A · Threat model
What EVPN is designed against
- Hostile public Wi-Fi
- Local network observers
- Routine ISP visibility into destination traffic
- DNS leakage
- Accidental traffic leakage when VPN protection is enabled
A transparent look at what EVPN is designed to protect, what a VPN cannot guarantee, and how logging is minimised by architecture.
A · Threat model
B · What EVPN protects
C · Limits
Transparency matters more than slogans. EVPN cannot guarantee:
D · Architecture separation
Installation / Promotions
|
Authorisation
|
Short-lived capability
|
VPN Gateway
|
Private DNS
|
Internet
The system that serves a promotion should not be able to reach the system that carries your traffic.
E · Logging policy
This is policy and architecture language. It is not a claim that infrastructure has already been independently audited.
F · Audit / transparency
NOT YET AUDITED
Target transparency work includes external application review, infrastructure/no-logging audit, published remediation and a clear vulnerability-reporting path. Dates and providers will be named when engagements are real — not before.
G · Research
Exploring additional transports for restrictive networks.
Research into reducing observable traffic patterns where practical.
Hybrid key-exchange and hardening as standards mature.