TLS-Based Tunnel Encryption
We secure all VPN tunnels with TLS (Transport Layer Security), employing AES-GCM cipher suites combined with Elliptic-Curve Diffie–Hellman Ephemeral (ECDHE) key exchange. This configuration provides both confidentiality/integrity and forward secrecy for user traffic.
Key Rotation & HKDF Derivation
Encryption keys are rotated regularly—either on a time schedule or upon new session establishment. We leverage the HMAC-based Extract-and-Expand Key Derivation Function (HKDF):
• Extract: Derive a pseudorandom initial key material (IKM) from the shared secret and a salt via HMAC.
• Expand: Generate distinct encryption and authentication keys from the IKM using HMAC with context-specific identifiers.
All Phases Encrypted
Every phase, from VPN connection establishment and authentication to traffic billing and user data transmission, is fully encrypted with AES-GCM-256.
		



























One of the best VPNs I ever used! It's easy and super quick to set up and since School wifi is not the best this VPN is incredibly reliable and I am able to use my apps would recommend definitely.