How OpenVLAN is built, what we can and cannot see, and how to report issues.
All traffic is encrypted between your devices with AmneziaWG. No hop, including ours, decrypts it.
Private keys are generated on your hardware and never leave it — not to our servers, not to your IdP, nowhere.
Our coordination servers only distribute public keys and policy decisions. They hold no traffic and no secrets that would decrypt anything.
Networks start closed. Every "open" is an explicit, logged, reviewable rule.
When direct paths fail, encrypted traffic may relay through our DERP-equivalent servers — they forward ciphertext and nothing else.
Admin actions, policy edits, and privileged sessions are logged and exportable.
| Item | Status |
|---|---|
| Independent penetration test (annual) | Completed Aug 2026 — summary available under NDA |
| SOC 2 Type II | In progress; report expected Q4 2026 |
| GDPR / UK GDPR | DPA available; SCCs for international transfers |
| Data residency | EU and US regions today; self-hosted option on Enterprise |
| Subprocessors | Published list, updated with 30 days' notice |
| Breach notification | Customers notified within 72 hours of confirmed incident |
Demo site — compliance statuses shown are illustrative.
We welcome reports from researchers and users alike, and we credit every valid report.
Denial of service on shared infrastructure, social engineering of staff, physical attacks, and findings in services we merely use (report those upstream). Vulnerabilities that require a malicious tailnet admin are documented properties of the shared-key model.
Check system status →