Trust Center

Security Overview

WireGuard Wave A design and honest security boundaries.

Published August 2, 2026 · Editable in admin CMS

Security Overview

4Anox encrypts your supported traffic between the app and our VPN servers. This page describes the Wave A design in honest terms — not marketing theater.

Protocol (Wave A)

  • WireGuard is the primary tunnel protocol for Android Wave A.
  • Keys are generated and handled according to our key-management design; private keys are not logged.
  • Additional protocols (e.g. OpenVPN, IKEv2) are planned as post-MVP complements — not claimed as available until shipped.

What the tunnel protects

When connected, traffic that is routed through the VPN tunnel is encrypted to our exit server. Your apparent public IP for that traffic becomes the server’s IP in the selected region.

What a VPN does not magically fix

  • Compromised devices or malware
  • Phishing and account takeovers
  • Sites that already know you via login cookies
  • Local network policies you are not allowed to bypass

We do not claim “military-grade,” “unbelievable anonymity,” or guaranteed protection against every threat.

App & platform security

  • Entitlements for paid features are enforced server-side, not only on the device.
  • HTTPS for API calls; certificate and config delivery follow our control-plane design.
  • Kill switch / Always-on VPN behavior will match store-approved and documented semantics — we will not invent leak-protection claims ahead of implementation.

[FEATURE_CONFIRMATION_REQUIRED] Kill switch details must match shipped Android behavior before marketing them.

Infrastructure

  • VPN nodes are provisioned separately from the marketing site.
  • We do not list or operate Israel (IL) locations (product policy).
  • First launch regions include Singapore, US-East, UK, Germany, and Netherlands — see Servers.

Reporting a vulnerability

If you believe you found a security issue in 4Anox clients or infrastructure, email security@4anox.com. Please avoid public disclosure until we have had a reasonable time to respond.

A formal vulnerability disclosure program (VDP) page may be added later under Trust Center P1.

Related

Logging Policy · Privacy · Contact