Trust center

What we keep, and how to check.

Plain answers to the questions people ask a VPN before trusting it — with links to the documents and pages where you can verify each one.

Reviewed 25 September 2026

What DXVPN doesn't log

DXVPN doesn't log the content of your traffic, the websites you visit or your DNS queries.

  • Kept: your email, a hashed password and your username
  • Kept: plan, payment status and transaction IDs from the payment provider — never card details
  • Kept: total traffic per billing period, to enforce plan limits
  • Deleted 30 days after your subscription ends or your account is deleted

Warrant canary

A dated statement that DXVPN has received no secret orders, gag orders or demands for backdoors. If it stops being updated, treat that as a signal.

  • Latest statement dated 3 April 2026

Transparency report

The number of requests for user data DXVPN received, and how many records it handed over.

  • Latest report: Q1 2026 — 0 requests, 0 disclosures

Open-source engines

Every engine that touches your traffic is open source and can be inspected.

  • sing-box — VLESS, Trojan, VMess, Shadowsocks, Hysteria2, VLESS-WS
  • AmneziaWG
  • mtg v2 — MTProto proxy
  • AdGuard Home — DNS filtering

Hardened servers

DXVPN rents and manages its own servers.

  • Firewall (UFW) and fail2ban
  • Non-standard SSH ports
  • Services run as dedicated non-root users
  • Automatic security updates

Encryption

Modern, well-reviewed cryptography on every protocol.

  • TLS 1.3 + Reality (VLESS, Trojan)
  • ChaCha20-Poly1305 (AmneziaWG)
  • AES-256-GCM (Shadowsocks 2022)
  • bcrypt password hashes; TOTP or Telegram 2FA

Report a vulnerability

Found a security issue? Write to security@sechb.com or contact @dxvpnbot. The security.txt file lists the contacts and the PGP key.

Live status

Node availability and latency are published on a public status page.

  • Two nodes online, including the Netherlands
  • Planned: Hong Kong, Tokyo, Singapore

Legal documents

All documents →