Overview
The VPN can be enabled or disabled through the Enigm ecosystem where the feature is available and permitted by policy. The VPN is independent from message encryption. Enigm secure messaging and secure calls use app-level security models. VPN protection operates at the network transport layer and addresses different risks.Purpose
The VPN is designed to provide optional transport protection for network traffic. It can reduce visibility from intermediate network observers and can help protect users on untrusted local networks. The VPN can help mitigate:- Network observation.
- Untrusted local networks.
- Public Wi-Fi exposure.
- Certain metadata exposure scenarios.
Relationship With End-to-End Encryption
End-to-end encryption and VPN protection solve different problems. End-to-end encryption is designed to protect message content at the application layer so that message plaintext is not intended to be accessible to server-side components or intermediate network observers. The VPN is designed to protect transport context by reducing network-level visibility from local or intermediate observers. The VPN does not decrypt, inspect, or define Enigm secure messaging content. Secure messaging and secure calling must remain protected even when the VPN is disabled.Network Privacy
The VPN can provide additional network privacy by reducing exposure to local network operators, public access networks, and certain intermediate observers. Network privacy benefits may include:- Reduced local network visibility.
- Reduced exposure on public Wi-Fi.
- Reduced visibility of some transport-level metadata.
- Policy-aligned network path protection where enabled.
Transport Protection
The VPN is a transport protection layer. It can help protect traffic between the user device and network-facing services from certain network observation risks. Transport protection is distinct from:- Message content encryption.
- Device trust.
- Account authentication.
- Call participant verification.
- User or contact trust decisions.
Device Trust Considerations
The VPN does not make compromised devices trustworthy. Device trust remains governed by:- Device enrollment state.
- Device revocation state.
- Device association.
- Protected key material.
- Local unlock state.
- OS security posture.
- Optional Enigm OS Trust state where deployed.
Optional Usage Model
The VPN is optional. Users may enable or disable it through the Enigm ecosystem where supported by product configuration and deployment policy. Optional usage means:- Enigm App functionality must not depend on VPN availability.
- Secure messaging must remain end-to-end encrypted whether the VPN is enabled or disabled.
- Secure calls must maintain their own session security model whether the VPN is enabled or disabled.
- Policy may require or restrict VPN use in managed deployments.
Security Limitations
The VPN does not mitigate:- Compromised endpoints.
- Malware with sufficient privileges.
- Device compromise.
- Social engineering.
- Message disclosure by trusted participants.
- Incorrect user trust decisions.
- Weak device security posture.
- Plaintext exposure after authorized local decryption.
- End-to-end encryption.
- Device security.
- Account security.
- Secure key management.
- User or contact verification.