AES-256-GCM Encryption
All tunnelled traffic is encrypted with AES-256-GCM, with Perfect Forward Secrecy for session keys.
Everything a security review needs to know about how PrivyNet protects your data - encryption, infrastructure isolation, data handling, incident response, and compliance - in one place.
What actually protects your traffic in transit
All tunnelled traffic is encrypted with AES-256-GCM, with Perfect Forward Secrecy for session keys.
Built into virtually every OS - connect with your device's native VPN client, no app install required.
A modern, low-overhead protocol built for restrictive networks, secured over TLS.
Node software is kept current with security updates as they're released.
Full technical detail is available in our Security & Privacy help article.
Every customer gets their own dedicated node - never shared, never multi-tenant
Each customer gets an isolated VPN node - no shared processes with any other customer.
No shared routing between tenants - traffic paths never cross customer boundaries.
Every deployment gets its own resource group and virtual machine in Azure, not a shared multi-tenant box.
Admins can revoke a user's access immediately from the dashboard - no waiting on a support ticket.
See how this is built in our Dedicated VPN Infrastructure overview.
What we don't log, and what limited data we do retain
We never log the websites you visit, your DNS queries, or your traffic content.
Limited connection/security metadata (e.g. IP address, login times) is retained for a fixed period for account security and abuse prevention, not indefinitely.
Exactly what's collected and for how long is documented - no vague promises.
Full retention periods are set out in our Privacy Policy.
Our commitments, in writing
PrivyNet Ltd is registered in England and Wales and acts as data controller under UK GDPR. See our Privacy Policy for your rights and our obligations.
A Data Processing Agreement is available, including a 72-hour breach notification commitment. View our DPA.
99.9% uptime and defined incident response times are governed by our Service Level Agreement.
Account data is stored in the UK and EEA. Your VPN infrastructure itself is deployed in whichever of our 50+ regions you choose, giving you control over where that data lives.
You can request full account deletion at any time; we permanently delete your personal data within 30 days. See our Privacy Policy for the full retention and deletion schedule.
Cyber Essentials certification is on our roadmap. We'll update this page once it's achieved.
Privacy Policy, Terms of Service, Acceptable Use Policy, SLA, and DPA are all available from our Legal Hub.
The questions your finance, legal, or IT team will ask before signing off
No. PrivyNet is consumption-based - you're billed for what you use, with no fixed-term lock-in.
Billing is processed through Stripe. Invoices are available for download from your dashboard, so you can expense them or attach them to a purchase order.
Yes. A DPA is available, including a 72-hour breach notification commitment. View our Data Processing Addendum for the full terms.
99.9% uptime with defined incident response times, set out in our Service Level Agreement.
You can request full account deletion at any time. We permanently delete your personal data within 30 days, as set out in our Privacy Policy.
Email our security team directly using the contact button on this page - most vendor security reviews can be answered from this page plus our Privacy Policy and DPA.
Account data is stored in the UK and EEA. Your VPN infrastructure itself is deployed in whichever of our 50+ regions you choose.
Talk to us directly - most vendor security reviews can be answered from what's on this page plus our Privacy Policy and DPA.