Skip to content
  1. Home
  2. Security and responsible disclosure

Security and responsible disclosure

If you've found a security issue in PryVPN, we want to hear about it, and we'll work with you to fix it.

Last updated

Beta draft. This text explains our practices in plain language. It will be reviewed by counsel before PryVPN launches publicly, and the reviewed version will replace it.

How we protect PryVPN

  • WireGuard, with keys generated on your device. Private keys never reach our servers.
  • Servers that hold no browsing data and keep working with their last configuration if our control systems are unreachable.
  • Encrypted connections between our servers and our control systems. Each server gets its own credential through a single-use enrollment token.
  • An operations panel reachable only from our own network addresses, behind a password and a separate admin key, with role-based access and an audit log of every administrative action.
  • Signed releases of our server installer, with a published public key so anyone can verify them.
  • Planned: security keys for staff sign-in and staged rollouts with quick rollback.

Reporting a vulnerability

Email security@pryvpn.com with a description, steps to reproduce and the impact you expect. Please give us reasonable time to fix the issue before you share details publicly.

What we ask of you

  • Don't access or change data that isn't yours.
  • Don't degrade the service for other people, for example with denial-of-service testing.
  • Test only against your own account.
  • Keep the details confidential until we've fixed the issue.

What we promise

  • To acknowledge your report within three working days.
  • To keep you updated while we investigate and fix it.
  • To credit you publicly, if you'd like.
  • Not to take legal action over good-faith research that follows these guidelines.

security.txt

Our contact details are also published at /.well-known/security.txt, in the standard format.