VP.NET has announced the launch of a consumer virtual private network designed around a simple but ambitious claim: the service is built so that operators are cryptographically incapable of inspecting or logging user traffic. According to the company’s press release, the new VPN combines encrypted tunnels with Intel Software Guard Extensions, or Intel SGX, to isolate decrypted traffic inside secure hardware enclaves that system administrators themselves cannot access.
The launch positions VP.NET as a challenger to the long-standing trust model that dominates the retail VPN market. Instead of asking customers to believe a provider’s “no-logs” promise, VP.NET says users can verify the software environment before sending any traffic at all. Each session begins with live attestation, a cryptographic process intended to prove that the expected server software is running prior to the first packet exchange.
A Verifiable Privacy Pitch
The core message behind the launch is that privacy should not depend on corporate reputation, marketing claims, or policy statements alone. In VP.NET’s framing, the consumer VPN sector has spent years relying on unverifiable assurances while handling one of the most sensitive categories of data possible: a user’s full internet traffic.
Andrew Lee, chairman of VP.NET and founder of Private Internet Access, criticized the legacy VPN model in blunt terms. He argued that giving all internet traffic to a third-party operator and simply hoping that company behaves responsibly is no longer a sufficient standard. VP.NET, he said, was designed to deliver hardware-guaranteed privacy, replacing “trust us” branding with verifiable protections by design.
That language is central to the company’s market positioning. In practice, VP.NET says decrypted traffic remains sealed inside SGX enclaves, creating a hardware-enforced barrier between user data and the humans running the service. By the company’s account, this means that operators cannot secretly inspect sessions, extract traffic, or quietly turn logging on behind the scenes without detection.
How the Architecture Is Described
In its technical overview, VP.NET says it uses encrypted tunnels in combination with SGX enclaves to process traffic in an environment protected from administrators and backend operators. The company also says that traffic is mixed, batched, and obfuscated in order to make timing analysis more difficult. This matters because metadata and timing correlations can reveal patterns even when content itself is encrypted.
Another major element is attestation. VP.NET says every connection starts with a cryptographic proof that the server is running the software the client expects. The significance of that claim is straightforward: if the backend were altered, a properly functioning attestation system should reveal the change to the client. According to the company, that creates a public and immediate detection mechanism for backend modifications.
Mark Karpeles, VP.NET’s CTO and former Mt. Gox CEO, said any changes made to the backend would be detected immediately and publicly by the client software. He further stated that the company is therefore incapable of deploying secret backdoors. In a market where users routinely have no direct visibility into server-side operations, that assertion is clearly intended to differentiate VP.NET from incumbents whose policies often remain opaque at the technical level.
Crypto and Cypherpunk Figures Behind the Project
The team attached to the launch gives the product a distinctly crypto-native identity. VP.NET says the project brings together several early cypherpunk and crypto industry figures, including Andrew Lee, Mark Karpeles, Roger Ver, and media entrepreneur Matt Kim, who is identified as the company’s CEO.
Roger Ver framed the service in terms familiar to the digital asset community. In his words, Bitcoin removed banks from the trust equation, while VP.NET is trying to apply the same principle to internet routing and online privacy. Whether or not observers agree with that analogy in full, it reflects a broader effort to transplant the “don’t trust, verify” ethos from cryptocurrency infrastructure into consumer internet services.
Matt Kim echoed that framing, saying the company does not expect users to be persuaded by branding or rhetoric. Instead, he said, people should verify the system for themselves and observe how it behaves. The emphasis on self-verification is notable because it mirrors one of the most enduring ideals in privacy and crypto culture: trust minimization through transparent technical architecture.
Targeting a Multibillion-Dollar VPN Market
VP.NET is entering a large and crowded category. The company notes that industry analysts estimate consumer VPNs generate billions of dollars annually, yet most services still operate on what it describes as a “trust us” basis. That critique is not new, but VP.NET is attempting to turn it into a product-level differentiation strategy by arguing that zero-trust principles are overdue in mainstream privacy products.
Its argument is that the VPN market has stagnated technologically at the level of user assurances. Many providers advertise no-logs policies, but users generally have limited ability to independently verify those claims in real time. By contrast, VP.NET is presenting attestation, enclave isolation, and auditability as the foundations of a more measurable privacy model.
The company also says that because operators do not have access to the SGX enclaves, there are no logs available to subpoena or monetize. That is a powerful statement from a privacy branding perspective, though, as with any infrastructure claim, market participants will likely watch for independent scrutiny, implementation details, and operational proof over time.
Why Wyoming and the United States
One detail that stands out in the release is VP.NET’s choice to incorporate in the United States, specifically in Wyoming. The company says it made that choice because of transparent court oversight, contrasting that with what it described as more opaque offshore jurisdictions. In the VPN sector, providers often market themselves from offshore locations as a privacy advantage. VP.NET is taking a different approach, suggesting that legal transparency and visible oversight can be preferable to opacity.
That decision also aligns with the company’s broader messaging. VP.NET is not only trying to say that users do not need to trust the operator; it is also trying to present itself as unusually open about legal and technical assumptions. In that sense, the Wyoming incorporation decision appears intended to support the larger narrative of auditability and verifiable system behavior.
Founded in 2025, Positioned Around “Verifiable Privacy”
According to the release, VP.NET was founded in 2025 by cypherpunks and is headquartered in Wyoming. The company describes its platform as patent pending and says its goal is to replace “trust me” privacy with verifiable privacy. Specifically, it highlights hardware attestation, cryptographic guarantees, and transparent auditability as the pillars of its approach to protecting ordinary internet access.
The company’s broader claim is that user data should be both unreadable and un-loggable as a matter of system design, not internal policy. That is an important distinction for a market where privacy claims are often strongest in advertising copy and weakest in direct user visibility.
What Comes Next
At this stage, the announcement is based on the company’s own press release, so the next phase will likely center on real-world validation. The most important questions for the market are likely to include how robust the attestation workflow proves in practice, how understandable the verification process is for everyday users, how the service performs under normal load, and whether independent researchers can confirm the privacy guarantees described by the company.
Even so, the launch is notable because it pushes the VPN conversation in a more technical direction. Rather than competing only on price, server count, or geography, VP.NET is attempting to compete on provability. If that model gains traction, it could pressure the broader privacy services market to move beyond policy-based promises and toward architectures that users can inspect and verify for themselves.

