One subscription, every device you own
Windows, macOS, Linux, Android, iOS and a real command line. Five devices on one plan, each app built for its platform rather than wrapped once and shipped six times.
30-day refund, self-service. Cancel in two clicks.
Connection
Location
AutomaticApps
3Network
Diagnostic
Not connected
traffic going out as itselfNot connected
traffic going out as itselfThe apps are the product
Six clients, each one native, each one naming the limit it cannot engineer around.
iOS and iPadOS
One app for both device families, plus a Control Centre module that toggles in a tap. The kill switch runs through includeAllNetworks and On-Demand rules, so the tunnel comes back without opening the app.
Close the four exemptions Apple controls.
AirDrop, AirPlay, cellular calls and SMS, and push notifications route outside any VPN on iOS regardless of configuration. There is no API to change it, so we list them.
iOS and iPadOS — the connect screen in use
Every node, and whether the machine is really there
8 of the 40 locations are virtual: the address is local, the hardware is not. Each one says so on the marker and in the panel.
Physical — 32 of 40
Virtual — 8 of 40
Frankfurt
Germany
Bare metal in Frankfurt, netbooting a diskless image whose hash we publish.
Disks
none
Node key
rotates on reboot
Per-peer logs
none
Load or ping per node
How many people are on one
Which node you used last
All three need client telemetry we do not collect. Selection is weighted-random by advertised capacity, resolved on your device.
32
countries
40
cities
8
virtual, and labelled
6
native clients
5
devices per plan
Who can see what, at each hop
See the whole path, drawnYour device
Encryption starts here. The app holds your keys, and the kill switch blocks traffic until the tunnel is confirmed up.
Your network and ISP
The café, the hotel, the university, your ISP: all they see is one encrypted stream to one of our relays.
Our exit node
The only point where your traffic is in the clear. No disk to write to, and keys regenerated on every reboot.
The site you asked for
Sees an exit address shared by everyone on that relay, so it identifies the relay rather than you.
What this does not do: protect a device that is already compromised, hide you from a site you sign into, or defeat an adversary watching both ends of the network at once. The full threat model, including what we cannot defend against, is published.
Including the rows where we lose
A table that wins everything is marketing, and readers discount it entirely. Here is where we are behind.
| Shield | Typical big three | Budget providers | |
|---|---|---|---|
Renewal price shown beside intro | Yes | No | No |
Virtual locations labelled | All 8 | Partly | Rarely |
Protocol | WireGuard only | WireGuard + legacy | Mixed |
Native client per platform | 6 | 5–6 | 2–3 |
Command-line client | Yes | Sometimes | No |
Locations | 40 cities | 90–120 cities | 60+ |
Independent audit | Not yet | Yes, published | Varies |
Headline monthly price | $9.99 | $3–4 year one | $2–3 year one |
Dedicated IP available | No | Yes, paid add-on | Yes |
Two-year total cost | $95.76 | $130–200 | $110–160 |
Fewer cities, no audit yet, a higher sticker price, and no dedicated IP — the last one architectural rather than commercial, because a permanent address per subscriber is an identifier we have decided not to hold.
Speed, because nobody's published figure is reproducible. Streaming access, because it changes weekly. Server counts, because a count of virtual machines is not a measure of anything.
Including the uncomfortable ones
Usually. You pick a city, and the service you are using sees an address there instead of yours. Some platforms actively block VPN addresses and the result changes week to week, so we do not publish a list of which ones work — anyone who does is describing a snapshot.
Five devices on the standard plan, ten on Plus. They do not have to belong to one person. You name each device yourself and can revoke any of them from your account page.
The kill switch installs before the handshake starts, so nothing leaves the device in the clear while the tunnel is coming up. If the network is one of the captive-portal kind, the app tells you that rather than showing a failure.
Epiqueera is registered in India, which means we are required to store a validated account identity and to disclose it on a binding legal order. We are not required to store what you did online, and we do not. Both lists are in the privacy policy, in full, and they are worth reading before you buy.
Not yet. We will commission one by the earlier of 5,000 subscribers or twelve months from launch, and publish it in full. Until then the threat model is published, the node images are reproducible against published hashes, and we are not going to call ourselves audit-ready in the meantime.
Fast enough that you will not notice it on a normal connection — WireGuard rather than a legacy protocol. We do not publish a number, because no provider's published number is reproducible on your line and quoting one would be theatre.
Two clicks from your account page. No retention offer, no phone call, no reason required. You keep access until the date you already paid for, and there is a self-service refund inside the first 30 days.
A city where we advertise an address but the machine answering is somewhere else, usually to reach a region with no suitable hosting. Eight of our forty are virtual, and every one is labelled as virtual on the map, in the list and in the app.
The full privacy policy, retention detail and quarterly transparency report are linked in the footer of every page.
Five devices, forty cities, one price that stays put
Thirty days to change your mind, refunded from the account page without asking anyone. Cancelling takes two clicks and never shortens what you already paid for.