Your app's outbound IP.
Permanent.

A dedicated IPv4 address your partners can allowlist, delivered over a tunnel to the servers you already run. Works on AWS, Kubernetes, Heroku, a laptop.

Address space we hold ourselves and announce from our own AS — not a slice of somebody else's shared proxy pool.

AS41800 · 194.0.108.0/22 · 2a05:d840::/29 · RIPE NCC member

“Send us your static IPs and we'll allowlist them.”

The sentence that stops an integration. Your bank, insurer or enterprise customer needs a fixed address. Your platform does not have one to give.

AWS Lambda, Cloud Run, Fargate

Outbound traffic leaves from a pool of shared addresses that changes without notice. Your customer cannot allowlist a moving target.

Kubernetes

Every node egresses as itself. Add a node, and the partner firewall you spent three weeks getting through starts rejecting you.

Heroku, Render, Railway

No static outbound IP at any price. The integration is blocked on infrastructure the platform does not sell.

How it works

Four steps. None of them involve talking to us.

  1. 1

    Order

    Pick a plan. No sales call, no quote, no contract to negotiate.

  2. 2

    Pay

    Bank transfer against an invoice. Access opens when funds arrive.

  3. 3

    Install

    One config file. wg-quick up, and you are done.

  4. 4

    Ship

    Your traffic leaves as your address. It does not change again.

# on the machine that needs the address
sudo cp anchoredip-1.conf /etc/wireguard/wg0.conf
sudo wg-quick up wg0

curl -4 ifconfig.me
194.0.108.128          # yours, and it stays yours

The default configuration routes only traffic from your leased address through us. Your default route, your SSH session and everything else on the machine are left alone.

What you get

A dedicated IPv4 address

Assigned to you alone. Nobody else sends traffic from it, so nobody else can damage its reputation.

An IPv6 /48 with every plan

65 536 subnets. Every machine gets a globally routable address of its own, with no NAT in the way.

A private network between your machines

Your app in Frankfurt and your worker in Singapore reach each other over the tunnel. Bind the service to that address and it is published to nobody.

Reverse DNS you control

PTR records set from the dashboard. Missing or wrong ones break more integrations than people expect.

WireGuard or AmneziaWG

Same crypto. AmneziaWG adds obfuscation, so the handshake is not recognisable to deep packet inspection.

Addresses that are checked before you get them

Every address is screened against blocklists before assignment, and re-checked daily afterwards.

Pricing

Published, fixed, the same for everyone. From $0.

Loading plans…

What is in every plan, and what happens if you lapse →

Where this is the wrong tool

Cheaper to read now than to find out after you have integrated.

One routing location, in Kazakhstan

Traffic through us adds latency proportional to the detour. For allowlisted API calls a few times a minute this is invisible. For a chatty database protocol between two continents it is not. Additional locations follow demand.

Machines reach each other through us, not directly

The private network is hub and spoke. Fine for job queues, control traffic and admin access; wrong for bulk transfer between your own machines.

One inbound address per lease

Every machine on a lease sends as the same address, but only one can receive connections on it. That is how IP routing works, not a limitation we chose.

Outbound mail needs a conversation first

Sending mail from a fresh address without warming it damages the block for everyone on it. Ask before you start, and we will tell you honestly whether it is a fit.

We are the operator, not a reseller

The address space is registered to us at the RIPE NCC and announced from our own autonomous system. There is no upstream who can decide tomorrow that your address belongs to someone else.

Autonomous system
AS41800
IPv4
194.0.108.0/22
IPv6
2a05:d840::/29
Registry
RIPE NCC

Your addresses are routed to you inside our /24 announcements over a point-to-point tunnel. Small blocks are not announced separately — that keeps the global routing table clean and your reachability predictable. BGP sessions are available if you want to run routing yourself, and are not required otherwise.

Stop explaining why your IP changed.

Pick a plan, pay, install one file. Nothing to schedule and nobody to call.

Get your static IP