Dynamic WireGuard routing

Connect once.
Your exit moves when it needs to.

A standard VPN pins you to one gateway. wgorch keeps your device on a stable entry and steers each device's exit live — by load, by your preference, and away from any gateway that falters — in under a second, without dropping your tunnel.

keys generated on your device · WireGuard kernel data plane · no traffic proxied through us

EU · HelsinkiUS · New YorkASIA · SingaporeENTRYDEVICE

How it works

Three moving parts, one that actually moves.

  1. 01

    Connect to a stable entry

    Your device holds one WireGuard peer to a nearby entry gateway. That endpoint doesn't move, so the tunnel stays up.

  2. 02

    We steer your exit

    The control plane picks each device's exit by load and your preference, and programs it live with policy routing — no interface restart.

  3. 03

    Failover in under a second

    When a gateway degrades, only the affected devices are rerouted to a healthy exit. Everyone else is untouched.

Per-device routing

Every device gets its own exit decision, isolated from the rest. Move one without touching the others.

Region & exit selection

Choose an entry region and a preferred exit where your plan allows, or let the balancer decide.

Live health failover

Continuous gateway health checks reroute you off anything unhealthy, automatically.

Your keys, your device

Private keys are generated on the device and never sent to us — we only ever see your public key.

Config & QR in a click

Download a ready WireGuard config or scan a QR straight into the app. Rotate or revoke anytime.

Cluster & transit ready

Exits can egress locally or hop an encrypted transit overlay to a sister node in another region.

<1s

to reroute a device's exit, live

0

interface restarts during reroute

1:1

per-device isolation — one move never touches another

Route smarter, not harder.

Spin up a device in minutes. Pick a region, download a config, scan a QR — and let the control plane keep your exit healthy.