Step 1: Encrypt
Your device encrypts traffic before it leaves, using AES-256
No jargon — just what actually happens to your connection between your device and the sites you visit.
Your device encrypts traffic before it leaves, using AES-256
Traffic travels through a VPN server instead of directly to the destination
The destination sees the VPN server's IP address, not yours
Leak protection and a kill switch cover the connection if anything goes wrong
When KeenVPN is active, your device encrypts your traffic before it leaves, using AES-256 encryption. That encrypted traffic travels to a KeenVPN server first, rather than going straight to the website or app you're using. From there, it's decrypted and sent on to its destination, which sees the VPN server's IP address instead of yours.
That's the whole core mechanism: encryption plus rerouting. Everything else — kill switches, leak protection, split tunneling — exists to keep that mechanism from failing quietly.
It hides your traffic content and real IP address from your ISP and from the sites you visit, and it protects your connection on networks you don't control. It does not make you anonymous online in every sense — a site you log into still knows it's you. See our fuller, more direct take on VPN capabilities and limits in the KeenVPN Manifesto.
Common questions about how does a vpn actually work?.