Protect data in transit
A VPN should help protect communication while it travels across public Wi-Fi, shared networks, mobile networks, hotels, airports, and other networks users do not control.
A good VPN is not defined only by whether a tunnel connects.
A VPN should help protect communication while it travels across public Wi-Fi, shared networks, mobile networks, hotels, airports, and other networks users do not control.
A professionally designed VPN should use modern and reviewed cryptographic protocols and avoid relying on secrecy or obscurity alone.
The tunnel should be established only with trusted infrastructure. Endpoint identity, authentication, and configuration delivery matter as much as tunnel creation.
Good VPN design should consider both IPv4 and IPv6. Dual-stack environments should be tested as dual-stack environments.
The application should verify that the expected secure path is ready before reporting that protection is active.
If activation cannot be completed, a VPN should avoid leaving the user in an incomplete or confusing network state.
Users should have understandable connection status, troubleshooting information, and visibility into whether the tunnel is active.
VPN software should be distributed through trusted paths with verifiable release information such as checksums where available.