501D / SECURITY
Security architecture
Small boundaries, explicit ownership, and reversible network changes.
Privileged service boundary
The Windows interface does not apply routes or configure the tunnel directly. Those operations run in a dedicated Rust service behind a narrow command boundary.
Tunnel ownership
VoidPN distinguishes its own running tunnel from an externally managed service. Durable ownership supports safe restart reconciliation without taking over an unknown connection.
Transactional recovery
Network changes are tracked so partial setup failures can restore prior state. A recovery-required state remains explicit when cleanup cannot be confirmed.
Scope
This architecture reduces accidental interference with system networking. It does not make applications, accounts, or devices immune to compromise.