WireGuard is the tunnel. HomeVault is the product around it.
WireGuard provides a modern encrypted VPN protocol with a deliberately small design. For a complete consumer product, however, the tunnel is only one part of the job.
HomeVault adds the pieces needed around that tunnel: appliance identity, client pairing, connection-state handling, direct-connect attempts, encrypted relay fallback and a native app experience.
Direct first, resilient when networks get awkward.
When the client can establish a direct path to the HomeVault appliance, that is the preferred connection. Real-world networks are not always cooperative, especially across mobile carriers, hotel networks and restrictive NAT.
For those cases, HomeVault can use its Secure Relay to carry the already encrypted VPN packets. The relay is a transport fallback, not the holder of the VPN private keys.
For people who do not want to administer a VPN server.
Technical users can absolutely build a WireGuard server themselves. HomeVault is aimed at the person who wants the security and performance characteristics of that approach without turning remote access into another server they have to operate.