XVPN VNSTACK

Standard protocols. Minimal privileges.

Native VPN uses WireGuard. Chrome uses an authenticated TLS proxy. The backend does not receive client WireGuard private keys.

Control plane and Node Agent authenticate with TLS 1.3 mTLS. API security includes Argon2id, token rotation and rate limiting. The proxy rejects invalid/expired credentials and closes revoked connections. IPv6 and DNS must be tested on every platform before release.