════════════════════════════════════════════════════════════════════════════════
For the sailor leaving port, the horizon was the first sign that something had changed. The moment it opened ahead of them, unbroken, unowned, extending in every direction, was the moment everything behind them became irrelevant. No fixed shore. No boundary marker. Just open sky meeting open sea at the only line in the world that has never been drawn by anyone.
The horizon belongs to no flag. It cannot be seized, taxed, or barricaded. It retreats at the same pace you advance toward it: always ahead, always open, always sovereign. HORIZON was named for that line. The line past which no watcher has jurisdiction.
Your ISP sees every website you visit. Every search you run. Every app that calls home. They see it because most internet traffic, even when the page itself is encrypted, leaks a map of everywhere you go. This is not an accident. It is how the network was built.
HORIZON closes the gap.
HORIZON is a WireGuard client app with one distinction from every other WireGuard client: the key exchange is post-quantum hardened. Standard WireGuard uses Curve25519, classical elliptic-curve cryptography that a quantum computer could eventually break. HORIZON layers ML-KEM-1024 on top of it using WireGuard's built-in pre-shared key mechanism. The tunnel is established with both simultaneously. Breaking it requires breaking both. A quantum computer that defeats Curve25519 still hits a wall of post-quantum lattice cryptography. WireGuard is a modern VPN protocol, the same one built into most home routers today. If you have a WireGuard config already, you paste it in and connect. HORIZON handles everything from there: manages the connection, keeps the tunnel locked, and makes sure nothing leaks outside it.
Your traffic routes through your own connection, your home network, your router, wherever your config points. Not through our servers. Not through a VPN company you have to trust. Through yours. That is not a feature. That is the architecture.
HORIZON is free. Not freemium. Not free-with-logs. Free.
No accounts. No credit cards. No email. No registration. Paste your config. Connect. The tunnel is open. The horizon is yours.
Three scenarios define why the encrypted tunnel matters.
PROTOCOL ONE: SURVEILLANCE INFRASTRUCTURE. Your ISP can see every website you visit, even when the page itself is encrypted, because the act of looking up a domain name happens in plaintext. HORIZON routes all of that through your private tunnel before it touches your ISP's network. What your provider sees: one encrypted connection. Nothing more.
PROTOCOL TWO: HOSTILE NETWORK. Public Wi-Fi is open by design. Anyone on the same network can watch your traffic, tamper with it, or insert themselves between you and the sites you visit. HORIZON encrypts everything before it leaves your device. The network around you can be as hostile as it wants. The tunnel is not.
PROTOCOL THREE: GEOGRAPHIC RESTRICTION. Some content is only available in certain countries based on where your internet connection appears to be. HORIZON routes your traffic through your home network or chosen connection point. Websites see that location, not wherever you physically are. The restriction disappears.
────────────────────────────────────────────────────────────────────────────────
PROTOCOL 01: ISP SURVEILLANCE
THREAT ▸ Your ISP can see every site you look up, even on encrypted connections. DNS queries travel in plaintext by default.
HORIZON routes all traffic, including DNS lookups, through your private WireGuard tunnel before it touches your ISP. Your provider sees one encrypted connection going out. No domains. No destinations. No browsing history.
PROTOCOL 02: HOSTILE NETWORK
THREAT ▸ Public Wi-Fi has no security. Anyone on the same network can watch, intercept, or tamper with your traffic.
HORIZON encrypts everything before it leaves your device, before it ever touches the Wi-Fi network. No one on the same connection can read your traffic or interfere with it. The network around you can be completely untrusted. Your tunnel is not.
PROTOCOL 03: GEOGRAPHIC RESTRICTION
THREAT ▸ Some content is locked to specific countries based on where your internet connection appears to be located.
HORIZON routes your traffic through your home network or chosen connection point. Websites and services see that location, not where you physically are. If your home network is in the right place, the restriction is simply not present.
────────────────────────────────────────────────────────────────────────────────
NIST CERTIFIED — THE SAME STACK FEDERAL AGENCIES ARE CURRENTLY SCRAMBLING TO ADOPT
STANDARDCERTIFICATIONCLASSIFICATIONOPERATIONAL DETAIL
ML-KEM-1024NIST FIPS 203 · Post-QuantumPOST-QUANTUM KEMPost-quantum key encapsulation layered on Curve25519 via WireGuard's pre-shared key slot. Both classical and post-quantum keys must be broken simultaneously to compromise the session. NIST FIPS 203 standardised, same as DAVEY_JONES_LOCKER.
WireGuardRFC-quality · Formally VerifiedFORMALLY VERIFIED~4,000 lines of audited kernel-space code. Formally verified cryptographic model. No legacy cipher suite negotiation. One algorithm, one implementation, one attack surface.
ChaCha20-Poly1305RFC 8439 · AEADAUTHENTICATED ENCRYPTIONSymmetric encryption of all tunnel traffic with integrated authentication. 256-bit keys, considered quantum-resistant under Grover's algorithm. Protects against both eavesdropping and packet tampering.
Curve25519RFC 7748 · ECDHELLIPTIC CURVE DHClassical elliptic-curve key exchange. Per-session ephemeral keys. Paired with ML-KEM-1024 in a hybrid model: classical security today, post-quantum hardened for the future.
BLAKE2sRFC 7693 · Keyed HashCRYPTOGRAPHIC HASHUsed for all keyed hashing operations in the WireGuard handshake. Faster than SHA-2 in software; constant-time implementation resistant to timing side-channels.
Perfect Forward SecrecyECDH + ML-KEM Ephemeral KeysSESSION ISOLATIONEvery session negotiates fresh ephemeral keys for both classical and post-quantum layers. Compromising one session reveals nothing about any other. Past traffic is permanently inaccessible.
────────────────────────────────────────────────────────────────────────────────
Post-quantum key exchange: ML-KEM-1024 layered on top of Curve25519 via WireGuard's pre-shared key mechanism; both must be broken simultaneously; a quantum computer that defeats classical elliptic-curve still hits a post-quantum lattice wall
WireGuard client: paste your config and connect; works with any WireGuard-compatible router, home network, or provider; the same protocol built into most modern routers
DNS leak protection: your DNS lookups travel inside the encrypted tunnel; your ISP cannot see what sites you visit while connected
Kill switch: if the tunnel drops unexpectedly, all internet traffic stops immediately until the tunnel is restored; nothing sneaks out unencrypted
Split tunneling: choose which apps go through the tunnel and which use your regular connection directly; route only what you want
Auto-reconnect: if the connection drops due to a network change or sleep/wake cycle, HORIZON reconnects silently without you having to do anything
No accounts required: there is no sign-up, no email, no login; install, paste your config, connect
Live connection stats: see your tunnel status, how long you have been connected, and how much data has passed through, in a live terminal-style display
Multiple config profiles: save and switch between different connection configs; home network, travel, and work all in one place
────────────────────────────────────────────────────────────────────────────────
⚠ Free to use. Single-operator license. Not for redistribution. HORIZON is provided as-is with no warranty. Use in compliance with your local jurisdiction. Operators are responsible for lawful use. HORIZON is built on the WireGuard® protocol, used under the MIT License. WireGuard® is a registered trademark of Jason A. Donenfeld.
════════════════════════════════════════════════════════════════════════════════
ACQUISITION_COST: $0.00 USD
SECURE PAYMENT VIA STRIPE · INSTANT DIGITAL DELIVERY · VERIFIED PRIVATEERS ONLY