Security

Engineered to be checkable.

Privacy is only as strong as the engineering behind it. Here's the security that protects every Room VPN connection, on every device.

X25519 + XChaCha20-Poly1305

Each session starts with an ephemeral key exchange; every control message is sealed under its own nonce.

Encrypted to the exit

Where the exit presents a certificate this app has pinned, traffic is encrypted the whole way and the relay only ever sees ciphertext.

Automatic kill switch

If the tunnel drops, your connection is cut rather than falling back to the open internet.

Traffic routed whole

The tunnel takes the default route, so what leaves your device goes through it. It does not replace your DNS resolver — your network's own is still the one answering.

The app tells you the truth

When an exit offers no certificate, traffic is readable at the relay — and the app says so instead of showing a padlock anyway.

Fresh keys every session

The handshake is ephemeral, so keys are not reused between sessions.

Read our no-logs policy.

See exactly what we keep — and everything we don't.

No-logs policy