SecureNet Add-On

Private Browsing You Can Verify

WireGuard VPN with zero DNS logging, published configurations, and weekly security audits. GlassBox security for SecureNet customers.

$9 /month or $89/year
0 DNS Queries Logged
1M+ Blocked Domains

What SafeNet Is (and Isn't)

SafeNet is more than a VPN. It's private browsing + full support + real-time transparency for SecureNet customers with Protectli Vaults. Connect to a SafeNet network and all your traffic automatically routes through our Chicago server. No apps to install, no per-device configuration.

30 Days Free

Every SecureNet system includes a full month of SafeNet free. Experience private browsing, real-time server monitoring, and full support for your OSS system.

Love it? Add a payment method to continue. Don't need it? It simply expires. No cancellation required.

Important: SafeNet is exclusive to SecureNet systems on Protectli hardware. It is not a standalone VPN service you can purchase separately.

What SafeNet Includes

🔒

Private Browsing VPN

Your ISP sees only encrypted WireGuard traffic. They cannot see what websites you visit, what you search for, or what you do online.

🛠️

Full Support

Everything OSS touches is supported. SecureNet configuration, SafeNet connectivity, hardware issues. Open a ticket, get help.

🔍

GlassBox Transparency

Weekly security audits, daily filesystem snapshots, published configs. Verify every claim yourself. No other VPN offers this.

What SafeNet Is NOT For

Travel or Coffee Shops

SafeNet protects your home network only. When you're at Starbucks, your phone isn't tunneled through SafeNet (unless you use a separate mobile VPN).

🎬

Streaming Services

Netflix, Hulu, Disney+, and YouTube are blocked by design. Streaming services also actively block VPNs anyway.

🎮

Gaming or Torrenting

UDP traffic is blocked to manage bandwidth and protect the service. Use your regular network for gaming.

How It Works

SafeNet creates an encrypted WireGuard tunnel between your Protectli Vault and our Chicago server. Traffic on SafeNet networks is automatically routed through this tunnel.

Traffic Flow
Your Device
Vault Encrypts
ISP (sees encrypted blob)
Chicago Server
Internet

Websites see: Chicago IP address  |  Your ISP sees: Encrypted WireGuard packets

Connecting to SafeNet

Method How Subnet
SafeNet WiFi Connect any device to the SafeNet SSID (VLAN 60) 10.60.60.0/24
SafeNet Port Plug into Port 3 on the Vault (wired devices, switches) 10.70.70.0/24
Regular Networks Home, Smart, Guest networks route directly to ISP 192.168.x.x
Visual Confirmation

If your device has a 10.x.x.x IP, your traffic is being tunneled. If it has a 192.168.x.x IP, you're on a regular network. Check at whatismyip.com to verify you see a Chicago IP address.

WireGuard Protocol

SafeNet uses WireGuard, a modern VPN protocol with approximately 4,000 lines of code (compared to OpenVPN's 100,000+), making it faster, simpler, and easier to audit. The encryption stack uses ChaCha20, Poly1305, Curve25519, and BLAKE2s. For complete protocol details, see the AI Whitepaper.

Support Included

SafeNet isn't just a VPN. It's your support subscription for your entire OSS system. As long as you're a SafeNet subscriber, you have full support for everything OSS touches.

What's Covered

SecureNet configuration, SafeNet VPN connectivity, OPNsense questions, hardware troubleshooting, WiFi access point issues, network segmentation, Monit alerts, and anything else related to your OSS system.

What's Not Covered

Third-party devices on your network (NAS, Ubiquiti switches, smart home hubs). If we trace an issue to third-party hardware, we'll let you know and point you in the right direction.

🎫

How It Works

Open a ticket through our support portal. Best effort response during business hours. Thorough written support with video guides for common issues.

🔧

Hardware Support

Even without SafeNet, we support hardware issues. Protectli backs the hardware with a 2-year warranty and ships replacements before you return the defective unit.

Proactive Support (Opt-In)

During onboarding, you can opt into proactive monitoring. Your Vault's Monit system sends alerts to both you and OSS. If we see something concerning (LAN port down, CPU pegged, disk filling up), we email you before a small issue becomes a big problem. This is daily alert review, not a staffed 24/7 NOC.

Support Tiers

Customer Type Support Level
SafeNet Subscriber Full support for everything OSS touches. Troubleshooting, guidance, proactive monitoring (if opted in).
Non-Subscriber (after trial) Hardware support only. Troubleshooting guide provided. Confirmed hardware failures coordinated with Protectli RMA.
Out of Warranty (2+ years) Best-effort guidance. Hardware replacement at customer expense.

Browse-Only Policy

SafeNet enforces a browse-only policy by design. This isn't a limitation. It's how we keep the service fast, legal, and affordable for everyone.

✓ Allowed

  • • Web browsing (HTTP/HTTPS)
  • • Email (IMAP, SMTP, POP3)
  • • Mobile apps (most use TCP)
  • • Embedded video in web pages
  • • Standard TCP protocols

✗ Blocked

  • • Streaming (Netflix, Hulu, Disney+, YouTube)
  • • Torrenting / P2P
  • • UDP gaming
  • • VoIP / Video calls (Zoom, Teams, Discord)
  • • FTP

Enforcement works at two levels: UDP is blocked at the protocol level (kills streaming, gaming, VoIP), and streaming CDNs are filtered at DNS (netflix.com, disneyplus.com, etc. return NXDOMAIN). This keeps bandwidth manageable across 200+ customers sharing 10 Gbps, eliminates piracy liability, and keeps the price at $9/month.

Note on VoIP: VoIP quality suffers through any VPN tunnel due to latency. Your other networks (Home, Smart, Guest) have unrestricted internet with QoS priority for voice traffic. Use those for video calls.

Privacy Architecture

Most VPNs ask you to trust them. We give you the tools to verify. Here's exactly what we log, what we don't, and what that means for your privacy.

Server KNOWS Server DOES NOT Know
Your WireGuard public key Your name or identity
Your tunnel IP (10.x.x.x) Your home IP address
Total bandwidth used Which websites you visit
That a peer is currently connected DNS queries (logging disabled in Unbound)

If the Server Were Compromised or Subpoenaed

Scenario What Exists On Server What Does Not Exist
Government subpoena Public key, tunnel IP, bandwidth total DNS queries, browsing history, timestamps
Server compromise Peer configs, current connections Customer names, DNS history, browsing data
ISP request Encrypted packets to/from server Any content or queries
Verify It Yourself

All server configurations are published on Forgejo. You can verify that DNS logging is disabled, check our firewall rules, and see exactly what's running. Better yet, check the GlassBox Verification portal below.

GlassBox Verification

Every week, our server runs a battery of security scans and publishes the raw results. No editing. No cherry-picking. You get the same output our team sees. This is what "open source security" actually means.

🛡️

Lynis Security Audit

Full system security audit covering SSH, firewall, file permissions, kernel parameters, and 200+ other checks.

View Report →
🐛

Rootkit Hunter

Scans for 498+ known rootkits, backdoors, and trojans. Verifies system binaries haven't been replaced.

View Report →
🔒

AIDE File Integrity

Compares current system files against a cryptographic baseline. Any unauthorized change is logged and reported.

View Report →

Daily Server Snapshot

Every day at 5:00 AM EST, the server generates a complete filesystem snapshot with SHA-256 checksums of every configuration file. Compare these hashes against the files published on Forgejo to verify nothing has been modified.

================================================================================ SAFENET CHICAGO 01 - FILESYSTEM VERIFICATION SNAPSHOT ================================================================================ FILE CHECKSUMS (SHA-256) /etc/wireguard/wg0.conf [Interface only] c36adb87ba37d3c2... /etc/unbound/unbound.conf 8808b474175ff8ee... /etc/unbound/unbound.conf.d/safenet.conf 74427ad48f3842e9... /etc/iptables/rules.v4 360bebfe068d07e0... /etc/fail2ban/jail.local f5d0283fb94e496b... /etc/ssh/sshd_config 30d2dac64c52f2ed... ... 21 files checksummed total SERVICE STATUS WireGuard (wg0): active Unbound DNS: active nginx: active fail2ban: active DNS Blocklist: 1,462,896 domains IP Blocklist: 41,686 addresses

View Full Snapshot →   |   Verification Portal →   |   Forgejo Source →

What Else We Publish

Resource What It Shows Link
Live Server Metrics CPU, RAM, disk, network usage updating every 5 seconds status.oss-vpn.net →
DNS Blocklist The exact domains being blocked on your connection dns-combined.txt →
IP Blocklist The exact IPs being blocked at the network level ip-combined.txt →
Source Code All server configuration scripts and blocklist tooling Forgejo →

All reports are plain text. No accounts, no JavaScript required. Download them with curl and inspect them yourself. If something looks wrong, email us. We want to know.

Pricing & Free Trial

Simple, transparent pricing. No data caps. No device limits. One price covers your entire household, plus full support.

30 Days Free with Every SecureNet System

Your trial starts on onboarding day. Full access to everything: VPN, dashboard, support.

Add a payment method to continue after your trial. No hassle if you don't.

SafeNet VPN + Support

$9 /month

Or $89/year (save 18%)

First month included free with SecureNet consultation
Cards, Apple Pay, Cash App Pay, Google Pay, and Link accepted via Stripe

What's Included

  • Private browsing VPN through Chicago server (LA and Virginia coming soon)
  • Full support for everything OSS touches
  • Proactive support option (opt-in Monit alerts)
  • GlassBox verification portal with weekly security audits
  • • WireGuard encryption for all SafeNet traffic
  • • Zero DNS query logging
  • • Unlimited bandwidth (no caps)
  • • Unlimited devices (entire household)
  • • First access to new features

What Happens When Trial Expires?

If You Subscribe If You Don't
Add a payment method and everything continues. VPN, support, dashboard access. No interruption. SafeNet quietly expires. No cancellation needed, no awkward emails. Your SecureNet still works, you just lose VPN and full support.

Hardware support continues regardless: Even without SafeNet, we support hardware issues. If your Vault fails, Protectli ships a replacement before you return the defective unit. SafeNet subscription covers software, configuration, and ongoing support.

Is SafeNet Right for You?

✓ Good Fit

  • ✓ You want ISP privacy while browsing at home
  • ✓ You want support for your OSS system
  • ✓ You want whole-network VPN without per-device apps
  • ✓ You value transparency and verification over trust
  • ✓ You understand browse-only restrictions
  • ✓ You already have (or are buying) SecureNet

✗ Not a Good Fit

  • ✗ You need VPN for streaming services
  • ✗ You need VPN for gaming (UDP)
  • ✗ You need travel/mobile VPN protection
  • ✗ You want to torrent
  • ✗ You're comfortable troubleshooting on your own
  • ✗ You don't have SecureNet hardware

Remember: SafeNet is optional. SecureNet provides enterprise-grade security with or without SafeNet. The subscription adds VPN privacy, full support, and proactive monitoring. It's not required for network protection.

Roadmap

SafeNet is just getting started. Here's what's coming for subscribers.

🌎

LA & Virginia Servers

Additional server locations for better geographic coverage and lower latency.

Coming Soon
🤖

AI Log Analysis

Automated analysis of your system logs to catch issues before they become problems.

Planned
👁️

24/7 Active Monitoring

Staffed monitoring with immediate response to critical alerts, not just daily check-ins.

Planned
Subscriber Benefits

SafeNet subscribers get first access to new features as they roll out. Your subscription supports continued development of the platform.

Ready for Private Browsing + Full Support?

SafeNet is included free for your first 30 days with SecureNet. Schedule a free intro call to learn more about the complete system.