Security — CipherVPN
SECURITY & DISCLOSURE

Security at CipherVPN

Our commitment to protecting your data, our platform, and the communities that depend on CipherVPN for privacy-first network access.

Report a Vulnerability security.txt

Security Architecture

CipherVPN is built on a security-first architecture with multiple layers of protection.

WireGuard Encryption

Modern cryptographic protocol with ChaCha20-Poly1305 encryption, providing state-of-the-art performance and security.

Zero Traffic Logging

We do not log, monitor, or store VPN traffic content. Only minimal connection metadata required for service operation is retained.

DNS Leak Prevention

All DNS queries are routed through encrypted tunnels, preventing DNS leaks and ensuring your browsing activity remains private.

Kill Switch

Enforced kill switch blocks all internet traffic if the VPN connection drops, ensuring your IP is never exposed.

Infrastructure Hardening

Our servers run hardened operating system configurations with regular security patching and access control enforcement.

Transparency

We publish transparency reports detailing any legal requests we receive and how we respond to them, consistent with applicable law.


Responsible Disclosure Policy

If you discover a security vulnerability in our services, applications, or infrastructure, we want to hear from you. We are committed to working with security researchers to verify and address reported issues promptly.

Security Contact

security@ciphervpn.eu

All security vulnerability reports are handled confidentially.

View security.txt

What to include in your report

  • 1 A clear description of the vulnerability and its potential impact
  • 2 Step-by-step instructions to reproduce the issue
  • 3 Any proof-of-concept code, screenshots, or video demonstrations
  • 4 Your contact details for follow-up communication
  • 5 Affected system, URL, component, or version if known

Our commitments to researchers

  • Acknowledge receipt of your report within 72 hours
  • Investigate and verify all legitimate reports
  • Keep you informed of our progress throughout the process
  • Not pursue legal action for good-faith disclosures
  • Credit researchers in our security acknowledgements

Out of Scope

• Social engineering attacks against CipherVPN staff

• Physical attacks against CipherVPN infrastructure

• Denial of service attacks

• Spam or automated scanning without prior approval

• Vulnerabilities in third-party software or services

• Accessing or modifying user data without permission