Invite-only privacy network

Privacy infrastructure
for every device.

Nultow gives you WireGuard and AmneziaWG access to two countries with three curated DNS profiles โ€” managed from a control plane that keeps no activity logs.

  • No activity logs
  • WireGuard + AmneziaWG 3.1
  • DNSSEC validated resolvers
  • Single-use configs
nultow-hel1-wireguard.conf one-time link
[Interface]
# PrivateKey = <delivered once, never stored server-side>
Address = 10.66.66.42/32
DNS = 10.66.66.1
MTU = 1280

[Peer]
PublicKey = hAz1nTk9mQ4pR7sV2xL6cB8dF0gJ3wY5uE1iO6aS7=
Endpoint = hel1.nultow.opceanai.com:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25

2

Countries, 3 paths

3

DNS profiles

2

Obfuscated transports

0

Activity logs kept

Network

Two countries, three ways to route

Direct entry in Helsinki or Montreal, plus a multi-hop path that enters in Finland and exits in Canada with a single SNAT.

Operational

Helsinki ยท FI

hel1

Primary entry node: DNS stack, panel and API. Direct exit with port-forwarding-free NAT.

WireGuard 51820/udpAmneziaWG 443/udp
Operational

Montreal ยท CA

bhs1

Exit node for direct CA traffic and the multi-hop path. DNS replica and failover.

WireGuardAmneziaWG
Operational

Multi-hop

fi โ†’ ca

Traffic enters in Helsinki and leaves from Montreal. MTU 1360 for WireGuard, 1280 for AWG.

Policy routingSingle SNAT
Nodes report health without inspecting traffic. Transports: WireGuard ยท AmneziaWG 3.1
Why Nultow

Built like an operator tool, not a data product

Everything you need to run the network. Nothing that watches what you do with it.

Zero activity logs

Only aggregate byte counters per device. No destinations, no DNS queries, no traffic metadata, no analytics.

Keys delivered once

Key pairs are rendered in memory and streamed through single-use links. Private keys are never stored server-side.

Every device

Phone, laptop or router. Manage devices, rotate keys and switch DNS profiles from one panel.

Aggregate usage

Watch bytes in and out per device with 7/30/90-day ranges โ€” without inspecting a single connection.

Hardened sessions

Opaque httpOnly session cookies, TOTP for admins and re-authentication before destructive actions.

Onion access

Tor v3 onion service with optional client authorization for the panel and API. Never an exit relay.

DNS profiles

Pick how much the resolver should block

The profile is applied on the node, per tunnel IP. Change it from the panel and it takes effect without touching your configuration.

DNS profile comparison
CapabilityStandardUnfiltered, DNSSEC-validated resolverSecureRecommendedFamilyEverything in Secure, plus ads, trackers and NSFW
DNSSEC validation
Malware, phishing & C2โ€”
Ads & trackersโ€”โ€”
Adult / NSFW contentโ€”โ€”
QNAME minimisation, no ECS
Query loggingNoneNoneNone
Resolver endpointsdns.nultow.opceanai.com/dns-queryshield.nultow.opceanai.com/dns-queryfamily.nultow.opceanai.com/dns-query

DNS inside the tunnel always points at 10.66.66.1; the node maps your peer to the right resolver.

Platforms

One network, any client

Import the same one-time config everywhere. Native clients keep the keys on device; Nultow only ever sees public keys.

  1. 1

    Install the WireGuard tools for your distribution.

  2. 2

    Download your one-time .conf from the panel.

  3. 3

    Bring the tunnel up and verify the handshake.

nultow.conf
sudo wg-quick up ./nultow-hel1-wireguard.conf

Android

In development

Nultow app (Kotlin/Compose) with client-side keys, always-on and kill switch.

Linux

Available

WireGuard or AmneziaWG tools + a one-time .conf from the panel.

Windows

Available

WireGuard for Windows or AmneziaWG client with the exported .conf.

macOS

Available

WireGuard from the App Store plus the DNS profile of your choice.

iOS

Available

WireGuard app with the exported .conf and DoH/DoT DNS profile.

Routers & other

Available

Any WireGuard/AmneziaWG capable device. Tor onion access included.

How it works

From invite to connected in minutes

The panel is the control plane: it registers peers, applies DNS policy and issues configs. It never sees your traffic.

  1. 1

    Redeem your invite

    Accounts are invite-only. Enter the single-use code you received.

  2. 2

    Create a device

    Choose a node and transport; Nultow registers the peers and issues a one-time .conf.

  3. 3

    Connect & pick DNS

    Import the config, connect, then switch between Standard, Secure and Family at any time.

Have an invite code?

Create your account, add your first device and get a one-time configuration in under five minutes.

2 nodes ยท 3 DNS profiles ยท 0 activity logs

Nultow โ€” Private. Fast. Simple.