Windows
cyberlexs/colitu-windowsWindows 10 and 11 app: interface, connection management, updater and installer.
git clone https://github.com/cyberlexs/colitu-windows.git
cd colitu-windows\v2rayN
dotnet build v2rayN.sln -c ReleaseView the source code on GitHub ↗Android · Android TV
cyberlexs/colitu-androidPhone, tablet and TV app: interface, protocol selection, VPN service and updater.
git clone https://github.com/cyberlexs/colitu-android.git
cd colitu-android/V2rayNG
./gradlew assemblePlaystoreDebugView the source code on GitHub ↗Why are we open source?
Choosing a VPN means trusting a company with your internet traffic. We want to earn that trust with code anyone can inspect, not with words.
A VPN sees a lot
All of your device's traffic flows through a VPN app. You shouldn't have to trust software like that blindly.
Proof, not promises
Saying "we keep no logs" is easy. With open code, anyone can see for themselves what the app collects and where it sends it.
More eyes, safer code
Bugs in closed code can go unnoticed for years. Researchers anywhere can study open code, so problems are found and fixed faster.
A freedom that's yours
The GPL-3.0 licence lets you read, build, change and share the code. That right cannot be taken back from you.
What can you verify in the code?
- The app has no built-in server list; connection details come from the API, issued for your account.
- Session keys are stored encrypted on the device: with the Android Keystore on Android and DPAPI on Windows.
- Updates are installed only if their SHA-256 hash matches the release manifest.
- The code shows exactly how protocols are tried and how the connection is verified.
- Every request and field the app sends to the API is defined in the code; there is no hidden tracking or ad library.
What's open and what isn't?
We want to be clear about open source. Here is what is open and what is not:
- ✓Windows appAll on GitHubOpen
- ✓Android and Android TV appAll on GitHubOpen
- —iPhone and iPad appNot released yet; we'll share its status here once distribution is ready.Closed
- —Server infrastructure and account systemKept closed so our protection against abuse and attacks is not weakened.Closed
Contribute
Bug reports, translation fixes and suggestions are welcome on GitHub. If you publish your own build, please use your own name and logo; the Colitu name and logo are not covered by the GPL.
Found a vulnerability?
Please don't open a public issue. Send the details to support@colitu.com, or through Support with "Security" in the subject; we'll get back to you before the fix.
Projects we build on
Colitu stands on solid projects the open-source community has built over many years. We thank them.
Verify the file you downloaded
Every installer on colitu.com is tied to a release tag on GitHub and the commit that tag points to. The checksums below are read from the signed release manifest the apps use when updating.
Windows · Version 2.5.0
Release on GitHub ↗- Tag
- v2.5.0
- Commit
- —
- ColituVPN-Setup-2.5.0-x64.exe
- SHA-256 ff3057f8a9870262e8df4d9a2e8b86c833d1b777ca0f4117136b23d9dd33a645
The release manifest is signed with ECDSA P-256; the app installs no update without verifying the signature and the file checksum.
Android · Version 2.4.2
Release on GitHub ↗- Tag
- v2.4.2
- Commit
- 63053fc1934869eea4f3fda231b145c5a4d703ed
- Colitu-2.4.2.apk
- SHA-256 64a232df91287f22fb4f9357e7c624b72e16a835d2c4ac6a759fb652c78ecb96
- Colitu-2.4.2-arm64-v8a.apk
- SHA-256 9a351e34d846ad4b72ccbb51ad977bc4d99956a296da0055df56a44a62ae2eb2
- Colitu-2.4.2-armeabi-v7a.apk
- SHA-256 405a3e3f044a779fc08cf8f15fe03b1a3df714c05776fa074a86951ec4c97f1e
- Signing certificate
- SHA-256 900e364616e5fce83766310f74bd06e4743a6936460a9e108edd096dfb5e82fc
Before installing an update, the app compares the APK checksum and signing certificate with these values.
How to check it yourself
# Windows (PowerShell)
Get-FileHash .\ColituVPN-Setup-*-x64.exe -Algorithm SHA256
# Linux / macOS
sha256sum Colitu-*.apk
# Android signing certificate
apksigner verify --print-certs Colitu-*.apkThe checksum must match the value on this page and in the GitHub release. To build from source, run the commands above on that release's tag.
Read the code, then decide.
Use our open-source apps on the free plan: 10 GB every month.