Security

Security & Trust Center

How OpenVLAN is built, what we can and cannot see, and how to report issues.

Architecture: designed so we can't read your traffic

End-to-end encryption

All traffic is encrypted between your devices with AmneziaWG. No hop, including ours, decrypts it.

Keys stay on devices

Private keys are generated on your hardware and never leave it — not to our servers, not to your IdP, nowhere.

Least-privilege control plane

Our coordination servers only distribute public keys and policy decisions. They hold no traffic and no secrets that would decrypt anything.

Deny-by-default ACLs

Networks start closed. Every "open" is an explicit, logged, reviewable rule.

Relays can't read

When direct paths fail, encrypted traffic may relay through our DERP-equivalent servers — they forward ciphertext and nothing else.

Audit everything

Admin actions, policy edits, and privileged sessions are logged and exportable.

Compliance posture

ItemStatus
Independent penetration test (annual)Completed Aug 2026 — summary available under NDA
SOC 2 Type IIIn progress; report expected Q4 2026
GDPR / UK GDPRDPA available; SCCs for international transfers
Data residencyEU and US regions today; self-hosted option on Enterprise
SubprocessorsPublished list, updated with 30 days' notice
Breach notificationCustomers notified within 72 hours of confirmed incident

Demo site — compliance statuses shown are illustrative.

Vulnerability disclosure

We welcome reports from researchers and users alike, and we credit every valid report.

  • Email security@openvlan.com (PGP key published)
  • Please include reproduction steps and affected components
  • We acknowledge within 48 hours and triage within 5 business days
  • Safe harbor: good-faith research on your own tailnets won't get you in trouble
  • Bounty program: rewards for qualifying vulnerabilities in the control plane and clients

Out of scope

Denial of service on shared infrastructure, social engineering of staff, physical attacks, and findings in services we merely use (report those upstream). Vulnerabilities that require a malicious tailnet admin are documented properties of the shared-key model.

Check system status →