WireGuard, packaged for home

WireGuard-based remote access in a dedicated home appliance.

HomeVault uses WireGuard-based encrypted networking, then adds appliance provisioning, native pairing, connectivity recovery and Secure Relay fallback around it.

WireGuard is the tunnel. HomeVault is the product around it.

WireGuard provides a modern encrypted VPN protocol with a deliberately small design. For a complete consumer product, however, the tunnel is only one part of the job.

HomeVault adds the pieces needed around that tunnel: appliance identity, client pairing, connection-state handling, direct-connect attempts, encrypted relay fallback and a native app experience.

Direct first, resilient when networks get awkward.

When the client can establish a direct path to the HomeVault appliance, that is the preferred connection. Real-world networks are not always cooperative, especially across mobile carriers, hotel networks and restrictive NAT.

For those cases, HomeVault can use its Secure Relay to carry the already encrypted VPN packets. The relay is a transport fallback, not the holder of the VPN private keys.

For people who do not want to administer a VPN server.

Technical users can absolutely build a WireGuard server themselves. HomeVault is aimed at the person who wants the security and performance characteristics of that approach without turning remote access into another server they have to operate.

Questions people ask

Frequently asked questions

Does HomeVault use WireGuard?

Yes. HomeVault's VPN data path is built around WireGuard-based encrypted networking.

Why use an appliance instead of configuring WireGuard manually?

Manual WireGuard is a strong option for technical users, but you still need to provision keys, distribute client configurations, handle changing network conditions and maintain the host. HomeVault is designed to turn those operational tasks into a managed appliance and app experience.

What happens when a direct WireGuard connection cannot be established?

HomeVault prefers a direct encrypted path. When network conditions prevent that, the Secure Relay can transport the encrypted VPN packets until a direct path becomes available again.

Can the Secure Relay read my VPN traffic?

The relay is designed to transport encrypted VPN packets rather than terminate the private VPN session. WireGuard private keys remain with the paired endpoints rather than being provided to the relay.

Your home network. Anywhere.

Be first in line for HomeVault.

Join early access for launch and availability updates. Joining the list does not place an order or take payment.

Join early access