IRVIO Project

OPEN SOURCE · ONE-HOP · PEER-TO-PEER VPN

02 / 06

How it works

01

Two roles. One network.

IRVIO is deliberately simple: there are only two functional roles. A node may perform either one or both at the same time.

Exit Node

An Exit Node is a regular participant that carries its own traffic while sharing its connection with others. When someone selects your node as their exit point, their encrypted traffic reaches you through a protected tunnel and enters the internet through your IP address.

The principle is simple: when you use IRVIO, you are IRVIO. The more people share their connections, the faster, stronger and more resilient the network becomes.

IRVIO is free, with no subscriptions or access fees. While you are connected to the network, your node also acts as an Exit Node and provides its internet connection to other participants. You use other participants’ exit points, and they can use yours.

Server

A Server provides distributed service infrastructure: Kademlia/DHT, Rendezvous signaling and participant discovery. In this role, a node helps devices find one another and establish a direct connection; it does not need to carry their user traffic.

To remain a reliable reference point for the network, a Server must be reachable from the outside through a public IP address or a consistently forwarded port.

The same node can use IRVIO for its own traffic and also act as an Exit Node. If a client selects it as the exit, the tunnel terminates on that node and traffic reaches the internet through its connection. This is still one VPN hop, not a relay through a Server to another Exit Node. Such nodes can also provide exits during the network’s early development.

Roles within the network
Exit Nodeuses the network
and provides internet access
IRVIO nodemay perform one or both roles
Serverprovides discovery and coordination
and may act as an Exit Node

02

Choose a country in one click

Users do not need to inspect IP addresses, compare latency or understand the network’s internal structure. The choice comes down to one action: selecting an exit country.

The client queries several independent Servers, obtains a fresh list of available Exit Nodes in that country, checks the options directly from the user’s device and automatically connects to the most suitable node.

Participant discovery does not depend on a single central server.

The client checks candidate reachability and connection parameters directly from its own device. Discovery and coordination are distributed among network participants using Kademlia/DHT and Rendezvous. If a direct connection to the selected node cannot be established, the client tries other available options. The lowest latency alone does not guarantee the highest throughput.

Finding a suitable Exit Node
Choose a country
Several Serversreturn available participants
Check the optionson the client device
Selected Exit Node

03

Introduction first, then a direct tunnel

A Server helps participants exchange service information and establish a connection through NAT. These functions are separate from carrying user traffic.

The client and the selected Exit Node establish a direct encrypted P2P tunnel. A node providing only discovery and coordination does not become an intermediate relay for that tunnel.

There is one VPN hop between the client and the Exit Node in IRVIO. If the selected node combines the Server and Exit Node roles, it carries user traffic in its capacity as the exit.

The tunnel uses AmneziaWG, a WireGuard-based protocol with obfuscation mechanisms. These are designed to make VPN traffic harder for DPI systems to identify. Effectiveness depends on the protocol version, settings and network conditions; bypassing every filter is not guaranteed.

Service exchange and user traffic
Discovery
Client
Server
Exit Node
Traffic
Client
Exit Node
Internet

The Server role provides discovery and coordination. The same node can carry user traffic when selected as an Exit Node; this does not add another VPN hop.

04

Who can see what

The connection between your device and the selected Exit Node is encrypted. VPN tunnel protection ends at the exit; it does not replace end-to-end encryption between an application and the destination service.

The Exit Node sees destination addresses and connection metadata. It can also see traffic content if the application does not use its own encryption. HTTPS protects the content of a website connection independently of the VPN. External services see connections arriving from the Exit Node’s public IP address.

Nodes providing only discovery and coordination process the service metadata needed to find participants and establish connections. If such a node is also selected as an Exit Node, the properties of an exit apply to it.

A direct connection does not make network activity invisible. Network operators can observe outer addresses, timing and the volume of encrypted packet exchanges. IRVIO does not promise absolute anonymity.

Read more in the Privacy notice.

05

Familiar UX, fundamentally different architecture

For the user, everything feels familiar: open the application, choose a country, press Connect and use browsers or applications as usual.

External websites see the IP address of the selected Exit Node. The difference lies inside the architecture: the exit points do not belong to one VPN provider; the network itself provides them.

06

A living system that should not lag

Participants constantly connect and disconnect, and the network’s geography changes over time. The IRVIO client obtains fresh options and, when necessary, can reconnect to a working node with minimal user involvement.

IRVIO is created by people and for people. The more participants join, the more Servers run and the more Exit Nodes become available, the broader the geographic coverage and the more resilient the network becomes against blocking.

07

Your node and participation

In the current version, connecting to IRVIO also enables your node’s participation as an Exit Node. This is a required part of the exchange: other participants can access the internet through your connection and public IP address.

The official software blocks certain ports and protocols to reduce specific opportunities for abuse. These restrictions do not eliminate every unwanted activity over permitted traffic.

Restrictions and participation rules

08

Questions and answers

IRVIO is free. Why do you need my connection?

Access to IRVIO requires no subscription or payment. The network works through mutual sharing of internet connections: you use other participants’ exits and provide your own to them.

Who can see my traffic?

The VPN tunnel encrypts data between your device and the Exit Node. The exit sees destination addresses and can read content that the application itself does not encrypt. HTTPS continues to protect the content of website connections. Discovery and coordination nodes process service metadata, rather than the contents of this tunnel, unless they are the selected Exit Node.

Can someone abuse my IP address?

Yes, that risk exists: other participants’ connections can reach the internet through your public IP address. Port and protocol restrictions reduce specific opportunities for abuse but do not eliminate abuse over permitted traffic. IRVIO cannot guarantee that your IP address will not receive complaints or be blocked.