Connection protocols
Every server offers the same set of protocols. The app picks the one that works on your network and switches to another without interruption if one is blocked.
| Protocol | Transport and encryption | Where it helps |
|---|---|---|
| Hysteria2 | TLS 1.3 over QUIC (UDP); the server certificate comes from ACME | Fast on lossy, unstable and mobile networks |
| VLESS Reality | TLS 1.3 over TCP; Reality imitates a real site's handshake with X25519 keys and needs no certificate of its own | Restricted networks with deep packet inspection (DPI) |
| VLESS XHTTP | An HTTP-like stream over Reality | Networks that cut long TCP connections |
| Trojan | TLS 1.3 over TCP with the same certificate as Hysteria2 | TLS-based fallback where UDP is blocked |
| Shadowsocks 2022 | 2022-blake3-aes-256-gcm (AEAD) with a new key per session | Lightweight, low-latency alternative |
The apps connect to a server's domain name, not to its IP address. Server addresses, ports and keys are never published on any page; the apps receive them over an encrypted connection after signing in.
Accounts and passwords
Argon2id
Passwords are stored with Argon2id: 64 MiB of memory, 3 passes, 2 lanes, a 16-byte random salt and a 32-byte hash. We cannot see your password either.
Rate limits
Sign-in, password reset, sign-up and promo code attempts are rate-limited; sign-in and password reset are also limited per e-mail address.
E-mail verification
An account gets no VPN access until the 6-digit code from the e-mail is verified.
Sessions
Every device has its own session and connection credentials. You can sign out devices and sessions one by one from the dashboard.
App security
Android Keystore
On Android, session tokens are encrypted with a key held in the Android Keystore; the key cannot be extracted from the device.
Windows DPAPI
On Windows, session data is encrypted with DPAPI. Only administrators and SYSTEM can open the folders that hold sessions, connection settings and logs.
Certificate pinning
The Android app only accepts certificates for colitu.com and its subdomains that chain to pinned root keys (Let's Encrypt ISRG, with Google Trust Services as a backup). The pins expire on 30 September 2027 on purpose: an app that was never updated falls back to normal system trust instead of losing the API. The Windows app currently uses system certificate validation.
Private logs
The Windows app never writes the VPN cores' DNS and connection lines to its log, and masks host names and addresses in the remaining error lines.
Kill switch
The Windows kill switch is built on the Windows Filtering Platform, like the WireGuard client: if the VPN drops, traffic cannot leave outside the tunnel. The filters live in a dynamic session, so Windows removes them if the app crashes.
HTTPS only
The apps do not allow unencrypted HTTP connections.
Signed updates
Windows
The update manifest (latest.json) is signed with ECDSA P-256. The app verifies the signature with a public key built into it, then compares the installer's SHA-256 with the manifest. If either check fails, nothing is installed.
Android
The app compares the new APK's SHA-256 and its signing certificate's SHA-256 fingerprint with the release manifest; Android also checks that the APK is signed with the same key.
Matching the source
Every release is tagged on GitHub; the release page lists the commit, the files and SHA256SUMS. You can compare the checksums on the download page yourself.
Server logging policy
Access logs are off on our VPN servers: Xray writes only warnings and errors, sing-box only warnings. We do not record the sites you visit, your DNS queries or the content of your traffic. Servers only count the amount of traffic per user, for quotas and fair use.
| Data | Why | Kept for |
|---|---|---|
| Sign-in and IP history | Account security, abuse prevention | 180 days |
| Traffic per user | Quotas and fair use | 90 days; then only period totals |
| Device records | Device allowance | Until the device is removed or the account is deleted |
| E-mail delivery records | Delivery problems | 90 days |
| Visited sites, DNS, traffic content | — | Never recorded |
The full list is in the privacy policy. Expired records are deleted by an automatic job. Privacy policy →
Infrastructure isolation
Control plane and servers apart
Accounts, payments and administration run on the control plane. VPN servers hold no user database; they only receive the device keys needed to authenticate connections.
mTLS
Every VPN server connects to the control plane over mutually authenticated TLS (mTLS); a server without an identity gets no configuration.
Admin panel
The admin panel runs on a separate domain with role-based permissions; admin endpoints are closed on the public API.
Payments
Card and bank details are entered on the payment provider's page and never reach Colitu.
Web
The site is served with a nonce-based strict Content Security Policy, HSTS, CSRF protection and headers that prevent framing.
Incident response
Detection and containment
Servers and services are monitored continuously; their live state is public at status.colitu.com. During a suspected incident the affected server is withdrawn from clients and its keys are rotated.
Notification
When we confirm a breach that affects personal data, we tell the affected users by e-mail without undue delay and publish what happened and what we did on this page and the status page.
Afterwards
After every incident we share the cause and the measures taken in the transparency section.
Reporting a vulnerability
If you find a vulnerability, please report it to support@colitu.com with “Security” in the subject before sharing it publicly. We will review it and get back to you; please keep the details private until a fix is released. We will not take legal action against good-faith research. Details are in SECURITY.md in our repositories and at /.well-known/security.txt.
support@colitu.comVerify the code yourself
The Windows and Android apps are on GitHub in full under GPL-3.0.
Last updated: 1 October 2026