Swiss Shield: Double-Hop Privacy
Every connection passes through Switzerland first. Two servers. Two layers of encryption. Zero logs.
Included in Plus and Pro plans Β· No extra cost Β· Automatic routing
Two Hops. Two Layers. One Seamless Connection.
Swiss Shield routes your traffic through two encrypted WireGuard tunnels automatically. You just pick your exit country.
Your Device
Traffic is encrypted and sent through the first WireGuard tunnel to Switzerland.
Swiss Server (Zurich)
Traffic arrives encrypted. The Swiss server forwards it through a second WireGuard tunnel. It never sees your content.
Exit Server
Decrypts the outer layer and routes traffic to the internet. Only sees a Swiss IP β never your real one.
Destination
The website sees only the exit server's IP address. No trace of you or Switzerland.
What Each Party Can See
| Who | What they see | What they DON'T see |
|---|---|---|
| Your ISP | Encrypted traffic to Switzerland | Your actual destination |
| Swiss Server | Encrypted traffic from you, encrypted traffic to exit | Actual content β just forwards encrypted packets |
| Exit Server | Traffic from a Swiss IP, destination website | Your real IP address |
| Destination website | Exit server's IP address | You, Switzerland, or your ISP |
| An attacker | Would need to compromise TWO servers in TWO countries simultaneously | Good luck. |
Why Two Hops?
A single compromised server exposes your traffic. Two servers in different jurisdictions makes correlation attacks near-impossible.
Double Encryption
Two separate WireGuard tunnels with different encryption keys. Compromising one server reveals only encrypted traffic heading to the other.
Two Jurisdictions
Different countries mean different legal systems and different court orders required. No single government can compel access to both servers.
Swiss First Hop
Protected by the Swiss Federal Data Protection Act. Switzerland won't comply with bulk foreign surveillance requests.
Zero Logs On Both
Even with physical access to either server, there is nothing to find. No connection logs, no traffic logs, no timestamps.
Separate Encryption Keys
Each hop uses independent keys. Compromising one server does not expose the other tunnel's traffic.
Correlation Resistance
An attacker would need simultaneous access to both servers in different countries with different legal systems. That is not realistic.
Why Switzerland as the Entry Point?
Switzerland is not just a pretty flag on a website. It provides real, meaningful legal protection for your first hop.
Swiss Privacy
Your first hop is always protected by Swiss law. Even if the exit country has weaker privacy protections, your identity remains shielded behind Switzerland.
FADP Protected
Independent Courts
No Bulk Surveillance
No Data Retention
Fast Enough That You Won't Notice
WireGuard is ultra-fast. Two hops add only 10-20ms of latency β still faster than most single-hop OpenVPN connections.
~15ms
Added Latency
Two hops, barely noticeable
Full
Bandwidth
Each tunnel runs at full speed
10 Gbps
Swiss Backbone
Premium European infrastructure
< 1s
Connection Time
WireGuard connects instantly
Protocol Comparison
OpenVPN (single hop)
~80ms
Slower protocol overhead
WireGuard (single hop)
~12ms
Fast and lightweight
Swiss Shield (double hop)
~25ms
Two hops, still faster than OpenVPN
When to Use Swiss Shield
When single-hop just isn't enough.
Journalists
Protect your sources with two layers of separation between you and the content you access.
Business Travellers
Travelling through high-surveillance countries? Swiss Shield ensures your corporate data stays private.
Maximum Privacy
For anyone who wants the strongest possible protection for their everyday browsing.
Enhanced Privacy for Sensitive Browsing
Add an extra layer of privacy for banking, medical research, or any sensitive online activity β your real location stays completely hidden.
Activists & Whistleblowers
Two jurisdictions and two encryption layers make traffic correlation practically impossible.
High-Threat Environments
When the stakes are high, double-hop provides defense in depth against sophisticated adversaries.
Single Hop vs Swiss Shield
Swiss Shield is included in Plus and Pro plans at no extra cost.
Standard Connection
Fast, reliable, good privacy
- Single encrypted tunnel
- One server jurisdiction
- Zero logs
- WireGuard speed
- Double encryption
- Two-jurisdiction protection
- Correlation attack resistance
Available on all plans
Swiss Shield
Maximum privacy, two-hop protection
- Double encrypted tunnel
- Two server jurisdictions
- Zero logs on both servers
- WireGuard speed on both hops
- Double encryption
- Two-jurisdiction protection
- Correlation attack resistance
Included in Plus and Pro plans
Entry Is Always Switzerland. Exit Is Your Choice.
Choose from our growing list of exit server locations around the world.
Swiss Entry Server
Zurich, Switzerland β always your first hop
Your Exit Server
Any location you choose
Frequently Asked Questions
Activate Swiss Shield Today
Two servers. Two layers of encryption. Two jurisdictions. Zero logs. The strongest online protection available.
View Plans & Get Protected