# URnetwork vs Cloudflare WARP

WARP is free last-mile encryption into Cloudflare's network, and Cloudflare
says itself that it is not an anonymity product; URnetwork splits the path
so the exit never learns who you are and the operator cannot read the
sealed session.

**Choose WARP** if you want free, unlimited encryption with no account and
the speed of a nearby Cloudflare edge. **Choose URnetwork** if you want an
exit you choose down to a city, a residential address, and a split path in
open code. Both ship hybrid post-quantum key agreement. WARP is the easier
product. URnetwork splits visibility between its operator and a member-run
provider.

[Cloudflare WARP](https://one.one.one.one) is the tunnel in the 1.1.1.1
app from Cloudflare, one of the largest networks on the internet. It
encrypts traffic from your device into the nearest Cloudflare edge, using
MASQUE by default since late 2024, with a WireGuard-based stack
(BoringTun) still selectable. The base tier is free and unlimited with no
account; WARP+ is about $5 a month as of early 2026. Cloudflare's launch
post is direct about the job: WARP "is not designed to allow you to
access geo-restricted content" and "will not hide your IP address from
the websites you visit."

URnetwork uses member-run exits. The provider does not receive your source IP
on the relayed path. Native apps seal traffic to the provider by default.
[How URnetwork works](/docs/overview) explains the full design. The
[threat model](/docs/threat-model) holds the complete record of what is stored
and enforced.

## Six differences that affect the choice

| | Cloudflare WARP | URnetwork |
|---|---|---|
| Price | Free and unlimited; WARP+ about $5/month as of early 2026 | Free daily allowance; Pro $5/month or $40/year |
| Account | None required at all | One-tap account with no email; recovery seed phrase; on-chain USDC |
| Speed and consistency | Anycast to a nearby edge on a 300-plus-city network | Member uplinks; URnetwork puts its average streaming speed at 40 Mbps+ |
| Location choice | None; you surface from a Cloudflare address matched to your country | Browse countries, search for a city |
| Exit address | Cloudflare ranges, recognizable as Cloudflare | Residential member addresses; ordinary traffic to the sites you visit |
| Trust and verification | One company terminates the tunnel and can see source and destinations together; apps and service closed | Two relay parties: the exit never sees your IP, and the operator cannot read the sealed session; open client and server code |

Caveats below the table:

- Post-quantum is parity. WARP has been rolling out hybrid ML-KEM key
  agreement since September 2025, with temporary downgrades allowed in the
  first phase. URnetwork's X25519MLKEM768 client-to-provider session is
  default in the native apps, skipping any provider it cannot seal to rather
  than downgrading. The browser extension has no sealed session; there, the
  operator's data path logs nothing, pinned by a test in the open code.
- Filtering sits in different places: Cloudflare offers malware and
  adult-content blocking at its resolver (1.1.1.1 for Families), while
  URnetwork ships a "Block ads and trackers" toggle in every app, off by
  default, applied on your own device.
- Both cover Android, iOS, macOS, Windows, and Linux. URnetwork adds a
  browser extension paired with its web app, and an explicit kill switch
  on every platform. Current URnetwork prices are at
  [ur.io/products](https://ur.io/products).
- BoringTun is open source; the WARP apps and the service side are closed.

## What WARP is, and is not

WARP's job is securing the stretch between your device and Cloudflare:
your ISP or a coffee-shop network sees only an encrypted tunnel. Cloudflare
scopes it that way itself, pointing anyone who wants anonymity to "a
traditional VPN or a service like Tor." The mechanics have moved on since
that 2019 post; the app now assigns "a Cloudflare IP address corresponding
to the country in which you are connecting from", so websites see a
Cloudflare address rather than yours. The substance stands: there is no
location choice, the exit is near your real location, and one company
knows whose session that address belongs to.

That position is the whole trust model. Cloudflare terminates the tunnel,
so it can see your IP address and your destinations together, and what it
does with that view is governed by pledges. The pledges exist and are
specific: no user-identifiable log data written to disk, never sell
browsing data, and an app policy that promises not to "retain a link"
between your IP address and the websites you visit, while keeping
pseudonymized account and operational data for up to two years. No third
party has tested any of them.

URnetwork is arranged so that view never assembles. The provider that
carries your traffic to the internet does not receive your source IP, and
the operator in the middle relays a sealed session it cannot read, so no
single party holds both your identity and your activity. The storage rules
behind that are enforced in the open server code, with the full record in
the [threat model](/docs/threat-model).

![Who can see what — single-party VPN vs Apple Private Relay's closed two-party split vs URnetwork's split knowledge](/docs-assets/infographic-who-sees-what.svg)

*WARP is the left column in its purest form. The right column is the
split you can read in open code, dispersed across member households.*

## What the examinations cover

Cloudflare has twice commissioned an independent privacy examination, in
2020 and 2026, by a Big Four accounting firm (KPMG in the original 2018
pledge, unnamed in the delivered reports). Both cover the 1.1.1.1 public
DNS resolver's commitments, not WARP. The findings were clean, down to the
candid disclosure that at most 0.05% of packets, querying IPs included,
are sampled for troubleshooting. Two scope notes matter. The 2018 pledge
said annual, and the delivered examinations are six years apart. And the
2019 WARP posts promised to "regularly work with outside auditors" on
WARP's own pledges; the examinations that followed were of the resolver.
So WARP's privacy story is policy on top of full single-party visibility,
from a company whose enterprise business gives it no advertising motive,
and no audit has reached it.

The operational record is strong and openly reported. In July 2025 the
1.1.1.1 resolver had a roughly hour-long global outage; Cloudflare's
postmortem calls it an internal configuration error, not an attack, and it
was an availability incident rather than a privacy one. No WARP privacy
breach is on record.

URnetwork has no independent audit of its protocol or the operator's
server code either; the details are under Limits. Its compensating
position is different in kind: the operator's storage design is enforced
in public code that anyone can check on any day, rather than pledged in
policy.

## One company, several vantage points

Concentration is the other structural fact. The company that terminates
your WARP tunnel also serves as an egress relay for Apple's iCloud Private
Relay, where Apple's design withholds user identity from it; runs the
1.1.1.1 resolver; and reverse-proxies a large share of the web's sites as
its core business, on a network spanning more than 300 cities. Each
vantage point carries its own privacy controls, and nothing on record says
Cloudflare combines them. The structural point stands anyway: a large
fraction of internet traffic surfaces inside one company in different
roles, and WARP is the role in which it also knows your address.

URnetwork's design goes the other way. Egress is dispersed across member
households, each carrying a slice of your traffic, with per-site affinity
keeping any one site on one exit. The operator coordinates but cannot read
the sealed session, and its server code is public.

## Where WARP wins

- Free, unlimited, no account, near-zero setup.
- Speed and latency: anycast to a nearby edge plus Cloudflare's backbone.
- Operational maturity and capacity a young decentralized network cannot
  match.
- Accurate self-description: the product does what its maker says, and
  does not claim what it does not do.
- The right tool for encrypting traffic on an untrusted network.

## Where URnetwork wins

- The split. The exit never learns who you are, and the operator cannot
  read the sealed session. No single party holds identity and destinations
  together; Cloudflare sees both ends of the tunnel it terminates.
- Location choice down to a searched city; WARP offers none.
- Residential exit addresses; Cloudflare's ranges are recognizable as
  Cloudflare.
- Open client and server code, checkable continuously; WARP's pledges are
  policy, untested by any third party.
- A supply side: members can share their connection as participants in the
  [UR protocol](https://ur.xyz), under signed metered contracts, with an
  open-source filter dropping file-sharing and attack traffic before it
  leaves a member's line.

## Limits and evidence

URnetwork's main limits:

- No independent audit covers the protocol, the connect engine, or the
  operator's server code. Two 2025 third-party assessments cover other
  surfaces: a penetration test of the web application and API (April–May
  2025), and the Leviathan MASA AL2 assessment of the Android app, which
  passed. Leviathan writes that its assessment "should not be read as a
  holistic security evaluation or comprehensive penetration test." Neither
  examined logging, retention, or the data path.
- The split assumes the operator and the providers in your window are
  independent. Nothing in the system attests that independence, and no
  outside party has measured the fleet. See the
  [threat model](/docs/threat-model), §6.1.
- The WireGuard-compatible fallback endpoint assigns one stable tunnel
  address, so several providers could recognize the same client across
  sessions. The native tunnel is the recommended path.
- Coverage counts are self-published, with no outside measurement; the
  mechanism, a location existing only while a member's device is online in
  it, is the checkable part.

WARP's limit is the position, not the conduct. Cloudflare terminates the
tunnel, so one company can see your address and your destinations
together; its pledges about that view carry no third-party attestation,
and the two examinations it cites cover the resolver, a different product.
Cloudflare's own framing of WARP as transit encryption rather than
anonymity is accurate, and the right way to use it.

Trying URnetwork costs nothing: the Instant Account takes one tap and no
email, and WARP is free outright, so you can run each against your own
sites before paying for anything. More questions are answered in the
[FAQ](/docs/faq).
