‹ Harbor
How it works

From tapping Connect to your first encrypted request

Three steps happen every time you connect. None of them require you to configure anything.

1

Connect

Open the app and pick a server, or let Harbor choose the fastest one nearby based on your current location.

Under the hood: the app authenticates your device with the nearest Harbor gateway and negotiates a fresh encryption key for this session only.
2

Encrypt

Your traffic is sealed before it leaves your device, using the WireGuard protocol — unreadable to your Wi-Fi network, your carrier, or anyone between you and Harbor's server.

Under the hood: WireGuard wraps each packet in ChaCha20 encryption, which stays fast enough that video calls and gaming don't lag.
3

Arrive

Your request reaches the internet from Harbor's server address, not yours. Sites and trackers see the server — never your device or its location.

Under the hood: the response follows the same encrypted tunnel back to your device, and the session key is discarded the moment you disconnect.
device harbor server open web encrypted plain request, new address

The technical details

ProtocolWireGuard
EncryptionChaCha20-Poly1305
Key exchangeCurve25519, new key per session
DNSResolved through the tunnel, not your ISP
Kill switchBlocks traffic if the tunnel drops
ReconnectAutomatic on network change

Common questions

Does this slow down my connection?

WireGuard is lightweight enough that most people notice little to no difference in everyday browsing or streaming.

What happens if I lose signal mid-session?

The kill switch blocks outgoing traffic until the tunnel reconnects, so you never fall back to an unencrypted connection without knowing.

Can Harbor see what I do once I'm connected?

The server relays encrypted traffic without inspecting or recording it, and no destination or activity logs are kept.

Ready to see it in action?

Install Harbor