OpenVPN, WireGuard, or a fully private VPN server

A VPN server that belongs to you. We build it on your VPS or provision one for you, configure the protocol that fits how you actually use the internet, then hand over the keys. No shared infrastructure, no account sitting in someone else's database, one server that answers to a single user: you.

Not sure which protocol you need? That's the most common starting point, and it's exactly what the first conversation is for.

Every setup ends with a full credential handover. Nothing stays with us.
Private VPN server setup by Erothots

Pick the protocol that matches your situation

Three ways to run your own VPN. The right one depends on your devices, your network conditions, and how much control you want at the end.

OpenVPN

The veteran

Two decades in production and audited more times than any VPN protocol alive. Slower to connect than WireGuard, but it gets through networks that block everything else, which is sometimes the whole job.

  • AES-256-GCM over TLS
  • Runs over TCP port 443, where UDP traffic is blocked
  • Supported by routers, NAS boxes, and older systems WireGuard can't reach
  • The safer pick behind strict corporate or hotel firewalls
Set up OpenVPN

Fully private server

Both protocols, one owner

A dedicated server in the country you choose, running WireGuard and OpenVPN side by side, on an IP address that has never been shared with another VPN user. The closest thing to owning your own piece of the internet.

  • Dedicated IP in your chosen country
  • Both protocols installed, switch whenever a network demands it
  • Pairs with our Dedicated IP and National IP services
  • Root access handed to you at delivery
Build my server

What every setup includes, no matter the protocol

Your keys, your server

At handover you receive root credentials and change the password yourself, while we watch our own access disappear. We keep no copies of keys, configs, or logins. What runs on that server afterward is entirely your business.

Leak protection done right

A kill switch that actually cuts traffic when the tunnel drops, DNS routed through the tunnel instead of your ISP, and IPv6 handled rather than ignored. Most leaks we fix come from setups that skipped exactly these three things.

Configs for every device

Ready-made profiles for Windows, macOS, Linux, Android, and iPhone, plus router configs on request so the whole household rides the tunnel. You test each one with us before we call the job finished.

OpenVPN vs WireGuard: the honest version

Both protocols are secure when configured correctly. The differences that matter in daily use are speed, battery, and what happens on hostile networks. Here is how they actually compare.

What matters WireGuardOur default OpenVPN
Raw speedUsually sits close to your unencrypted line speedNoticeably slower on the same hardware, the overhead is real
Connection timeUnder a secondSeveral seconds, sometimes longer on TCP
Battery on mobileLight. Built for phones that hop between networksHeavier, the daemon works harder to hold the session
Blocked networksEasy for firewalls to spot and drop, since it's UDP-onlyCan dress itself as regular HTTPS on TCP 443 and walk through
CodebaseRoughly 4,000 lines, small enough to audit in a weekendLarge and mature, audited repeatedly over 20 years
Best forDaily driving, streaming, phones, travelCorporate firewalls, hotel networks, older hardware
Swipe sideways to see the full table

Our default recommendation is WireGuard, with one exception. If the networks you connect from are the kind that block things on purpose, offices, hotels, certain countries, OpenVPN over TCP 443 earns its slower speed by simply working. That's why the fully private server option runs both: WireGuard for every ordinary day, OpenVPN for the days a network fights back.

The situations that bring people to a private VPN

Working remotely from another country

A stable IP in your home country keeps banking apps, payroll systems, and company logins from treating every session like a break-in attempt.

Public Wi-Fi you have no reason to trust

Airport, cafe, hotel. The tunnel encrypts everything before it touches the local network, so whoever runs that router sees noise and nothing else.

Reaching your home server from anywhere

Your media library, files, or home automation, reachable over the tunnel without exposing a single port to the open internet.

Services that lock you out by region

A dedicated IP in the right country keeps the services you already pay for treating you like you never left.

A small team that needs one trusted exit IP

Whitelist a single address on your tools once, and everyone connects through it. Far simpler than managing five consumer VPN accounts.

Leaving a subscription VPN you stopped trusting

When the provider is you, the no-logs policy isn't a marketing page. It's a server you hold root on, doing only what you told it to do.

From first message to handover, in four steps

1

Tell us how you use the internet

Which devices, which countries, which networks give you trouble. If you already know the protocol you want, say so. If not, we recommend one and explain why.

2

We build the server

On a VPS you already rent, or on one we provision in your chosen country. Hardened, updated, firewall rules in place, protocol installed and tested from our side.

3

You test on every device

We send config profiles for each of your devices and stay on the line while you connect, check for leaks, and confirm speeds look right on your actual connection, not ours.

4

Keys change hands

You take root access, change the password, and from that point the server is yours alone. Documentation for common maintenance is included so you're not calling us to reboot it.

Questions people actually ask

The five things almost everyone wants settled before they order a setup.

No, and you don't have to take our word for it. At handover you change the root password yourself while we're still connected, and you watch our session die. We keep no keys, no configs, no backdoor accounts. Auditing the server afterward is your right, and we'll show you how.
If you already rent a VPS you're happy with, use it and pay only for the setup work. If you don't, we provision one in the country you pick and transfer billing to you, so the hosting relationship is between you and the provider, not routed through us. Owning that relationship directly is part of the point.
WireGuard, and you'll probably never think about it again. It's faster, kinder to phone batteries, and simpler to maintain. The only people we steer to OpenVPN are those connecting from networks that actively block VPN traffic, because OpenVPN can disguise itself as ordinary HTTPS and WireGuard can't.
Sometimes, and we'd rather be straight about it than promise what nobody can. A private server on a plain IP tends to survive longer than commercial VPN endpoints, whose address ranges are known and blocked wholesale. OpenVPN on TCP 443 helps too. But filtering systems change without notice, so tell us where you'll be connecting from and we'll tell you honestly what to expect.
The handover includes plain-language documentation for the usual maintenance: restarting the service, adding a new device, applying updates. For anything past that, you can come back to us for paid support, but the server never depends on us being around. That independence is the product.

Something we didn't cover?

Ask us directly

One server. One user. Your rules.

Tell us your devices, your country, and the networks that give you trouble. You'll get a protocol recommendation and a plan before anything gets built.