You inherit the tunnel. You own the sentences users believe.

White-Label VPN: What You Inherit vs What You Own

On a hosted white-label VPN you inherit protocols and servers. You own the brand, the price, the support inbox, the store accounts, and the privacy-policy wording. Mix those up and you will write promises you cannot keep.

KloxVPN Team
18 min readPublished 2022-11-01
White-Label VPN: What You Inherit vs What You Own
You inherit the tunnel. You own the sentences users believe.

White-label founders talk like they bought a VPN company. They bought a slice. The slice is easy to describe if you are willing to be unromantic: you inherit protocols and servers; you own brand, pricing, the support inbox, store accounts, and the wording on your privacy page.

I keep seeing the mix-up. A partner copies node poetry from a network they do not run. Or they treat pricing as 'whatever the platform charges plus a dollar' and then cannot staff the inbox that dollar was supposed to fund. Or they launch on the vendor's developer account and call it their brand. The App Store does not care about your feelings. Users care about the logo on the icon and the email that answers at 11 p.m.

Chargebacks care too. The descriptor on the card is an ownership document. If it still says the platform, you will spend support time explaining a charge the user does not recognize. Fix the descriptor. That is column B. Do it before the first paid user, not after the first dispute. Card brands are slow. You are slower if you wait.

This is not the no-logs piece. That one is about controller versus processor and first-person promises about boxes you cannot SSH into. This one is the ownership map: which layers arrive with the platform, which layers are yours even if you wish they were not.

KloxVPN sells a consumer product (WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, from $2.83 a month, seven-day money-back) and partner motions. White-label is your brand on our network. Reseller is you selling Klox. If you want a custom split, use contact. I will not invent city counts or admin route names so your wiki looks complete. Confirm the live packet on a call.

If you cannot draw a two-column list — inherited vs owned — you are not ready to publish a homepage. You are ready to confuse a lawyer.

I have sat on calls where the founder could recite WireGuard talking points and could not say who owned App Store Connect. That call is the product. The protocol lecture is a hobby. Write the owner of every login before you buy ads. Ads on a brand you do not control is how you pay to acquire users for someone else's binary.

Related reading: How to Use a VPN on Curling Wi-Fi and OpenVPN TCP Fallback on a White-Label Stack. WireGuard on a White-Label VPN Stack and No-Logs When the Brand Isn't the Network Operator. What is a VPN? and Download KloxVPN.

Looking for a reliable VPN?

KloxVPN — from $2.83/month. Apps for every device.

View Plans

The two-column list I make partners write

Column A: what arrives because a network already exists. Column B: what still has your name on the invoice, the listing, or the lawsuit caption.

Column A is usually WireGuard, OpenVPN, OpenConnect, and Shadowsocks on the clients, exit nodes, IP reputation work, protocol fallback when UDP dies, and the unglamorous job of keeping a handshake boring from a phone on LTE. You inherit the behavior of that stack. You do not inherit the right to lie about it.

Column B is the brand system, the price, the mailbox, Apple and Google accounts, and every sentence that says 'we' to a customer. You can outsource design. You cannot outsource the fact that the customer paid you.

I make people write this on a single page, in verbs, not in architecture diagrams. 'We set retail price.' 'They rotate a burned IP.' If a line cannot take a verb, it is a slogan.

White-label branding versus the VPN tunnel
Your logo is packaging. The tunnel is still WireGuard, OpenVPN, OpenConnect, and Shadowsocks.

    How to read this page

  1. 1Skim the seating / order diagram.
  2. 2Do the numbered steps once on your real network.
  3. 3Use the FAQ if a sentence was too long.
  4. 4Follow one related article — not ten tabs.
Typical hosted white-label split. Confirm Klox's actual packet on a call.
LayerUsually inheritUsually ownWhat blows up if you swap them
Protocols (WireGuard, OpenVPN)Client behavior, fallbacksHow you describe them in help docsYou promise a handshake you cannot tune
Servers / exitsPacket path, IP hygieneWhat you tell users during an outageSilence, then refunds
BrandNothingName, icon, site, emailsUsers think they bought Klox
PricingYour cost floor, not your retailPlans, trials, refund window you advertiseSupport cost eats the margin
Support inboxMaybe a status note from the operatorTickets, tone, SLAs you publishCopy-paste macros that do not match the app
Store accountsNothing usefulDeveloper identity, listings, review notesHostage binary, no exit
Privacy policy wordingFacts about the network, if they give you a noticeYour 'we,' your processors, your deletion storyA slogan that fails in email one

Inherited infrastructure does not inherit your honesty. You still type the words.

— KloxVPN operator notes

Cloudflare Learning: What is a VPN?

Wikipedia: Virtual private network

IETF RFC 8446 (TLS 1.3)

Why founders reverse the columns

Protocols feel like identity. 'We are a WireGuard company' sounds like a moat. It is not. Lots of apps speak WireGuard. Your moat is distribution, trust, and whether a human answers. Servers feel like assets. On hosted, they are someone else's assets that your users touch. Pricing feels like a platform decision because a spreadsheet said 'cost plus.' Cost plus is how you discover tickets cost more than the plus.

I do not mind ambition. I mind a homepage that talks like column A is column B.

Reseller is a different map

Reseller: the user buys Klox. You own the relationship you actually contracted — often a commission story — not the binary. Do not write a privacy policy as if you operate nodes. Do not put your logo on a fake client. If you want the brand column, that is white-label, and you take the inbox.

Protocols you inherit, copy you still write

Klox consumer and partner clients are in the WireGuard-plus-OpenVPN world because some networks hate UDP and some devices still want the older stack. You inherit that product choice when you brand the apps. You do not inherit the right to say you invented the handshake.

Help Center articles are yours. If you tell users 'always use WireGuard' and their hotel only passes TCP 443, you will refund them and blame the protocol. The protocol did not fail. Your copy did.

TLS 1.3 (RFC 8446) may sit under control-plane traffic or parts of OpenVPN. Users do not need a lecture. Reviewers and careful buyers might. Do not paste cipher poetry you cannot defend. Cloudflare's explainer is enough for 'what is a tunnel.' Your FAQ still has to match the toggles in the app you ship.

What 'we support WireGuard' is allowed to mean

It means the client can bring that tunnel up to the operator's nodes, on the platforms you actually shipped. It does not mean you can tune keepalive timers. It does not mean you can promise battery life in hours. Battery is a device, a radio, and a keepalive fight. Inherited stacks still drain phones if users leave kill switch on in a basement with one bar.

OpenVPN is not a branding problem

It is a coverage problem. Teams hide the toggle because it looks old. Then office parks cannot connect. You own the decision to expose the fallback. The platform owns making it work. If you hide it, own the refunds.

Servers you inherit, outages you still narrate

Users do not email the rack. They email the brand. When an exit is sick, you need a sentence that is true. 'We are looking into it' is allowed. 'Our global backbone is fully redundant' is a novel if you cannot define backbone.

I will not invent a city count for Klox in this article. Operators typically want enough exits that travel is not a coin flip, plus a way to move users off a hot IP. Confirm what you actually get. If you publish a number you guessed from a marketing map, a user in that city will test it on day one.

Capacity and abuse live with the operator on hosted. Your job is routing the complaint and not promising a dedicated IP you did not buy as a SKU.

HTTPS versus a VPN tunnel
HTTPS locks the page. A VPN wraps the path to a server you chose.

Status pages vs tweet energy

If you do not get incident notice, you will learn about outages from one-star reviews. Ask how the operator tells partners. I will not name an API. Confirm the channel. Then decide whether your status page is a mirror or a lie.

You cannot inherit reputation as a slogan

A clean IP this morning is a listed IP tonight. Streaming blocks are not a moral judgment. They are lists. Do not screenshot a 4K play button as a guarantee. That is listing-asset work we cover elsewhere. Ownership point: the promise is yours even when the IP is not.

Brand is not a skin. It is the identity users sue.

Logo, name, icon, domain, from-address, in-app strings, receipt footer. If any of those still say the platform's name, you are running a confusing product. Confusion is how chargebacks get extra adjectives.

You own trademark clearance. You own the look that does not clone a giant consumer VPN so hard that Apple thinks you are a knockoff. Guideline 2.3 energy applies: metadata should describe your app. Inherited UI chrome does not give you their brand equity.

White-label means the customer believes they bought you. Act like it in every surface, including password-reset mail.

Email that still says the vendor

I have seen branded apps send 'via SomePlatform' in Gmail. Users forward that to support and ask if they were phished. Fix the from-domain and the footer. This is not optional polish. It is the ownership test.

Domain you do not control

If the vendor holds the customer-facing domain, you do not own the brand. You rent a subdomain. Fine for a pilot. Fatal for a company you want to sell.

Pricing you own, including the refund you advertised

Klox consumer pricing starts from $2.83 a month on the published plans, with a seven-day money-back window. That is our consumer story, not a mandate for your brand. You can charge more. You can charge less until support eats you.

You own annual vs monthly mix, family framing around five devices, and whether you copy a seven-day window you cannot honor in Stripe. If you advertise 30-day refunds and your processor fights you, that is your problem. The inherited network will not refund on your behalf unless the contract says so.

Do not publish an SLA credit schedule you invented. Operators typically want clarity on refunds for multi-day outages. Confirm what, if anything, the platform will do. Then write only that.

Five devices is a household fact

Klox includes five devices on consumer plans because a house is a phone, a laptop, a tablet, and an argument. If you sell 'unlimited devices' on a white-label, confirm the platform even allows it. If you sell one device to look cheap, you will lose the family buyer and still pay the same support for password resets.

Trials are an inbox generator

A seven-day trial with a hard paywall trains people to open tickets on day six. You own that design. Inherited protocols do not make trial users polite.

The support inbox is yours even when the packet is not

This is the line people hate. They want the vendor to 'handle tech' and their VA to 'handle billing.' VPN tickets do not split clean. 'Can't connect' is protocol, Wi-Fi, expired account, and a kill switch. Your agent is the router. If they only know billing, they will escalate everything and you will hate the vendor for a problem you staffed wrong.

Ticket volume is not a vibe. A messy 1,000-user base can throw 80 to 150 tickets a month. At a few dollars fully loaded per ticket, a $3 plan is a hobby. You own hiring. You own macros that match the app. You own not asking for destination URLs if your policy says you do not look at them.

The operator may give you a status note. They will not sit in your Zendesk.

Macros that leak inherited internals

Do not tell users to 'restart the wg0 interface' unless you sold a Linux power-user product. Do not name internal node hostnames. Translate. Inherited ops language in a consumer inbox makes you look like a reseller pretending to be a brand — which, if you are white-label, you should not look like.

Hours you published

If the site says 24/7 and you are one person in one timezone, you own the lie. Inherited networks do not staff your nights. Cut the claim or staff it.

Store accounts: if you do not own them, you do not own the brand

Apple and Google are slow identity systems. Organization accounts, DUNS, Play Console identity. White-label brands that want a real product put listings under their legal entity. If the vendor publishes as themselves, users install them. That can be a valid reseller-like motion. It is not white-label in the sense customers mean.

You own review notes, demo accounts, nutrition labels, Data safety forms, screenshot sets. We have a rejection-patterns piece for policy failures and a screenshots piece for listing assets. Ownership point here: those forms are your signatures. Inherited binaries do not inherit our App Store history. You start at zero.

Packet Tunnel Provider and VpnService live in the inherited client. The declarations live in your console. Split those in your head or you will wait on a vendor to 'fix review' when the fix is your privacy text.

Transfer later is a fairy tale you should still plan

Account transfers exist and they hurt. Do the identity matching before launch if you can. If you cannot, write the transfer as a project with calendar, not as a footnote.

Demo logins are yours to keep fresh

Reviewers need a working account. If your trial expires in 48 hours and review takes a week, you own the failure. Inherited nodes being 'up' does not help a dead password.

Privacy-policy wording is a writing job, not a download

You own the sentences. You may inherit a network notice you should link, not launder. Do not copy a RAM-disk poem from a company that runs its own fleet. Do not copy a SaaS generator that never mentions tunnels.

The no-logs article is the deep cut on first-person promises. Here the ownership rule is smaller: you write the policy that matches your Stripe, your mailbox, your chat widget, and the operator's linked notice. If you cannot name those processors, you are not done.

Stores will compare App Privacy / Data safety to the policy. That comparison is your problem. The inherited client might include a crash SDK. You still tick the box.

What you may quote from the operator

Their public policy, if they have one, and what your contract allows you to say. Quote with a link. Do not rephrase into 'we never' if they said 'the operator does not.' Pronouns are the whole game.

What you must not quote from a competitor

Audit names, certification logos, city counts, SLA percents. If Klox has not given you a fact, it is not a fact for your page. Ask. Then write.

What you cannot inherit no matter how much you pay

Review history. Trust. A refund rate of zero. A support culture. Trademark clearance. The right to use someone else's screenshots. A merchant account that will not get tested by fraud in week three.

You also cannot inherit a SOC 2 logo from this blog. If you need attestations, ask what exists and put only that on a security page. I will not decorate this article with certifications we have not handed you.

You cannot inherit user love from a protocol. WireGuard is widely liked among people who like protocols. Your one-star reviews will still be about billing.

You cannot inherit a quiet abuse desk. Complaints will name the brand on the app. Your contract should say how notices route. If it does not, you still own the email that arrived. Reply or get pulled by a host. Those are the choices.

Distribution is yours

SEO, ads, affiliates, ISP bundles. The network does not show up in search for your invented brand. Budget it. Inherited performance does not replace a channel.

Legal process mail

It may arrive at you, them, or both. Own a routing rule in the contract. Do not publish a heroic warrant-canary you copied. That is not ownership. That is costume.

Contracts, APIs, and sentences you should not invent

Partners fill security pages with numbers they found on someone else's PDF. Uptime percents. Admin routes. City counts. SOC 2 badges. I will not invent those for Klox here. If you need an API to provision accounts, say that in the call: operators typically want create, disable, device revoke, and a support lookup that is not a browsing history. Then write down what you were actually shown.

SLA talk is the same. Operators typically care about how incidents are declared, how long you can stay dark before you owe users a true sentence, and whether credits exist. A percent without a measurement window is decoration. Confirm Klox's commitments on a call. Put only those words on your enterprise one-pager.

This is ownership again. You own the published sentence. The platform owns the datapath. If you publish a fake route, your integrator will build against it and then blame you at 2 a.m.

What a useful partner wiki contains

Who submits stores. Who is merchant of record. Where refunds go. What the admin actually shows (online now? bytes? last handshake?). How abuse mail routes. How you export customers. The date you last verified each line. A wiki that is a copy of a competitor's is worse than no wiki. It trains new hires to lie.

Procurement will ask anyway

Let them. Answer with 'here is what we operate' and 'here is what the network operator operates.' Dual answers feel messy. Messy is accurate. A single 'we' that covers both columns is how you fail a security questionnaire in question three. We already wrote the no-logs version of that trap. This is the rest of the questionnaire: uptime, subprocessors, who has SSH. Do not SSH-brag if you do not have SSH.

How to use the map before you launch

Write the two columns. Walk every surface: site, app strings, stores, receipts, macros, ads. If a sentence claims an inherited layer as a personal feat, cut it. If a sentence dumps an owned layer on the vendor, staff it or stop selling.

Then pick the motion. White-label if you want column B in full. Reseller if you want attach revenue without owning a binary. Contact if you are an odd shape and you know it.

Consumer users who just need a VPN can go to pricing and download. Do not send them a partner form. Do not send procurement to a $2.83 checkout and call it enterprise. Different rooms.

If you skip the workshop, you will still do it, just later, after a one-star review explains the split better than you did. I would rather you spend the hour now. The ads can wait. The confusing homepage should not ship.

A one-hour workshop that saves a quarter

Get the person who writes ads, the person who answers tickets, and the person who will click Submit in App Store Connect in the same call. Read the homepage aloud. Every time someone says 'that's the platform,' write it under inherit. Every time someone says 'we'll handle it,' write the name. If the name is empty, you found the hole.

When inherited pieces become your problem anyway

Always, in the user's eyes. The map is for you and your lawyer. The user has one logo. Plan the narrative for when the inherited layer fails. That narrative is owned. If you have none, you will improvise in public.

Key Takeaways

A hosted white-label VPN hands you a tunnel that already exists. It does not hand you a company. Protocols and servers show up with the platform. Brand, price, inbox, store identity, and privacy wording stay on your desk even when you wish they would not.

Write the two columns. Staff column B. Stop narrating column A in the first person unless the contract and the facts agree. Reseller is the motion if you do not want column B. White-label is the motion if you do.

I would rather you launch with a plain policy and a staffed mailbox than with a cloned network poem and a VA who cannot reset a kill switch. Users forgive a slow city. They do not forgive a brand that does not know what it owns.

If you only remember one verb: staff. Inherited WireGuard will not answer a chargeback. Inherited exits will not rewrite your privacy page. You will. Schedule the people before you schedule the launch tweet.

When you want the branded path, use white-label. When you want to sell Klox, use reseller. When the split is weird, use contact and say which column you must hold.

Own the brand. Inherit the network.

White-label is your name on the Klox network. You still own price, inbox, and store listings. Bring the two-column list.

Talk to us about white-label

Frequently Asked Questions

Typically brand, retail pricing, support, store accounts, and policy wording. Protocols and servers stay with the operator on a hosted model. Confirm the live split on a call.

KloxVPN Team

Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.