For BYO, you might consider Algo VPN https://github.com/trailofbits/algo -- it gets IPSec right --
or, if you're feeling more bleeding-edge, WireGuard.
No. WireGuard, right now, is mostly useful to people who can run Linux (or people who want site-to-site VPNs). There's a cross-platform userland client in progress; a couple different organizations (us included) have kicked in to fund it.