The whole path, drawn
“Encrypted” means nothing without saying between which two points. Here is every hop your traffic takes, which of those machines are ours, and the one leg that runs in the clear.
Four hops, one tunnel
Select a hop to see what the machine at that point can and cannot see.
Your device
Encryption starts here. The app holds your keys, and the kill switch blocks traffic until the tunnel is confirmed up.
Every state the app can be in
There are four, and no fifth. Two of them look identical, which is a decision rather than an oversight.
Not connected
traffic going out as itselfNothing is intercepted. This is the only state in which your own address is visible.
Connecting
traffic blockedThe kill switch is installed before the handshake starts, so nothing leaves in the clear during this window.
Protected
Frankfurt, GermanyThe tunnel is confirmed up and every route points into it.
Connecting
traffic blockedA node rebooted and rotated its key, so the app refetched the relay list and is trying again. Identical to the state before it, on purpose.
The connecting and reconnecting cards are identical because the app cannot tell a first handshake apart from a retry after a node rotated its key — and should not try. Keys regenerate on every reboot, so a red banner there would be an alarm that fires during normal operation, which trains you to ignore it.
The apps themselves
Captures of each client in use. Reserved rather than filled with stock imagery, which would show a product that does not look like ours.
Desktop — connecting, then protected
Mobile — the connect screen and the location list
CLI — shield up, shield status, shield down
What this does not do
What this does not do: protect a device that is already compromised, hide you from a site you sign into, or defeat an adversary watching both ends of the network at once. The full threat model, including what we cannot defend against, is published.