Security

How HarmanVPN protects a connection

HarmanVPN combines a WireGuard-based VPN tunnel with on-device private keys, TLS-protected APIs, account controls, and short-lived VPN access tokens.

HarmanVPN does not claim that an independent security audit has been completed.

VPN tunnel

When you connect, HarmanVPN creates a WireGuard-based tunnel between the Android device and the selected active VPN node. Traffic is encrypted across that tunnel until it exits from the selected node.

On Android, WireGuard private keys are generated on the device and stored encrypted using Android Keystore-backed key material. HarmanVPN receives the public key needed to operate the peer, not the private key.

Account, API, and device security

HarmanVPN uses TLS for API traffic, one-way password hashes, email verification, password reset flows, and short-lived VPN access tokens.

Protecting the device, screen lock, email account, and HarmanVPN password remains the user’s responsibility. No transmission or storage method is perfectly secure.

  • Android displays its standard VPN permission prompt before a tunnel can start.
  • Android authentication tokens and persistent VPN private-key material use encrypted, platform-backed storage.
  • Login and security events may be processed to protect accounts and prevent abuse.

What a VPN cannot guarantee

A VPN does not provide absolute anonymity, make an unsafe device secure, prevent every website from tracking its own users, or guarantee access to a particular site, app, or streaming service.

The current product does not claim a kill switch, split tunneling, malware blocking, or completed independent security certification.

Report a security issue

Send a concise description, affected component, reproduction steps, and impact. Do not include access tokens, passwords, private keys, or unrelated personal data.

support@harmanvpn.com