Vantablack Logo
Vantablack
Keller Systems

Connect your computers directly. Zero middleman. No logins. Fully decentralized.

Vantablack links your home server, laptop, and cloud machines into one private network that works from anywhere. There is no account to create, no subscription, and no middleman such as Tailscale or Cloudflare sitting in the path — your devices talk to each other, encrypted end to end.

Private Network YOUR DEVICES ONLY

A closed network for your own machines, protected by your private key. Only devices you approve can join — everyone else is ignored.

Public Swarm OPEN MESH

An open mesh where devices help bounce encrypted traffic for each other. More participants make it harder to block — a practical way around censorship.

Designed for sovereignty, privacy, and durability

A resilient foundation for personal infrastructure, remote operations, and secure networking.

Infrastructure

Universal private interconnect

Connect home servers, workstations, edge hardware, and cloud VPS instances into a single flat private network. Devices find each other automatically across NAT firewalls, home routers, and changing IP addresses without opening router ports or exposing services to the public internet.

Works across any carrier or provider • Zero firewall reconfiguration required
Resilience

Multipath route dispersion

Outbound traffic is mathematically divided across multiple independent carrier paths simultaneously. A listener observing any single network link or tap sees only undecipherable random slices. Even if a link is completely severed or drops out mid-stream, remaining paths deliver the full message intact with zero retransmission delay.

Survives carrier drops and transit failures automatically
Cryptography

Post-quantum security by default

All sessions negotiate keys using hybrid post-quantum lattice cryptography (ML-KEM-768, FIPS 203) combined with classical X25519 curve algorithms, picking the strongest suite both peers support. Traffic captured today remains protected against future quantum decryption. Session master keys exist only in volatile RAM while active and are never written to disk or swap storage.

Standardized primitives • Session keys never touch disk • Formally verified (ProVerif 2.05)
Integrity

Zero central points of failure

No central servers, user accounts, or company databases exist to be compromised, seized, or subjected to downtime. Nodes authenticate each other directly via cryptographic public keys, with no third-party coordinator or vendor middleman in the data path.

Zero telemetry • No analytics • Self-organizing mesh operation
Storage & DTN

Autonomous dead-drop vaults

Store and exchange encrypted data asynchronously without central servers or rendezvous points. Destinations are addressed by cryptographic hash commitments; hosts store blind ciphertext with zero knowledge of content or recipients, while adaptive Poisson decay and Merkle anti-entropy reconcile partitions automatically.

Serverless blind storage • Merkle blackout reconciliation • Zero metadata at rest
Physical Anchors

Fallbacks below the internet

When every terrestrial path is gone — fiber cut, ISP blackout, jammed spectrum — two optional anchors extend the reachability ladder past the public internet: an HF/NVIS ionospheric radio carrier, and a quantum-entanglement anchor that brings out-of-band key material into the session ratchet — simulated by default, or from a real ETSI GS QKD 014 appliance when one is configured. Both are opt-in, both report honestly which mode they are in, and neither is required for normal operation.

Opt-in • Experimental • In-simulation by default, with a real QKD appliance backend • Never required for standard WAN operation

Physical-layer anchors

Two transports that sit below the internet on the reachability ladder. They ship today and they are off by default. The default build runs both in simulation; one production path — the ETSI GS QKD 014 client for a real QKD appliance — is built and tested against a mock appliance, but neither anchor has been verified against real radio or optical hardware.

ABOS Skywave EXPERIMENTAL — IN-SIMULATION

An HF/NVIS ionospheric carrier that becomes the last rung of the fallback ladder, chosen only after a direct path, a mesh relay, and a blinded TURN allocation have all failed. Frames cross the real ABOS DSP chain — LDPC forward error correction, DSSS/OFDM modulation — and travel over a virtual loopback channel; the SDR hardware drivers are simulation stubs. Opt in with --skywave.

QEL Quantum EXPERIMENTAL — IN-SIMULATION

A probed anchor controller that contracts a session's next ratchet epoch from out-of-band key material, with both peers proving agreement before either moves. By default it runs fidelity-constrained entanglement routing and BB84 key derivation over a live mesh topology export; the keys then come from a simulated noise model rather than a photon measurement, so the mix adds structural entropy rather than a secret. Set GHOST_QEL_BACKEND=etsi014 and it instead fetches keys from a real ETSI GS QKD 014 appliance over mutually-authenticated TLS — the configuration in which the key is genuinely secret. A route below the security cutoff yields no key at all rather than a weak one. Opt in with --quantum.

How Vantablack Compares

Vantablack was engineered from first principles to exceed WireGuard, Tailscale, Tor, and commercial VPNs simultaneously across post-quantum defense, loss resilience, and zero-trust decentralization.

Capability & Plain English Purpose VantablackSOTA WireGuard Tailscale Tor Network Commercial VPN
Post-Quantum Cryptography
Protection against future quantum supercomputers decrypting archived network traffic.
Hybrid ML-KEM-768 + ML-DSA-65 + X25519 (FIPS 203 / 204) Classical Only (Curve25519) Classical Only (Curve25519) Classical Only (Curve25519 / RSA) Classical Only (RSA / ECDH)
Network Architecture
Can the network be shut down, seized, or banned by attacking a central company or login server?
100% Serverless Autonomous Mesh (No coordinator, zero accounts, no login) Point-to-Point (Manual configuration required) Centralized (Requires Tailscale / Google / Microsoft login) Semi-Centralized (Relies on 9 Directory Authorities) Centralized (Provider servers & billing accounts)
Packet Loss & Congestion Resilience
What happens when a connection drops packets, experiences jitter, or carrier congestion?
Reed-Solomon RS(2,1) Erasure Sharding (Any 2 of 3 shards reconstruct data instantly with 0ms delay) Single Path (Retransmits dropped packets) Single Path (Retransmits dropped packets) Single TCP Circuit (Head-of-line blocking stalls stream) Single Tunnel (Connection latency stalls)
Mobile Roaming Handover (Wi-Fi → LTE)
Does your connection freeze or disconnect when leaving home Wi-Fi for mobile cellular data?
Zero-RST Silent Re-Anchor (Seamless live session migration; zero dropped frames on physical carrier) Endpoint Roaming (Requires packet exchange to update) DERP Relay Switch (Session stalls or re-handshakes) Circuit Breaks (Must negotiate brand new 3-hop circuit) Tunnel Drops (10–30 second disconnection & IP leak)
Traffic Analysis & Censor Disguise
Can an ISP, government firewall, or censor detect that you are running a VPN/mesh?
Uniform 576B Frames + Authenticated Jitter + Exponential Poisson Cover Traffic (Indistinguishable from noise) Known Packet Lengths & Handshake Headers (Trivially blocked by DPI) WireGuard Fingerprints (Easily throttled or identified) Obfs4 pluggable transports (Base Tor easily blocked) Standard OpenVPN / WireGuard / IPsec headers
Traffic Timing & Latency Controls
How does the network protect against traffic timing analysis while supporting fast real-time interactive tasks?
20ms Multi-Packet Mix Batching (Default, destroys correlation) + 1ms Low-Latency Micro-Jitter Toggle (VoIP/Gaming) Immediate Forwarding (Vulnerable to timing correlation) Immediate Forwarding (Vulnerable to timing correlation) Fixed High Latency (~300–800ms, unsuitable for real-time) Immediate Forwarding (Easily correlated by ISP/upstream taps)
Privilege & System Footprint
Does running the client require root/administrator access or kernel driver modifications?
Zero-Admin Userspace Mode (Automatic unprivileged fallback to SOCKS5 on :1080 and DNS on :1053; optional TUN driver) Requires Root / Admin Kernel Driver Requires Root / Admin Daemon & TUN Driver Userspace SOCKS (No full system TUN) Requires Admin Installer & Kernel Filter Drivers
Formal Mathematical Verification
Has the cryptographic security been proven by rigorous machine-checked mathematics?
Formally Verified via ProVerif 2.05 (Session secrecy proven: RESULT not attacker(secret) is true) Formally Verified (Noise protocol Tamarin/CryptoVerif models) Relies on WireGuard proof (Coordination plane unverified) Academic papers (Partial formal proofs) No formal protocol model
In-Memory Hardware Defense
Are keys protected in RAM against physical memory dump attacks if a computer or phone is seized?
AES-256-XTS Memory Hardening + Volatile Zeroization on Drop Kernel memory zeroing (Plaintext in RAM) Standard user-space memory Standard user-space memory Standard user-space memory
Anonymity & Egress Forwarding
Can the destination or exit node discover who originally sent the traffic?
Clean-Room 3-Hop Onion Routing (RLY!) + Ephemeral Cryptographic Vouchers None (Exit node sees true client IP) None (Exit node sees Tailscale identity) 3-Hop TCP Circuits (Slow, circuit stalls) None (VPN company sees real IP & billing identity)
Autonomous Dead-Drop Storage
Serverless Tahoe-style ciphertext storage slots with zero host metadata exposure.
Cryptographic Commitments + Adaptive Poisson Decay (§22, §33) None Centralized Coordination State Single-hop Tor Onion Mailboxes Centralized Provider Storage
Partition & Blackout Recovery
Reconnecting after prolonged network blackouts, airplane mode, or censorship cuts.
Merkle Anti-Entropy Reconciliation (O(log N) branch sync, §29) Manual Re-handshake Session Re-negotiation Circuit Rebuild Tunnel Reconnect Delay
Reachability Below the Internet EXPERIMENTAL — OPT-IN
What happens when every terrestrial path is gone — fiber cut, ISP blackout, or jammed spectrum?
HF/NVIS Skywave Carrier as the Last Rung of the Fallback Ladder + a QKD-Entropy Anchor Feeding the Session Ratchet IN-SIMULATION BY DEFAULT None (IP only) None (IP only) None (IP only) None (IP only)

Download Vantablack

Vantablack is a native desktop app with a built-in control window and system tray icon. Download the installer, run it, and flip the connect switch — no terminal, no account, and no setup wizard required.

Ready-to-run Desktop Application

Flipping the connect switch secures your traffic immediately. The native app lives in your system tray and serves a responsive control panel you can also open from any phone or device on your network.

Download for Windows (.exe) ↓ macOS • Linux Releases ↗
Zero admin privileges needed • Per-user install • Portable • Open Source • Free code signing provided by SignPath.io, certificate by SignPath Foundation

Prefer building from source or running headless?

If you are deploying to a server, Docker container, or want to compile the pure Rust engine yourself:

01 Build from source with Cargo

Vantablack compiles in seconds with zero system dependencies:

# Clone repository
git clone https://github.com/KELLERBABG/Vantablack.git
cd Vantablack

# Build and run the desktop app (window opens automatically)
cargo run --release

# Or build headless for remote servers and Docker
cargo build --release --no-default-features

On Linux the window uses system GTK/WebKit. Servers, containers and remote boxes without a display can run the headless build, which serves the identical control panel over HTTP at http://localhost:2270.

02 Optional: isolate into your private network

By default your node joins the open Public Swarm. To create an isolated private mesh, assign a shared Network ID. Nodes without matching network credentials are silently dropped at packet ingress before any handshake occurs.

# Generate a 256-bit network isolation token
openssl rand -hex 32

# Start your node in isolated network mode
export GHOST_PSK=<paste-your-token>
ggn

Use the same Network ID token across your cluster. All data streams inside the network are independently encrypted per session with forward-secret ratchets.

03 Send your traffic through it — or just use the window

The app window is the control panel: flip the Connect switch and your traffic is protected. Apps that speak SOCKS can also point at the built-in local proxy (on by default), and if you would rather use a browser, the same panel is served at http://localhost:2270. To watch the whole thing work under simulated real-world network conditions, start the Docker demo.

# Route a request through the encrypted network
curl --socks5 127.0.0.1:1080 https://checkip.amazonaws.com

# Browser control panel (same UI as the desktop window)
open http://localhost:2270

# Or run the multi-hop network demo with a live dashboard
docker compose -f docker-compose.wan.yml up -d
open http://localhost:8080

Want the byte-level details?

Packet formats and byte-offset tables, kernel-level network simulation benchmarks, cryptographic design specifications, and audit notes all live in the technical documentation.