Your connection, on your terms.
A privacy-first mobile VPN for Android and iOS, built on a WireGuard core with exit nodes across multiple countries. It masks your origin address and your traffic from the networks you pass through — and it is engineered to stay reachable when those networks would rather it wasn't.
A lean, modern tunnel protocol — fast to connect, light on battery, and small enough to audit. The foundation the rest of the product is built on, rather than a legacy stack bolted together.
Traffic leaves through exit nodes in a choice of countries, so the address the wider internet sees is never the user's own. Origin and location stay the user's to disclose — or not.
Networks that throttle, filter, or interfere are the norm, not the exception. Meridian is engineered to keep a working path open and to reconnect cleanly when a link is disrupted.
This is a privacy VPN, not a DNS-blocking utility. The goal is to hide origin and traffic from the networks in between — with a minimal on-device footprint and a design that collects as little as possible.
Cafés, airports, hotels, and shared connections — networks the user has no reason to trust and no control over, where traffic is exposed to anyone else on the same link.
Users who move between countries and networks and want a consistent, private path out — regardless of what the local network permits or observes.
People who simply don't want their browsing tied to their identity by the networks and intermediaries they pass through in the course of a normal day.
A standalone consumer app — deliberately independent of the institutional stack and of the tunnels inside Nexilis's enterprise clients.
Consumer privacy VPNs — the space Meridian operates in, for context.
Built by a team whose day job is mobile security for regulated institutions — applied here to keeping a private connection open under pressure.
| Capability | Meridian | NordVPN | Proton VPN | Mullvad | Surfshark |
|---|---|---|---|---|---|
| WireGuard core | Yes | Yes | Yes | Yes | Yes |
| Kill switch / leak protection | Tested invariant | Yes | Yes | Yes | Yes |
| Independent no-logs audit | Planned | 6× audited | Yes | Raid-proven | Yes |
| Multi-country network | Regional | ~111 | Broad | Focused | Broad |
| Obfuscation / restrictive nets | Roadmap | Yes | Stealth | Bridges | Camouflage |
| Streaming unblocking | Not a goal | Strong | Moderate | Weak | Strong |
| Regional focus / sovereignty | Indonesia / SEA | Global | Swiss | Swedish | Global |
Public capability as of 2026 — provider figures move; verify before external use. On the fundamentals Meridian is at parity; the majors lead on audit track record, network breadth, and streaming. Its case rests on a leak-safety property proven by construction and a regional, security-house focus.
It is a short note for people deciding whether to put a privacy VPN in front of consumers, and on what basis. It describes what such a product actually promises, why so much of the category sells a reassuring icon rather than a verifiable property, and what it takes — technically and honestly — to earn the claim.
It is three short chapters, and it is candid in the third about how much of this product is built and how much is still ahead.
— The authors
A privacy VPN makes a simple promise. The networks a person passes through in an ordinary day — the café, the airport lounge, the hotel, the mobile carrier — should not be able to see where their traffic goes or read what it carries. In exchange for that, the user routes everything through an encrypted tunnel to an exit somewhere else, and the wider internet sees the exit, not them.
The promise is easy to state and easy to display: a padlock, a country flag, the word "connected." The property underneath is much harder, and it lives in a place the marketing never shows — the fractions of a second when the tunnel drops, the network changes, or the phone sleeps and wakes. In those seams, a carelessly built client leaks the user's real traffic in the clear, briefly and silently, while the icon still says connected. The gap between the promise and the property is exactly there.
Anyone can ship the icon. The question that separates a privacy VPN from a placebo is what happens at the seam.
The consumer VPN market is large, mature, and largely sold on assertion. The best providers — and there are genuinely good ones — back their no-logs claims with independent audits and RAM-only infrastructure, and that is real. But the marketing centre of gravity is speed, server count, and streaming, because those are the things a buyer can see. The correctness of the tunnel under stress is invisible in a shop window, so it is rarely where the competition happens.
That is an opening, not a complaint. A product that treats the seam as the point — that can demonstrate, rather than assert, that no sequence of drops and reconnections opens a leak — is competing on the one axis the category quietly under-serves. It will not out-spend the incumbents on hundred-country networks or hardened streaming. It does not need to, if it is honest about what it is for.
Meridian is built from the seam outward. Its reconnect core is a pure, testable state machine, exercised against several hundred thousand randomised transitions with no leak-window violations — a checked invariant of the code rather than a sentence on a feature page. On top of that sits a WireGuard tunnel, cloud-hosted exits in a deliberately small set of countries, and a no-logs posture built on RAM-only state, because durable session records and a credible no-logs claim cannot both be true.
Now the honesty the third chapter owes you. The reconnect core and the control plane are genuinely built and tested. The exit network is being stood up; the production tunnel is not yet wired; iOS is not yet begun; and an independent security audit and load test are the required next step before any privacy claim is made in public. This is a product with a proven spine and a body still under construction — and it is more useful to a board to hear that plainly than to be sold a finished story that isn't.
The wager is narrow and defensible: win on the correctness of the connection and the focus of the market, not on the size of the network.
The architecture, the resilience methodology, and the build plan are available on request.
The technical detail and build plan are available to qualified partners under NDA.
Every café, airport, hotel, and mobile network a user passes through can see where their traffic goes, and often what it contains. A privacy VPN exists to take that visibility away — cleanly, and without leaking at the seams.
The consumer VPN category is large and mature, and most of it is sold on a promise of trust: no-logs, audited, fast. Underneath those claims sits a harder engineering question that marketing rarely addresses — what happens in the fractions of a second when a tunnel drops, a network changes, or a device sleeps and wakes. In those windows, a poorly built client leaks the user's real traffic in the clear, silently, while still displaying a reassuring "connected" icon. The promise and the property diverge exactly where it matters most.
Meridian is built around the seam, not the icon: the correctness of the connection under stress is the product, not a footnote to it.
Two very different products are both called "mobile VPN." The first is a local filter: it takes the device's VPN slot, intercepts DNS, blocks bad domains, and never touches a server abroad. The second is a privacy VPN: it encrypts traffic and forwards it to a remote exit node in another country, hiding the user's origin address and traffic from every network in between.
Meridian is the second. Its function is to conceal origin and traffic behind exit nodes in a choice of countries — not to filter what a user can reach. That choice sets everything downstream: it means a real data plane, real exit infrastructure, and a real obligation to get the privacy properties right.
Client architecture: a pure-JVM tunnel core with a swappable backend interface, an Android service layer, and a Python control plane for address allocation, session brokering, and peer provisioning. Android first; iOS to follow.
Most VPNs assert a kill switch. Meridian's reconnect core was built as a pure, testable state machine and exercised against several hundred thousand randomised state transitions with zero leak-window violations — that is, no sequence of drops, changes, sleeps, and wakes produced a state in which real traffic could escape the tunnel. This is the difference between a claim and a property: the leak-safety is a checked invariant of the code, not a line on a feature page.
A kill switch you can describe is common. A leak-safety invariant you can test is the thing worth buying.
The comparison below is against the major consumer VPNs, on public capability as of 2026. It is deliberately honest about where a new, regionally focused entrant leads and where the incumbents' scale is real and not yet matched.
| Capability | Meridian | NordVPN | Proton VPN | Mullvad | Surfshark |
|---|---|---|---|---|---|
| WireGuard core | Yes | Yes (NordLynx) | Yes | Yes | Yes |
| Kill switch / leak protection | Yes — tested invariant | Yes | Yes | Yes | Yes |
| RAM-only / minimal state | By design | Yes | Yes | Yes | Yes |
| Independent no-logs audit | Planned | 6× (Deloitte) | Yes | Raid-proven | Yes |
| Multi-country exit network | Regional, building | ~111 countries | Broad | Focused | Broad |
| Obfuscation / restrictive nets | On roadmap | Obfuscated servers | Stealth | Bridges | Camouflage |
| Streaming unblocking | Not a goal | Strong | Moderate | Weak | Strong |
| Open-source client | Under review | Partial | Yes | Yes | Partial |
| Regional focus / sovereignty | Indonesia / SEA | Global | Swiss | Swedish | Global |
| Security-house provenance | Yes | Consumer-first | Yes | Yes | Consumer-first |
The honest reading: on the fundamentals — WireGuard, leak protection, minimal-state no-logs design — Meridian is at parity with the best. On the things that take years and capital — a six-times-audited track record, a hundred-country network, hardened streaming and censorship circumvention — the incumbents lead, and this brief will not pretend otherwise. Meridian's case rests on two axes the majors do not occupy: a leak-safety property proven by construction rather than asserted, and a regionally focused, security-house build for a market the global providers treat as an afterthought.
Competitor facts (audits, network size, protocols) summarised from provider disclosures and independent 2026 testing; figures move and should be verified before external use. "Planned" and "building" are stated as such deliberately — they are commitments, not current capabilities.
A privacy VPN's economics are dominated by data-plane egress, not by the client. "Safe on public Wi-Fi for Indonesian users" needs a small, deliberate footprint — on the order of a few points of presence, close to home — and closes very differently from "watch US streaming," which demands dozens of locations and constant IP rotation against active blocking. Meridian is scoped as the former: a focused privacy tool, not a global streaming network. Exit infrastructure is cloud-hosted; egress cost and IP reputation are treated as first-order product concerns, and each exit jurisdiction is chosen deliberately for its retention law, not for latency alone.
Each exit node subjects the service to the retention law of its jurisdiction, and some of those laws sit in direct tension with a no-logs promise. That is why exit locations are a privacy decision made deliberately, and why the operating-entity and jurisdiction structure is treated as upstream of the technical work rather than an afterthought to it.
The architecture detail, the resilience test methodology, and the infrastructure plan are available to qualified partners under NDA.
These documents render live on this page — there is no separate file to download, so what you read here always matches the current product. Deeper technical detail is available under NDA. Request a briefing.
Fifteen minutes covers the WireGuard core, the exit-node model, the resilience approach, and what distribution looks like for a consumer VPN.