VaultPony, without the open web in the middle.
This site runs as a Tor onion service and an I2P eepsite: the same pages, served directly over each network. No exit nodes touch the traffic, the mirrors keep no access logs, and they stay reachable from networks where vaultpony.app is blocked.
Verified addresses.
These are the canonical mirror addresses for VaultPony. Anything else claiming to be VaultPony on Tor or I2P is not us.
http://vaultepsitaepjysmom6fmwmyhldy4hcsenj254zazpmrfscc35drwid.onion/
http://kckmasjrjkmobxcfoumnutdflbm7cdzpfpfoypt7sy5dhygwgwiq.b32.i2p/
A v3 onion address is not a name that points somewhere. It is the service's public key. There is no certificate authority in the path and nothing to spoof: when Tor Browser connects, the address itself guarantees you reached the real VaultPony. Bookmark it and you cannot be phished onto a fake.
Why bother, for a site with nothing to hide?
VaultPony is a local-only encryption app. The site has no accounts and no tracking, so these mirrors are not about hiding what you read. They keep the site reachable where the clearnet domain is blocked, and let you visit without leaving a DNS trail behind you.
For Tor
Install the Tor Browser, paste the .onion address above into it, and you are on the mirror.
For I2P
Install an I2P router, either i2pd or the official I2P, point your browser at its local HTTP proxy, then open the .b32.i2p address. The router takes a couple of minutes to find the network the first time.
Verifying the download still matters
Reaching the real site is not the same as getting the real APK. The download button points at GitHub either way, so check the release signature and the checksum as you would from any network.
Do your own privacy homework
Both networks hide your connection, but staying anonymous also depends on how you use the browser. If that matters to you, read each project's own guidance rather than taking ours for it.