VPNGeek
Purchase
SECURITY

Protection you can verify, not just trust

Strong, modern cryptography, a no-logs policy enforced by architecture, and infrastructure designed so there is nothing to hand over. Here is exactly how it works.

Contact security
THE STACK

Modern cryptography, everywhere

AES-256-GCM
Symmetric encryption
ChaCha20
WireGuard cipher
IKEv2 / IPsec
Standards-based tunnels
PFS · DH-14+
Perfect forward secrecy
HOW WE PROTECT YOU

Four pillars of the VPNGeek design

Audited no-logs

We don't record your browsing, DNS queries, or connection timestamps tied to your identity. The policy is enforced by how the servers are built — and verified by an independent annual audit.

RAM-only, diskless fleet

Every VPN server runs entirely from volatile memory. There are no disks to seize and no persistent state — a reboot wipes the machine clean by design.

You hold the keys

On IPsec gateways you control the ciphers, subnets, and routing. Your pre-shared keys and certificates are yours; we never escrow them.

Defense in depth

Kill switch, DNS-leak protection, and automatic failover keep traffic inside the tunnel — even when a connection drops or a server goes down.

INFRASTRUCTURE

What runs behind the tunnel

The operational choices that make the no-logs promise real rather than aspirational.

Servers
RAM-only, diskless — no persistent storage of any session data
Encryption
AES-256-GCM and ChaCha20-Poly1305; SHA-256+ integrity
Key exchange
IKEv2 with Diffie-Hellman group 14 or higher; PFS on every tunnel
Protocols
WireGuard, OpenVPN, and standards-based IKEv2/IPsec
DNS
Private, encrypted resolvers; leak protection on by default
Access
Least-privilege operator access, hardware-key MFA, audit logging
RESPONSIBLE DISCLOSURE

Found something? Tell us.

We welcome reports from security researchers. Send details to our security team and we will acknowledge quickly, investigate, and keep you updated through to a fix. Good-faith research is always welcome — we will not pursue action against researchers who follow responsible disclosure.

Encrypted reports to security@vpngeek.com (PGP key on request)Acknowledgement within one business dayCoordinated disclosure once a fix ships
Report a vulnerability

Security questions before you commit?

Talk to the people who build and run the infrastructure — not a script.

Contact security Read our no-logs policy