ClearGlassInc · Secure Connectivity

Privacy you can verify.

ClearGlass Shield is designed as a privacy-first secure connectivity platform: minimized identity collection, encrypted transport, leak controls, verifiable infrastructure, and a separate enterprise security plane.

Request private-beta informationView ClearGlass Proof
Development status: product concept / architecture stage. This page does not represent an operating VPN service, active no-logs certification, completed audit, or available subscription. Do not purchase or rely on the proposed claims until the corresponding controls are implemented and independently verified.

01 · ClearGlass Proof

Trust should be inspectable.

The product differentiator is operational evidence rather than stronger marketing language. Planned public proof includes infrastructure, build, audit, incident, and disclosure records.

Infrastructure

Server inventory

Country, city, provider, ownership model, exit capability, and service status.

Release integrity

Signed artifacts

Client and gateway release hashes, signing-key fingerprints, and SBOM publication.

Assurance

Audit trail

Audit scope, findings, severity, remediation state, and completion date.

Transparency

Privacy reports

Quarterly transparency reporting and aggregate legal-request statistics.

Security

Disclosure program

Public vulnerability-reporting process, security contact, and advisories.

Reproducibility

Build verification

Instructions and evidence for reproducible desktop client builds.

02 · Private

Designed to minimize what must be known.

CapabilityProposed designConstraint
Access identityRandom ClearGlass Access ID; email optionalRecovery choices must not quietly recreate identity linkage.
TransportWireGuard-first; compatibility protocols only where necessaryProtocol support follows platform and threat-model requirements.
Network LockDefault kill switch, DNS leak protection, IPv6 protection, reconnect guardMust be validated with automated leak tests before claims.
Secure DNSEncrypted in-tunnel resolver; no query-history retention in Private modeOperational data flows must be mapped and independently reviewed.
Split tunnelingPer-app and per-domain controlsPlatform-specific routing behavior requires separate validation.
VeilOptional padding, timing variation, fixed packet sizing, multi-hopReduces some observable signals; does not guarantee traffic-correlation resistance.

03 · Architecture

Separate the private path from the control plane.

Shield ClientWindows · macOS · Linux · iOS · Android
WireGuard / compatible transports
Trust GatewayImmutable signed image, hardened runtime, secure boot and attestation targets.
kill-switch · DNS/IPv6 controls
Veil LayerOptional traffic-shaping and multi-hop mechanisms for defined threat models.
privacy/performance tradeoff
Proof LayerPublic inventory, signed artifacts, audit evidence, incident history.
verify · don't merely trust

Production change discipline

Signed image → reproducible build → independent verification → staged rollout → automatic rollback.

Data minimization

Authentication and payment systems remain logically separate from gateway operations; gateway design does not depend on persistent activity histories.

04 · Shield Teams

Enterprise security requires explicit telemetry.

The business product is not marketed as consumer “zero telemetry.” Organizations need controlled security events, administrator accountability, and exportable evidence.

Identity

SAML/OIDC SSO, SCIM, passkeys, TOTP, and hardware security keys.

Device trust

Device posture checks, private gateways, dedicated egress, and access policy.

Customer control

SIEM export, customer-defined retention, administrator audit trail, API and Terraform support.

05 · Proposed packaging

Simple value ladder. No false availability.

Shield Private

$6/mo
  • 7 devices
  • WireGuard-first
  • Network Lock
  • Secure DNS

Shield Veil

$10/mo
  • 10 devices
  • Veil modes
  • Multi-hop
  • Port forwarding target

Shield Teams

$12/user/mo
  • SSO + MFA
  • Device trust
  • Policy controls
  • SIEM export

Pricing is a target, not an active offer. Checkout, subscriptions, billing, service-level commitments, and product availability remain disabled until the underlying product and compliance controls exist.

06 · Safeguards

Claims are gated by evidence.

No anonymity guarantee

A VPN cannot eliminate browser fingerprinting, account linkage, malware, payment records, endpoint compromise, or sophisticated traffic correlation.

No “no logs” shortcut

The no-logs position is a future claim that must follow actual data-flow mapping, operations design, and independent audit evidence.

No imitation

ClearGlass Shield will not copy another provider's source code, copywriting, visual identity, trademarks, product names, or unsupported claims.