Status: The VPN service is planned for December 2026; details may change before then.
A VPN protects one stretch. Not everything.
A VPN encrypts the path between your device and the VPN server. It does not change what happens on your device or what lies beyond the VPN server. The protection has five layers; each has a job and a limit.
Layer 1: the tunnel
Your device and the VPN server agree on keys. After that, every data packet is encrypted before it leaves your device and decrypted only on the VPN server. From there it travels on to its destination; the reply takes the same route back.
| Who | Sees without a VPN | Sees with a VPN |
|---|---|---|
| Wi-Fi operator, internet provider | which servers your device talks to, when and how much; the content of unencrypted connections | the connection to the VPN server, when and how much |
| VPN service | nothing | technically everything the internet provider saw before |
| Site you visit | your IP address and everything you do there | the VPN server's IP address and everything you do there |
Sites using HTTPS are additionally encrypted from your browser to the site. The VPN service does not see their content either.
Layer 2: protocol and encryption
The VPN speaks WireGuard and OpenVPN. Both are open source and have been examined by independent experts for years.
| Feature | WireGuard | OpenVPN |
|---|---|---|
| Transport | UDP, port 9929 | UDP or TCP, ports 1194, 1195 and 443 |
| Encrypting the data | ChaCha20 with Poly1305 | AES-256-GCM from OpenVPN 2.4, ChaCha20-Poly1305 from OpenVPN 2.5 |
| Agreeing keys | Curve25519 | Diffie-Hellman over TLS, secured with a 4096-bit RSA key |
| Replacing keys | automatically while running | every 45 to 75 minutes |
Apps up to OpenVPN 2.3 get an older method; all the details are on the two protocol pages.
Both protocols generate the keys for the actual data afresh for every session and replace them while it runs (perfect forward secrecy). If a long-term key falls into the wrong hands later, traffic captured earlier cannot be decrypted with it.
Layer 3: the VPN servers
The tunnel ends on the VPN server; that is where your traffic is decrypted and passed on. So it matters how these servers are built.
- No hard drives. There is no storage medium in the VPN servers. The operating system sits in memory only, and the contents of memory are lost as soon as a server is switched off.
- Verified start-up. When switched on, a server loads its system image via iPXE from encrypted boot servers. It only comes up if the signature of the kernel and the initrd is correct; otherwise it restarts and tries again.
- Lean operating system. The servers run a cut-down version of Alpine Linux.
- No system log. Syslog is switched off, and the OpenVPN processes are not allowed to write anything. As a result, logs are not created even temporarily in memory.
- A short memory with WireGuard. A key management service removes every device from the server's memory that has gone three minutes without a handshake.
- No access at the machine. The VPN servers cannot be operated through a console, a keyboard or USB ports.
- Physical machines. The VPN servers are physical machines, not virtual ones, and stand in locked, separated racks.
- Maintained and monitored. Critical security updates are applied daily, and an intrusion detection system monitors the servers.
The limit: this design makes sure that nothing remains on a server. For as long as it runs, it processes your traffic in memory. Whom you trust with that remains the real question; it is covered under VPN and privacy.
Layer 4: DNS
Before your device opens a site, it asks a DNS server which IP address belongs to a name such as example.org. These queries reveal your destinations even when the content is encrypted. By default, a server run by your internet provider usually answers them.
The VPN service includes DNS servers that do not log queries. The configuration tells your device to ask these servers; the queries then travel encrypted through the tunnel. The paid plans also offer optional DNS servers that block ads and trackers.
A DNS leak occurs when queries go around the tunnel: your internet provider then still sees every name you look up, even though it no longer sees the connections themselves. Four things on your device can cause it:
- The VPN app. Not every app prevents DNS leaks; with the OpenVPN functions built into operating systems in particular, protection may be missing.
- Fixed DNS servers. If you or an app on the device have entered other DNS servers, the queries go there.
- The browser. By default, some browsers send DNS queries to a preset DNS service instead of the system's DNS server.
- Security software. Some antivirus tools redirect DNS queries no matter which DNS server is set.
Layer 5: when the connection drops
A tunnel can break: when switching from Wi-Fi to mobile data, after sleep mode, with poor reception. Depending on the app and the operating system, traffic can then briefly take the ordinary route again, without the tunnel and with your own IP address.
A block for this case is usually called a kill switch. Because the VPN works with the widely used apps, it is a feature of the app you choose. The WireGuard app for Windows, for example, can block all traffic outside the tunnel; the option is in the tunnel's settings. Check whether your app has such a block and whether it is switched on.
Two more gaps: IPv6 and WebRTC
The VPN supports IPv6. But if a device routes only IPv4 through the tunnel, its IPv6 traffic bypasses the tunnel, with your own address. After setting up, check whether your device sends both kinds of address through the tunnel or has IPv6 switched off.
WebRTC is the technology browsers use to set up calls and file transfers directly between two users. To do so, the browser finds out your device's addresses through what are known as STUN requests, and a site can read them out even while a VPN is running. In some browsers WebRTC can be restricted or switched off.
What a VPN cannot do
- It does not make you anonymous. Sites recognise you by sign-ins, cookies and the characteristics of your browser, even behind a different IP address.
- It moves trust. What your internet provider could see before, the VPN service can see afterwards. Why that is the real question is explained under VPN and privacy.
- It does not protect against malware or phishing. A forged site or a malicious attachment arrives through the tunnel just as it would without it.
- It does not protect a sign-in. If you log in to a service, that service knows you. A weak password stays weak.
- It ends at the VPN server. Beyond it, a connection is protected only if it is encrypted itself, for example by HTTPS.
- It does not change your device. Apps with location permission still know where you are, and settings such as language and time zone remain visible.
Questions
With HTTPS, do I need a VPN at all?
Not for the content of a site: HTTPS already encrypts it. A VPN additionally hides which servers your device talks to and protects connections that are not encrypted themselves.
Can the VPN service see what I do?
Technically it can see which servers your device talks to, but not the content of encrypted connections. This is not kept in a form that could be traced back to you; more under VPN and privacy.
What is the point of a server without hard drives?
There is no storage medium on which anything could remain. If a server is switched off or cut from its power supply, the contents of its memory are lost.
Does the VPN have a kill switch?
That depends on the app you connect with. Some apps can block all traffic outside the tunnel, others cannot. Switch the block on wherever there is one.
Back to the overview: VPN. The steps for setting up are under Setting up the VPN.
WireGuard is a registered trademark of Jason A. Donenfeld.