How we protect PryVPN
- WireGuard, with keys generated on your device. Private keys never reach our servers.
- Servers that hold no browsing data and keep working with their last configuration if our control systems are unreachable.
- Encrypted connections between our servers and our control systems. Each server gets its own credential through a single-use enrollment token.
- An operations panel reachable only from our own network addresses, behind a password and a separate admin key, with role-based access and an audit log of every administrative action.
- Signed releases of our server installer, with a published public key so anyone can verify them.
- Planned: security keys for staff sign-in and staged rollouts with quick rollback.
Reporting a vulnerability
Email security@pryvpn.com with a description, steps to reproduce and the impact you expect. Please give us reasonable time to fix the issue before you share details publicly.
What we ask of you
- Don't access or change data that isn't yours.
- Don't degrade the service for other people, for example with denial-of-service testing.
- Test only against your own account.
- Keep the details confidential until we've fixed the issue.
What we promise
- To acknowledge your report within three working days.
- To keep you updated while we investigate and fix it.
- To credit you publicly, if you'd like.
- Not to take legal action over good-faith research that follows these guidelines.
security.txt
Our contact details are also published at /.well-known/security.txt, in the standard format.