CryptoServers

Self-hosted VPN server in Switzerland

Run your own WireGuard or OpenVPN egress on hardware you control — no shared concentrators, no third-party logs, no lifetime-deal asterisks.

No KYC DMCA ignored Crypto only 60-second deploy
1 Tbps
DDoS absorption
41s
Median deploy
Zürich (CH-ZRH)
Datacenter
$16.99
Entry plan / month
Why Switzerland

The Switzerland case for Self-hosted VPN server

Switzerland is the strongest privacy-law jurisdiction we operate. The Federal Act on Data Protection (FADP, revised 2023) puts the onus on the data controller, not the host. Swiss court orders are required to compel any disclosure; foreign DMCA notices have no statutory effect at all. Network is Tier-1 with direct peering to Frankfurt, Milan, and Paris. Zürich is the comfortable pick for workloads where the legal posture matters as much as the throughput: mail servers, financial nodes, journalist infrastructure.

WireGuard, OpenVPN, Shadowsocks, Outline and Tailscale exit nodes are all permitted, with raw socket access on every plan and IPv6 announced by default. Because we publish the AS-path, your VPN egress IP isn't a known commercial-VPN range — apps that block major VPN providers won't auto-flag you.

Workload alignment

What Self-hosted VPN server gets from Switzerland

Full root, kernel modules permitted, raw sockets allowed. Required for WireGuard tun/udp.
IPv4 + /64 IPv6, BGP announcements on dedicated tiers if you bring your own range.
Egress IPs not part of any commercial VPN range — fewer apps auto-flag the traffic.
AES-NI on every CPU tier. WireGuard saturates 1 Gbps on a single core on Starter.
No traffic mirroring, no netflow retention beyond 24 hours. Documented on /privacy/.
Sysadmin FAQ

Self-hosted VPN server in Switzerland — questions answered

WireGuard or OpenVPN — does it matter which I run?
WireGuard is faster (kernel module on Linux 5.6+, hard to beat for raw throughput) and uses less CPU. OpenVPN is more permissive about NAT traversal and has older client support. Both work fine; we don't restrict either.
Will major sites detect this as a VPN and challenge me?
Less than commercial VPN ranges, but it isn't magic. Cloudflare and others increasingly fingerprint based on TCP/IP characteristics, not just IP reputation. If you're hitting CAPTCHAs everywhere on a particular IP, we re-IP you to a fresh /29 within the same prefix free of charge.
How many peers can a vps-growth handle?
Empirically 50–80 active WireGuard peers with light traffic, or 30–40 with sustained 5 Mbps each. Memory is the gating factor at scale, not CPU; WireGuard is cheap. If you outgrow it, vps-business at 16 GB DDR5 takes you to ~250 peers.
Can I announce my own /29 or /48 over BGP?
Yes — on dedicated tiers (ded-bastion and up). VPS plans share our prefixes. You bring an LOA and the IRR records; we provision the session within a day.
What logs do you keep on the host?
Billing records, panel actions (provisioning, reboots), and 24-hour ARP/MAC tables. No netflow, no NIC mirrors, no traffic captures of any kind. Full text is in /privacy/.

Deploy Self-hosted VPN server in Switzerland

From $16.99/month, paid in crypto, no email or ID required.