Security

Security

Last updated·

This page covers the technical measures CarrotVPN uses to protect your connection, and how to report a security issue if you find one. For what data we collect (and don't), see our No-Logs Policy and Privacy Policy.

Encryption Protocol

CarrotVPN uses WireGuard® as its underlying VPN protocol. WireGuard is open-source, uses modern cryptographic primitives (ChaCha20 for encryption, Poly1305 for authentication, Curve25519 for key exchange), and its protocol design has been formally analyzed and published in peer-reviewed academic research. Read more in our plain-language WireGuard explainer.

Authentication uses WireGuard's cryptographic key-pair model rather than a username/password system — a key pair is generated on your device at install, which is what lets CarrotVPN work without requiring an account. See how our no-account model works for details.

Built-In Protections

Kill Switch

If the VPN connection drops unexpectedly, the kill switch blocks internet traffic until the tunnel reconnects, preventing your real IP from being exposed during the gap. See our kill switch explainer.

DNS Leak Protection

DNS queries are routed through the encrypted tunnel rather than your network's default DNS resolver, so your ISP or network operator can't see which domains you're looking up. See our DNS leak protection explainer.

Split Tunneling

Choose which apps route through the VPN tunnel and which use your regular connection directly. See our split tunneling guide.

Server Infrastructure

CarrotVPN operates servers across multiple global locations. Server access is restricted to operational personnel, and because VPN activity logs are never generated in the first place (see our No-Logs Policy), there is no activity data sitting on servers to be at risk in the event of a breach.

Reporting a Security Issue

If you've found a security vulnerability in the CarrotVPN app or our infrastructure, please report it to support@vinnorokom.com. Include enough detail to reproduce the issue. We ask that you give us a reasonable opportunity to address the issue before any public disclosure, and we will not pursue legal action against good-faith security research conducted within these terms.

What We Can't Promise

No VPN, including CarrotVPN, can guarantee absolute, unbreakable security — and we'd rather say that plainly than make a claim we can't back up. What we can commit to: using a modern, publicly reviewed protocol (WireGuard®), not collecting VPN activity logs that could be exposed in a breach, and responding to legitimate vulnerability reports. CarrotVPN's own infrastructure has not yet undergone a formal third-party security audit; if and when it does, that will be reflected here.

Built on WireGuard®

Modern encryption, kill switch, DNS leak protection — free on Android.

Download CarrotVPN Free