Privacy-first VPN · mobile and desktop
Rover VPN
A VPN built around one question: who can see your traffic once it leaves the tunnel. Rover VPN ships mobile apps, a set of pre-configured global breakout locations, and the option to run your own breakout on infrastructure you control.
Breakout
Where your traffic re-enters the internet
The breakout is the point where traffic leaves the tunnel and reaches the public internet. Whoever operates it sees the traffic in the clear, minus whatever TLS protects. Most VPN products treat that point as an implementation detail. Rover VPN treats it as the product.
Pre-set global locations
- What it is
- Rover-operated breakout points in a set of global regions
- Pick by
- Region, in-app, per connection
- Use it for
- Roaming staff, travel, untrusted local networks, general privacy
- Transport
- WireGuard, or ZeroTier where the estate already uses it
Custom breakout (optional)
- What it is
- A breakout on infrastructure you nominate, in a region and jurisdiction you choose
- Egress IP
- Yours, and stable
- Use it for
- Traffic that has to appear to originate from your own network, or must not transit a third party at all
- Pairs with
- The same overlay the routers, switches, and RapidSTACK gateways join
Apps and clients
iOS and Android
Connect, switch breakout location, and reconnect on network change. The phone is the device most likely to be on a network nobody vetted, so it gets first-class treatment rather than a web portal.
Windows, macOS, Linux
Standard WireGuard clients, which means the client code carrying your traffic is open and widely reviewed rather than proprietary to a vendor.
Router-terminated
Terminate on a Rover Router instead of per device, so everything behind it is covered without an agent on each endpoint. Useful for a branch, a residence, or a temporary office.