Most VPNs ask you to trust a company in a country you have no standing in, with owners you cannot name, running code you cannot read. This is the other shape: one gateway in a Montréal datacentre, run by a single person, built from infrastructure published in the open. Your traffic exits in Canada — a local hop from Québec and Ontario, in a jurisdiction a Canadian court can reach, which is the point rather than a side effect.

󰔟 Two minutes to a working tunnel
Create an account, pay once, add a device, pick a tier, scan the QR code.
[ CREATE ACCOUNT ] [ CLIENT SETUP GUIDE ]

Who runs the tunnel

Here is what you can check about this one:

What you get

A WireGuard tunnel from your devices to a gateway I run, plus a DNS resolver that answers inside it — no client app, no bundled browser, no telemetry SDK. You get a configuration or a QR code and your operating system’s own WireGuard client does the rest: client setup guide.

Verify it, don’t trust it

Every claim on this page is a test you can read — the full dossier: who runs the tunnel, the tier mechanics, what is and is not logged, and the signed infrastructure audit that tests the no-log behaviour instead of asserting it.

The three tiers

󱠽 PIPE
Just the tunnel

DNS: untouched — the configuration carries no DNS setting, so your device keeps the resolver it already runs, outside the tunnel.

󰈉 PRIVACY
Tunnel + encrypted DNS

DNS: ours, inside the tunnel — your device resolves through 172.16.40.1, reachable only from inside the tunnel, which forwards upstream over DNS-over-TLS.

󰦝 SECURITY
Tunnel + encrypted DNS + blocking

DNS: ours, with filter lists — AdGuard Home at 172.16.41.1 blocks ads, trackers and known-malware domains before your device reaches them.

The tiers differ in DNS only — never in speed. All three run through the same gateway with the same shaping: up to 1 Gbit/s per connection.

How a tier gets assigned

The tier is chosen per device when you add it in the portal, so one subscription can run a laptop on privacy, a phone on security and a work machine on pipe.

The price

$10/mo 󰓹 per month — every tier included
3 󰾰 devices per account
1 Gbit/s 󰓅 up to, per connection

$10/mo (USD), billed monthly by card through Stripe. One subscription covers all three tiers — no data cap, no per-gigabyte billing, no usage-based fees. Cancel any time; access runs to the end of the paid period. The details live in terms & fair use.

Being straight about what this is not: it is a privacy service, not a geo-unblocking one — a single gateway, no rotating exit addresses, no residential proxy pools.

What we do not keep

Questions

Which devices can I use it on?

Three devices per account, each with its own tier, on any client that speaks WireGuard — the official Windows, macOS, Linux, iOS and Android apps, or a router that supports WireGuard imports.

Can my devices reach each other through the tunnel?

Only if you say so. The portal’s device-to-device page is where you link your own devices — one direction at a time, either all traffic or a named protocol and port list.

Can I bring my own DNS?

Yes — that is the pipe tier. Your device keeps whatever resolver it already has, including in-browser DNS-over-HTTPS.

How do I know my DNS is going through the tunnel?

The DNS leak test mints a unique probe name, has your browser look it up, and then checks whether that lookup reached YMR’s resolver inside the tunnel.

What happens if I cancel?

Access stops at the end of the paid period, and the device records are gone with the account.

󰔟 Two minutes to a working tunnel
Create an account, pay once, add a device, pick a tier, scan the QR code.
[ CREATE ACCOUNT ] [ CLIENT SETUP GUIDE ]
󰣨 ymrtech@ymrtech | 󰌠 NixOS | 󰍢 UTF-8