Sponsored contentVp.Net

VPNet: The New VPN Under Scrutiny

Explore VPNet's zero-trust VPN claims, architecture using Intel SGX, features, privacy policies, and the scrutiny it faces regarding user anonymity and legal requests.

VPNet: The New VPN Under Scrutiny
vpn

Illustrative image generated with AI

An Architecture Designed to Prevent Linking Users to Traffic

VP.NET LLC presents VP.NET as a “zero-trust” VPN designed to prevent connections between user identities, assigned IP addresses, and online activity.

The company says it cannot link an IP address and timestamp to either a current or former user. As a result, it claims it cannot retain or disclose this information.

The system uses Intel SGX, a technology that creates a protected enclave within servers. According to VP.NET, once the software has been deployed, even infrastructure operators—including the company itself—cannot alter its operation or introduce monitoring mechanisms.

These are vendor claims. No independent tests have been cited to verify that they are implemented across the entire infrastructure.

What the Service Offers

VP.NET LLC is controlled by founders Matt Kim, Mark Karpeles, Roger Ver, and Andrew Lee. The VPN servers are hosted in third-party data centers located in Germany, France, the United States, the United Kingdom, and Japan.

The company says it operates its own DNS servers and uses its architecture and obfuscation techniques to prevent linking inbound traffic to outbound traffic. It does not offer virtual locations.

The service supports protocols compatible with those used by WireGuard®, which VP.NET recommends to users. It also includes:

  • a kill switch;
  • DNS leak protection;
  • IPv6 leak protection;
  • IPv4 support, but no dual-stack IPv4/IPv6 configuration;
  • no port forwarding at this time.

The exact versions of the client, server software, and SGX components involved have not been disclosed.

Abuse Reports, DMCA Notices, and Government Requests

VP.NET says it cannot monitor user activity. However, when it receives a valid abuse report, its systems may still intervene in real time to block the disputed data flow.

The same procedure applies to DMCA notices: the legal team assesses the request and, if it considers it valid, the systems automatically block transmissions associated with that flow. According to the company, the block does not make it possible to identify the user.

VP.NET also states that a request to link a user—even a former user—to the corresponding traffic would be incompatible with its architecture. According to the company, obtaining such data would therefore require a change in legislation or congressional proceedings in the United States.

Payments, Support, and Outstanding Questions

Card payments are processed through Stripe, while all types of cryptocurrency—including privacy-focused currencies—are accepted directly. The company also plans to introduce gift cards from hundreds of brands.

VP.NET says it does not link payment data to account activity or assigned IP addresses. Support is handled using internal tools; for regular email communications, users may choose Gmail. The website also integrates Google Analytics.

The company claims to treat all traffic equally, without port forwarding and without associating flows with user identities. Independent verification is still needed to assess the actual configuration of the SGX enclaves, the implementation of kill switches and leak protections, and the observable behavior of the clients.

For those considering the service, no vulnerable versions or corrective updates requiring installation have been identified so far. Users should nevertheless verify the official clients, enable the kill switch, and periodically test DNS, IPv4, and IPv6 from a test network.

Read next

Back to home

Latest Cybersecurity News

All cybersecurity news →