Contents

Documentation/Help/Security

What is on by default — and what is not

Protection is not hidden behind “advanced” checkboxes.

Kill switch

While the VPN is on or reconnecting, the Windows firewall does not let traffic out past the tunnel. Allow LAN keeps printers and the router. You turn the VPN off yourself — the internet comes back.

DNS

Default is the profile DNS. Settings can turn on a filter (ads, family, Quad9) or a custom resolver, including DoH/DoT. An empty list in the profile means “whatever the server said”.

TLS fragmentation

The start of a TLS handshake leaves in small chunks so DPI has a harder time seeing the server. Not for Reality, Hysteria2, or TUIC: it breaks their handshake.

Keys stay on the machine

Profiles and the Premium key live in the app data folder. They do not go to a cloud. A backup is a password-protected file. Open the folder from Settings → About.

No connection logs

We do not record who connected, from where, or which sites you open. What the service stores and why is on the Privacy and Transparency pages.

Local network

Allow LAN works only together with the kill switch. Otherwise the toggle is grey. It is for the printer and the router, not for “get to the internet past the tunnel”.

IPv6

A common leak: the site sees your IPv6 while IPv4 goes through the VPN. Diagnostics will say There are leaks. For WireGuard add ::/0 to AllowedIPs or turn IPv6 off in Windows.

Routes in the profile

The Routes and DNS tab on a profile: your own IP/CIDR, Local networks and Multicast chips. OpenVPN is IPv4 only. On VLESS, Trojan, Shadowsocks and other proxy profiles private networks already go direct.