SECURITY

Privacy you can inspect.

A transparent look at what EVPN is designed to protect, what a VPN cannot guarantee, and how logging is minimised by architecture.

A · Threat model

What EVPN is designed against

  • Hostile public Wi-Fi
  • Local network observers
  • Routine ISP visibility into destination traffic
  • DNS leakage
  • Accidental traffic leakage when VPN protection is enabled

B · What EVPN protects

Protected path, by design

  • Traffic between device and VPN gateway
  • DNS requests inside the VPN
  • Originating public IP from normal destination websites
  • IPv4/IPv6 routing leakage where supported
  • Traffic during VPN interruption when kill switch is enabled

C · Limits

What a VPN cannot guarantee

Transparency matters more than slogans. EVPN cannot guarantee:

  • Anonymity against a global passive adversary
  • Anonymity after users sign into identifiable accounts
  • Protection from malware already installed on a device
  • Prevention of browser fingerprinting
  • Secrecy for plaintext HTTP after traffic leaves the VPN exit
  • Universal streaming access
  • Universal censorship resistance
  • Immunity from lawful infrastructure seizure

D · Architecture separation

Who should not know where traffic goes

Installation / Promotions

|

Authorisation

|

Short-lived capability

|

VPN Gateway

|

Private DNS

|

Internet

The system that serves a promotion should not be able to reach the system that carries your traffic.

E · Logging policy

Collect less on the data plane

Never intentionally logged

  • — Browsing history
  • — Destination history
  • — DNS query history
  • — Packet contents
  • — Per-session traffic history
  • — Account-linked connection history

Operational metrics (aggregate)

  • — CPU
  • — Memory
  • — Tunnel counts
  • — Aggregate throughput
  • — Packet loss
  • — Gateway health
  • — Service errors

This is policy and architecture language. It is not a claim that infrastructure has already been independently audited.

F · Audit / transparency

Current state

NOT YET AUDITED

Target transparency work includes external application review, infrastructure/no-logging audit, published remediation and a clear vulnerability-reporting path. Dates and providers will be named when engagements are real — not before.

G · Research

Future work, clearly labelled

Research

Transport agility / MASQUE

Exploring additional transports for restrictive networks.

Research

Traffic-analysis resistance

Research into reducing observable traffic patterns where practical.

Research

Post-quantum research

Hybrid key-exchange and hardening as standards mature.