The post-quantum VPN that's on by default
A post-quantum VPN protects the key behind your tunnel with math that quantum computers can't break, so traffic someone records today can't be decrypted later. Secria VPN adds an ML-KEM-1024 key to every WireGuard session, on by default, on every server. Nothing to switch on.

Why it matters now
Recorded today, readable tomorrow
A post-quantum VPN is about the traffic you send now, not a threat that starts later.
Harvest now, decrypt later
Encrypted traffic can be copied and stored for years. When a large enough quantum computer exists, the key exchange behind most VPNs today can be broken and the stored traffic read. This is called harvest now, decrypt later.
The standard is final
NIST published ML-KEM, its post-quantum key exchange standard, as FIPS 203 in August 2024.1 Waiting for a quantum computer to show up first means the traffic you send until then is already exposed.
WireGuard alone isn't enough
WireGuard agrees its keys with Curve25519, which a quantum computer could break. WireGuard leaves an optional pre-shared key slot for exactly this reason.2
A VPN carries everything
One tunnel holds your browsing, apps and messages in a single stream, which makes it a valuable thing to record. Read what your ISP can see without a VPN.
How Secria does it
ML-KEM-1024 in every WireGuard handshake
Your device makes a one-time key
When you connect, the app creates a fresh ML-KEM-1024 key pair and sends the public half over a hybrid post-quantum TLS connection.
The server seals a new secret
The server creates a random 32-byte preshared key for your session and returns it sealed with your ML-KEM-1024 key. It never travels in the clear.
WireGuard mixes it in
Both sides load that key into WireGuard, which mixes it into every handshake. Breaking the session now takes breaking ML-KEM-1024 as well as Curve25519.
A new key is made on every connect. It is hybrid, so you are never less safe than with plain WireGuard. The full design is in our VPN whitepaper5, and what ML-KEM is explains the algorithm in plain words.
Setting or default
Post-quantum you don't have to find in the settings
More VPNs now offer post-quantum protection. How it is switched on is where they differ.
| Question | Common today | Secria VPN |
|---|---|---|
| Turned on | Often a setting you enable yourself.34 | On by default. Nothing to switch on. |
| Protocols covered | Often one protocol only.3 | Every connection uses the post-quantum WireGuard tunnel. |
| Servers covered | Can switch off on some server types.3 | Every server. There is no cheaper tier of server to be routed onto. |
| Beyond the tunnel | Varies by provider. | Hybrid post-quantum TLS on the app's API, ML-DSA server checks and SLH-DSA signed downloads. |
| Strength | Varies by provider. | ML-KEM-1024, the strongest of NIST's three ML-KEM levels. |
- NIST, FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (August 2024).
- WireGuard, Protocol and cryptography: the optional pre-shared key exists “for, say, post-quantum resistance.”
- NordVPN, Post-quantum encryption explained (NordVPN Help Center). Enabled in settings, NordLynx protocol only.
- IVPN, Quantum-resistant VPN connections (IVPN Help).
- Secria, Secria VPN technical whitepaper, sections 4 to 8.
Checked September 2026. Secria facts are from our VPN page and whitepaper.
The rest of the VPN
Post-quantum is where it starts
Want the basics first? Read why you actually need a VPN.
No activity logs
We do not record browsing, DNS queries or traffic contents. While a session is live we hold the account and device it belongs to, the server in use and the time it started. That record goes when the session ends.
RAM-only servers
Every server runs from memory. Keys, configs and connection state are never written to disk. See how a RAM-only VPN works.
Multi-hop
Route through three servers so no single one knows both who you are and where you are going.
Kill switch
An OS-level kill switch blocks all traffic the moment the tunnel drops.
Private DNS
Lookups are resolved on our own servers with DNSSEC, never handed to a third-party resolver.
Split tunneling
Choose what goes through the VPN and what uses your normal connection.
Post-quantum on every plan
VPN Plus on its own, or with Secria Mail in Pro. Same VPN either way.
VPN Plus
$7.99/mo
The full Secria VPN on 5 devices: post-quantum on every server, RAM-only servers, multi-hop, kill switch, private DNS and split tunneling.
Get VPN PlusSecria Pro
$9.99/mo
The same VPN plus Secria Mail with 500 GB, unlimited aliases and 10 custom domains, in one account.
Get Secria ProMonthly prices shown. Yearly and 2-year plans cost less per month. Compare all plans
30-day money-back on plans bought here. App Store and Google Play purchases follow their own refund rules.
Questions about post-quantum VPNs
What is a post-quantum VPN?+
A VPN whose key exchange uses an algorithm designed to resist quantum computers, such as ML-KEM. It protects traffic recorded today from being decrypted once large quantum computers exist. Secria VPN adds an ML-KEM-1024 key to every WireGuard session.
Is quantum-resistant the same as quantum-safe or post-quantum?+
In VPN marketing, yes. All three describe cryptography meant to hold up against quantum computers. Post-quantum is the term standards bodies like NIST use.
Do I need a post-quantum VPN if quantum computers aren't here yet?+
The risk is to traffic recorded now and decrypted later, so protection only helps if it is on before that traffic is sent. Learn more in what post-quantum encryption is.
Is WireGuard quantum resistant?+
Not on its own. WireGuard agrees keys with Curve25519, which a quantum computer could break. It supports an optional pre-shared key, and a post-quantum VPN fills that slot with a key exchanged using an algorithm like ML-KEM.
Does post-quantum encryption slow down a VPN?+
Not in normal use. In Secria VPN the post-quantum key is added at the handshake, not in the data path, so you get WireGuard speed.
Is post-quantum on for every Secria VPN server?+
Yes. Every server runs the same post-quantum tunnel, and it is on by default for every connection. There is nothing to turn on.
Your connection, sealed for the long run. Post-quantum on every server, from your first connection.
iOS, Android, Windows, macOS and Linux. 30-day money-back.