Europe
Amsterdam
Netherlands
- Status
- live
- Type
- physical planned
- Protocol
- WIREGUARD
EVPN is a free, privacy-first VPN built around modern encrypted tunnels, private DNS, leak protection and a network architecture designed to separate identity from traffic.
EVPN is designed to reduce what any single system can know about you.
Identity, promotions and tunnel routing are separated by design. VPN gateways should receive only the minimum information needed to establish an authorised connection — not a profile of your browsing activity.
EVPN is designed to make secure networking automatic. Advanced controls remain available when you need them; sensible privacy defaults come first.
Modern encrypted tunnels, fast handshakes and efficient roaming between Wi-Fi and mobile networks.
Designed around:
MODERN CRYPTOGRAPHY • FAST HANDSHAKE • MOBILE ROAMING
Fail-closed traffic controls designed to keep DNS, IPv6 and application traffic from escaping outside the VPN when protection is enabled.
Designed around:
KILL SWITCH • DNS PROTECTION • IPv6 PROTECTION
DNS requests stay inside the encrypted tunnel and are designed to use EVPN-controlled recursive resolvers rather than a public resolver by default.
Designed around:
IN-TUNNEL DNS • DNSSEC • NO QUERY LOGGING POLICY
Automatically select an appropriate endpoint based on network quality, availability and proximity, while retaining manual control.
Designed around:
AUTO ROUTING • SERVER HEALTH • MANUAL CONTROL
A browser preview of the connection model — not a real VPN tunnel.
INTERFACE PREVIEW
DEMO ONLY — no real tunnel is established
EVPN handles the networking complexity while keeping the connection model intentionally simple.
Choose a location manually or let EVPN select an appropriate gateway.
The control plane authorises a temporary tunnel identity without sending account or promotion details to the VPN gateway.
Device traffic is routed through the VPN using a WireGuard-first transport architecture.
Traffic exits through shared VPN infrastructure while DNS remains inside the protected path.
EVPN is being designed around a smaller, transparent network of useful locations rather than inflated server numbers and mystery endpoints.
Europe
Netherlands
Europe
Germany
Europe
United Kingdom
Europe
France
Europe
Switzerland
Europe
Sweden
North America
United States
North America
United States
EVPN’s design does not require storing a history of websites or services visited through the tunnel.
Private DNS resolvers are designed with query logging disabled.
Do not maintain per-user destination-IP histories.
VPN gateways receive short-lived tunnel information rather than account or profile data.
Fail-open versus fail-closed network controls — and why “protection enabled” should mean traffic does not silently escape when a tunnel drops.
How DNS queries escape tunnels, what private resolvers change, and why “connected” is not enough if name resolution still leaves the protected path.
No. A VPN can hide your originating IP from destination sites and encrypt traffic on the path to the VPN gateway, but it does not make you anonymous. Signing into identifiable accounts, browser fingerprinting, malware and global adversaries can still reveal who you are. EVPN is designed for private connectivity — not absolute anonymity.
EVPN’s design does not require browsing history, DNS query history, destination-IP histories or per-session traffic profiles on the VPN data plane. Aggregate operational metrics (such as tunnel counts and gateway health) may be collected to run the service. See the Security and Privacy Policy pages for the full distinction between website data and VPN service data.
EVPN is designed WireGuard-first for modern encrypted tunnels, fast handshakes and efficient roaming. Additional transports (for example Stealth options for restrictive networks) are planned research/product work and will be labelled clearly when available.
Leak Shield is designed as a fail-closed control: when protection is enabled, traffic should not silently escape outside the tunnel during an interruption. Exact behaviour will be documented per platform when apps ship.
Yes by design. DNS requests are intended to stay inside the encrypted tunnel and use EVPN-controlled recursive resolvers rather than a public resolver by default. Private DNS resolvers are designed with query logging disabled.
Yes. Smart Connect can select an appropriate gateway automatically, and manual location selection remains available when you want explicit control.
Apps are planned for Windows, macOS, iOS, Android and Linux. The iOS client is in development; the others are planned. Download and store links will appear only when real builds are available.
Yes. There is no paid tier, no subscription and no checkout. Every privacy feature EVPN ships is available to everyone. The service is funded by clearly labelled commercial placements on EVPN’s own website and apps — promotion of our own FinDech-ecosystem projects, affiliate offers, sponsored placements and direct partnerships.
No. Placements are never targeted using browsing history, DNS queries, destination IP addresses or anything else derived from VPN traffic, and VPN traffic data is never sold or shared. Selection can read only the platform, app version, locale, the EVPN destination country you chose in the app, and the campaign date. See the Why Free page for the full boundary.
No. Placements never influence routing, tunnel security, DNS behaviour or connection quality, and they never appear inside websites you visit through the tunnel. If the promotion system fails or is switched off, the VPN keeps working normally.
The network is live: eight EVPN-operated locations have each passed end-to-end WireGuard acceptance and carry traffic. The app is not publicly distributed yet — iOS ships as a TestFlight build, and there is no App Store release to claim. We do not list a city as live before a tunnel through it has been proven.