Server inventory
Country, city, provider, ownership model, exit capability, and service status.
ClearGlassInc · Secure Connectivity
ClearGlass Shield is designed as a privacy-first secure connectivity platform: minimized identity collection, encrypted transport, leak controls, verifiable infrastructure, and a separate enterprise security plane.
01 · ClearGlass Proof
The product differentiator is operational evidence rather than stronger marketing language. Planned public proof includes infrastructure, build, audit, incident, and disclosure records.
Country, city, provider, ownership model, exit capability, and service status.
Client and gateway release hashes, signing-key fingerprints, and SBOM publication.
Audit scope, findings, severity, remediation state, and completion date.
Quarterly transparency reporting and aggregate legal-request statistics.
Public vulnerability-reporting process, security contact, and advisories.
Instructions and evidence for reproducible desktop client builds.
02 · Private
| Capability | Proposed design | Constraint |
|---|---|---|
| Access identity | Random ClearGlass Access ID; email optional | Recovery choices must not quietly recreate identity linkage. |
| Transport | WireGuard-first; compatibility protocols only where necessary | Protocol support follows platform and threat-model requirements. |
| Network Lock | Default kill switch, DNS leak protection, IPv6 protection, reconnect guard | Must be validated with automated leak tests before claims. |
| Secure DNS | Encrypted in-tunnel resolver; no query-history retention in Private mode | Operational data flows must be mapped and independently reviewed. |
| Split tunneling | Per-app and per-domain controls | Platform-specific routing behavior requires separate validation. |
| Veil | Optional padding, timing variation, fixed packet sizing, multi-hop | Reduces some observable signals; does not guarantee traffic-correlation resistance. |
03 · Architecture
WireGuard / compatible transportskill-switch · DNS/IPv6 controlsprivacy/performance tradeoffverify · don't merely trustSigned image → reproducible build → independent verification → staged rollout → automatic rollback.
Authentication and payment systems remain logically separate from gateway operations; gateway design does not depend on persistent activity histories.
04 · Shield Teams
The business product is not marketed as consumer “zero telemetry.” Organizations need controlled security events, administrator accountability, and exportable evidence.
SAML/OIDC SSO, SCIM, passkeys, TOTP, and hardware security keys.
Device posture checks, private gateways, dedicated egress, and access policy.
SIEM export, customer-defined retention, administrator audit trail, API and Terraform support.
05 · Proposed packaging
Pricing is a target, not an active offer. Checkout, subscriptions, billing, service-level commitments, and product availability remain disabled until the underlying product and compliance controls exist.
06 · Safeguards
A VPN cannot eliminate browser fingerprinting, account linkage, malware, payment records, endpoint compromise, or sophisticated traffic correlation.
The no-logs position is a future claim that must follow actual data-flow mapping, operations design, and independent audit evidence.
ClearGlass Shield will not copy another provider's source code, copywriting, visual identity, trademarks, product names, or unsupported claims.