Post-Quantum · ML-KEM768 + Classic-McEliece

Post-quantum VPN.
Every server. Every plan.

Draco protects your traffic against the quantum computers of tomorrow — today. WireGuard for speed, Rosenpass for a hybrid post-quantum handshake, on RAM-only servers that keep no logs. Not a premium add-on. The whole network.

Free tier · no credit card · 30-day money-back on paid
21 locations 🇺🇸 US🇨🇦 Canada🇲🇽 Mexico 🇨🇱 Chile🇬🇧 UK🇫🇷 France 🇪🇸 Spain🇩🇪 Germany🇳🇱 Netherlands 🇨🇭 Switzerland🇸🇪 Sweden🇵🇱 Poland 🇮🇱 Israel🇿🇦 South Africa🇮🇳 India 🇭🇰 Hong Kong🇸🇬 Singapore🇰🇷 South Korea 🇯🇵 Japan🇦🇺 Australia
A VPN built for the quantum era
Every design choice serves one goal: privacy that survives the next decade, not just this one.

Post-quantum handshake

A hybrid Rosenpass exchange — ML-KEM768 and Classic-McEliece layered over WireGuard's X25519 — so a future quantum computer can't unlock today's captured traffic.

21 locations, 20 countries

A hand-picked footprint across privacy-friendly jurisdictions and major business hubs — from Frankfurt and Zurich to Tokyo and Sydney. More added by the week.

RAM-only, seizure-resistant

Every exit runs diskless from a tmpfs root. Keys and state live only in memory; a reboot wipes the box. A pulled or imaged drive yields nothing.

No logs by construction

The exits keep no disk to log to. The control plane holds only your account and entitlement — never your traffic, never your DNS. Privacy that's structural, not just a policy.

One-tap connect

Pick a location or hit Quick Connect and Draco brings up the tunnel in a second. Your keys are generated on-device — the control plane never sees a private key.

Stealth mode — DPI-resistant

Flip on Stealth and Draco's traffic is shaped to look like ordinary encrypted internet, so deep-packet-inspection firewalls on restrictive networks can't fingerprint or block the VPN. Leave it on Auto and it turns on by itself wherever a network needs it — the post-quantum handshake rides underneath, unchanged.

Captive-portal aware

Hotels, airports and campus Wi-Fi hijack your first connection to a sign-in page — where ordinary VPNs get stuck fail-closed. Draco detects the portal, lets you log in, then brings the tunnel up automatically. It can even connect the moment you sign in to your device. No mainstream VPN does this.

Included with URSA

Every URSA Secure Mobile OS license and every paid Lyra seat carries full Draco — all locations, no extra charge. One account, one post-quantum backend.

Why post-quantum, why now
The threat isn't a future one. It's a record-now one.
A classical VPN

✕ Encrypted for today only

  • Key exchange rests on elliptic-curve / RSA math
  • A quantum computer breaks that math retroactively
  • Traffic captured today can be decrypted later
  • Post-quantum is a roadmap item, one protocol at a time
  • Logs and disks are a policy promise, not a design
Draco

✓ Encrypted for the next decade

  • Hybrid handshake — ML-KEM768 + Classic-McEliece + X25519
  • Quantum-safe on every server, every plan, today
  • Harvest-now-decrypt-later attacks get nothing usable
  • PQC is the default, not a premium tier
  • No-log is structural — the exits keep no disk

Harvest now, decrypt later

Adversaries are already recording encrypted traffic in bulk, betting that a large enough quantum computer will one day unlock it. A classical VPN doesn't protect against that bet — the ciphertext is copied while the key math is still breakable. Draco closes the window: with a post-quantum hybrid handshake on every connection, the data captured today stays sealed even against the machines of tomorrow.

Your whole network, one screen

Draco's app is deliberately simple: a live map, a list of every location with real latency, and one big button. The complexity — the post-quantum key exchange, the peer reconciliation, the kill-switch — happens underneath.

  • Live server map with per-location latency and load
  • Quick Connect, or pick a country by hand
  • A visible PQC badge on every active session
  • Free and paid locations in one honest list
Get Draco
Draco — Post-Quantum VPN
Cryptography you can name
Standards-based, hybrid by design — classical and post-quantum layered so you're never worse off than a classical VPN, and always ahead of one.
ML-KEM768 · FIPS 203 post-quantum KEM
Classic-McEliece · conservative PQ KEM
X25519 · classical hybrid layer
WireGuard · fast modern data channel
Rosenpass · PQ key-exchange daemon
RAM-only exits · no disk, no logs

On FIPS: the default profile is tuned for the strongest known post-quantum resistance — two independent PQ KEMs (ML-KEM768 and Classic-McEliece) over WireGuard — and those primitives are deliberately not the FIPS-approved set. A FIPS-mode profile (AES-256-GCM, ML-KEM-768, SHA-384) is available for regulated customers who require it. Post-quantum module validation is in process industry-wide: no CMVP certificate yet covers ML-KEM or ML-DSA, from any vendor.

How Draco compares
The leading VPNs got the fundamentals right — no-logs, kill-switch, audits. Draco keeps all of that and adds what none of them ship by default: post-quantum encryption on every server — plus DPI-resistant Stealth that keeps the quantum-safe handshake, and captive-portal auto-connect.
Proton VPN Mullvad NordVPN ExpressVPN
Post-quantum encryption on every server, every plan PartialWireGuard only, rolling out Partialexperimental
Named PQ algorithms ML-KEM + Classic-McEliece
No-logs, RAM-only exits
WireGuard data channel Lightway
DPI-resistant Stealth mode defeats VPN-blocking firewalls post-quantum preserved classical classical classical classical
Captive-portal auto-connect hotel / airport / campus Wi-Fi signs in, then tunnels Partialdetects only
Free tier
Paid price entry annual, per month $3.99 $4.99 $5.00 $3.39 $6.67
Included with a secure device URSA OS & paid Lyra
Kill switch & DNS-leak protection

Competitor details reflect each provider's publicly documented posture at the time of writing and are provided for honest comparison. Draco is the only one where the post-quantum handshake is the default on every server and plan — not an opt-in, a beta, or a premium tier.

Get Draco
One post-quantum account across every device.
Desktop & web

Intel Mac, or want one build for both? Download the universal macOS build (Apple silicon + Intel, signed & notarized).

Linux — one line, auto-detects Intel or ARM (Debian · Ubuntu · Kali · Raspberry Pi):  curl -fsSL https://draco.ursamobile.com/install.sh | sudo sh  · ARM64 / Pi direct: .deb · .tar.gz

Mobile
TV & streaming
Browser extension · route only your browser through a post-quantum exit, independent of the system VPN

The browser extension needs the small local Draco helper to keep the browser hop post-quantum — it ships in the desktop app, or grab it standalone: Linux helper (Windows/macOS helpers ship in their desktop installers). One-click install from the Chrome Web Store, Edge Add-ons and Firefox AMO — or load the packaged .zip unpacked. Safari can't run a proxy extension (Apple restricts the proxy API) — on Apple devices the system Draco app protects Safari and every app.

Simple, honest pricing
Post-quantum encryption on every plan — never held back behind an upgrade. Pay only for more locations and unlimited use.
Monthly Annual · save 40% 2-year · best value
Free
$0
The funnel — try post-quantum
  • Full post-quantum handshake
  • 1–2 locations
  • RAM-only, no-log exits
  • One-tap connect
  • No credit card
Get started
Paid · Most popular
$9.99 /mo
billed monthly
  • Everything in Free
  • All 21 locations
  • Unlimited bandwidth
  • Post-quantum on every exit
  • 30-day money-back guarantee
Get Draco
Business
$9.99 /seat/mo
Multi-user teams · volume pricing
  • Everything in Paid, per seat
  • One account for your whole team
  • Owner console — add, assign & remove seats
  • Volume discount at 15+ seats
  • Central billing & one invoice
Get Business
Included
$0
With URSA OS or paid Lyra
  • Full Draco — all locations
  • Every URSA OS license (all seats)
  • Every paid Lyra Team member
  • One login across URSA, Lyra & Draco
  • Already yours — nothing to buy
Talk to us
Enterprise — $14 / seat / mo. Everything in Business, plus SSO & SCIM, domain registration, central admin console, priority routing & support. Volume pricing at 100+ seats. Talk to sales →
Post-quantum VPN for every seat

Buy URSA Secure Mobile OS or a paid Lyra Team and full Draco comes with it — every location, every user, quantum-safe. One of the strongest privacy stories in enterprise and government mobility, included.

Get Draco free Contact Sales
Frequently asked
The short answers.
Can I run Draco at the same time as another VPN?
Yes — with one caveat on macOS. macOS decides which VPN answers DNS by its own network service order, and an app cannot move itself up that list. If another VPN (Tailscale, for example) sits above Draco, that VPN handles your DNS lookups and may pass them to your internet provider, even though your traffic is still encrypted and still exits from the location you chose. Draco detects this and shows a red ⚠ DNS not protected badge rather than letting it pass silently. To fix it: run tailscale set --accept-dns=false (your tailnet keeps working; you lose short MagicDNS names), disconnect the other VPN, or use Draco Mesh — our own post-quantum device-to-device mesh — so you don't need a second mesh VPN at all. iPhone, iPad and Apple TV are unaffected: they allow only one active VPN, so Draco always answers DNS there.
What makes Draco "post-quantum"?
Draco's key exchange uses a hybrid Rosenpass handshake that combines the post-quantum KEMs ML-KEM768 (FIPS 203) and Classic-McEliece with WireGuard's classical X25519. The session keys that protect your traffic are derived from all of them, so an attacker would need to break both the classical and the post-quantum math. This runs on every server and every plan — it's the default, not an add-on.
Is Draco really included with URSA OS and paid Lyra?
Yes. Every active URSA Secure Mobile OS license — individual, business, or government — and every member of a paid Lyra Team gets full Draco: all locations, unlimited use, no extra charge. Your URSA or Lyra login is your Draco login; the entitlement is set automatically by what you own.
What's the difference between Free, Paid and Business?
Every plan gets the full post-quantum handshake and the same RAM-only, no-log exits. Free gives you 1–2 locations to try it; Paid unlocks all 21 locations and unlimited bandwidth for $9.99/mo, $71.88/yr ($5.99/mo), or ~$95 for two years ($3.99/mo), with a 30-day money-back guarantee. Business is the same $9.99/seat/mo with multi-user support — one account for your whole team, an owner console to add/assign/remove seats, central billing, and a volume discount at 15+ seats.
What is Stealth mode?
Stealth mode shapes Draco's traffic so it looks like ordinary encrypted internet, defeating the deep-packet-inspection (DPI) firewalls that restrictive networks use to fingerprint and block VPNs. It's a per-location toggle — Auto (turns on by itself only where a network needs it, the default), On, or Off — and the post-quantum handshake runs underneath it, unchanged. There's a small throughput cost, which is why it's on-demand rather than always on.
Does Draco work behind hotel / airport / campus Wi-Fi?
Yes — Draco is captive-portal aware. Those networks hijack your first connection to a sign-in page, where most VPNs get stuck. Draco detects the portal, lets you complete the sign-in, then brings the tunnel up automatically. You can also have it connect the instant you sign in to your device, so you're protected without thinking about it.
Which countries can I connect through?
The footprint is 21 locations across 20 countries — the US (east and west), Canada, Mexico, Chile, the UK, Germany, the Netherlands, France, Spain, Switzerland, Sweden, Poland, Israel, South Africa, India, Hong Kong, Singapore, South Korea, Japan, and Australia — weighted toward privacy-friendly jurisdictions and major business hubs. New locations are added on a rolling basis.
Do you keep logs?
No — and it's structural, not just a promise. Every exit server runs diskless from RAM, so there's no disk to write logs to; a reboot wipes the box entirely. The control plane stores only your account and entitlement — never your traffic, never your DNS queries, never your connection history.
Does Draco ever see my private keys?
Never. Your device generates its own WireGuard and Rosenpass keypairs locally and sends only the public keys to the control plane. The control plane brokers connections and assigns overlay IPs, but a private key never leaves your device — there's nothing to leak.