Skip to main content

New in August: Password Manager ratings updated and expanded Read more

Security · Early access

SecShield security overview

This page describes the intended security model using only confirmed policy statements and configuration-backed feature status.

Model

Intended security model

SecShield is a VPN connection product. While connected, traffic between your device and the VPN path is intended to travel inside a protected tunnel. Destination services still see the VPN exit IP.

Tunnel

Tunnel architecture

Device to VPN path, then VPN exit to the internet. Confirmed protocol names and diagrams publish with production builds.

1

Device

App establishes a protected session.

2

VPN path

Traffic rides the encrypted tunnel while connected.

3

Internet

Requests exit to destinations from the VPN exit IP.

Encryption

Encryption and protocols

Confirmed encryption and protocol details will be published when the production build is ready.

Protocol selection Coming soon

Controls

Kill switch, DNS, and auto-connect

Kill switch Coming soon
DNS leak protection Coming soon
Auto-connect Coming soon

Lifecycle

Updates and security lifecycle

Production apps will receive security and product updates through their platform distribution channels. Exact update cadence will be published with launch materials.

Reporting

Vulnerability reporting plan

A public vulnerability reporting process will be published before or with launch. Until then, use the contact route for sensitive reports and mark them clearly.

Limits

Security limitations

Not anonymity

Logged-in services can still identify you.

Not endpoint security

SecShield does not replace antivirus or device hardening.

Depends on a healthy connection

If the app is disconnected, the VPN path is not protecting traffic.

Policy still prelaunch

Final production logging and retention policy will be published before launch.

Read privacy next

Security and privacy statements should be read together.