Helsinki ยท FI
hel1
Primary entry node: DNS stack, panel and API. Direct exit with port-forwarding-free NAT.
Nultow gives you WireGuard and AmneziaWG access to two countries with three curated DNS profiles โ managed from a control plane that keeps no activity logs.
[Interface] # PrivateKey = <delivered once, never stored server-side> Address = 10.66.66.42/32 DNS = 10.66.66.1 MTU = 1280 [Peer] PublicKey = hAz1nTk9mQ4pR7sV2xL6cB8dF0gJ3wY5uE1iO6aS7= Endpoint = hel1.nultow.opceanai.com:51820 AllowedIPs = 0.0.0.0/0, ::/0 PersistentKeepalive = 25
2
Countries, 3 paths
3
DNS profiles
2
Obfuscated transports
0
Activity logs kept
Direct entry in Helsinki or Montreal, plus a multi-hop path that enters in Finland and exits in Canada with a single SNAT.
hel1
Primary entry node: DNS stack, panel and API. Direct exit with port-forwarding-free NAT.
bhs1
Exit node for direct CA traffic and the multi-hop path. DNS replica and failover.
fi โ ca
Traffic enters in Helsinki and leaves from Montreal. MTU 1360 for WireGuard, 1280 for AWG.
Everything you need to run the network. Nothing that watches what you do with it.
Only aggregate byte counters per device. No destinations, no DNS queries, no traffic metadata, no analytics.
Key pairs are rendered in memory and streamed through single-use links. Private keys are never stored server-side.
Phone, laptop or router. Manage devices, rotate keys and switch DNS profiles from one panel.
Watch bytes in and out per device with 7/30/90-day ranges โ without inspecting a single connection.
Opaque httpOnly session cookies, TOTP for admins and re-authentication before destructive actions.
Tor v3 onion service with optional client authorization for the panel and API. Never an exit relay.
The profile is applied on the node, per tunnel IP. Change it from the panel and it takes effect without touching your configuration.
| Capability | StandardUnfiltered, DNSSEC-validated resolver | SecureRecommended | FamilyEverything in Secure, plus ads, trackers and NSFW |
|---|---|---|---|
| DNSSEC validation | |||
| Malware, phishing & C2 | โ | ||
| Ads & trackers | โ | โ | |
| Adult / NSFW content | โ | โ | |
| QNAME minimisation, no ECS | |||
| Query logging | None | None | None |
| Resolver endpoints | dns.nultow.opceanai.com/dns-query | shield.nultow.opceanai.com/dns-query | family.nultow.opceanai.com/dns-query |
DNS inside the tunnel always points at 10.66.66.1; the node maps your peer to the right resolver.
Import the same one-time config everywhere. Native clients keep the keys on device; Nultow only ever sees public keys.
Install the WireGuard tools for your distribution.
Download your one-time .conf from the panel.
Bring the tunnel up and verify the handshake.
sudo wg-quick up ./nultow-hel1-wireguard.conf
Nultow app (Kotlin/Compose) with client-side keys, always-on and kill switch.
WireGuard or AmneziaWG tools + a one-time .conf from the panel.
WireGuard for Windows or AmneziaWG client with the exported .conf.
WireGuard from the App Store plus the DNS profile of your choice.
WireGuard app with the exported .conf and DoH/DoT DNS profile.
Any WireGuard/AmneziaWG capable device. Tor onion access included.
The panel is the control plane: it registers peers, applies DNS policy and issues configs. It never sees your traffic.
Accounts are invite-only. Enter the single-use code you received.
Choose a node and transport; Nultow registers the peers and issues a one-time .conf.
Import the config, connect, then switch between Standard, Secure and Family at any time.