the frontline exits (IS, CH, RO). Not for the streaming-oriented US exits.
07What happens if you get a subpoena?+
We respond, honestly, that we don't have the data. We publish a warrant canary. If the canary disappears, assume the worst and switch protocols.
08Will my ISP see I'm using a VPN?+
On WireGuard, yes - they see encrypted traffic to a known VPN endpoint. On Shadow, no - the traffic looks like ordinary HTTPS to a CDN. Pick your threat model.
09Can I run it on a router?+
Manually via WireGuard config today. Native OpenWRT and pfSense builds are queued behind the Android and Linux clients.
10Why $5 a month? Why not free?+
Servers cost money. Free VPNs pay their bill by selling your traffic. We refuse to do that, so you pay us the price of one beer per month and we run clean infrastructure. If you genuinely can't afford $5 and you're behind a firewall, email us. We have a fund.
// last.byte

Take the pill.

$5 a month. Cancel in one click. No email, no card, no story to tell.