Nettica VPN Knowledge Base

Build Your Own Secure Cloud!

Have a Question?

Search or ask here!

What makes Nettica VPN special?

Let’s face it; there are lots of VPN options out there. Why should you use Nettica instead of one of the other solutions?

Privacy

We take the P in VPN (Virtual Private Network) very seriously; it’s our reason for existence. To protect your privacy, we prevent all tracking by Google across all our apps. (We cannot prevent Google from tracking when you open the Android app, nor Apple from tracking when you open the iOS app, but that is true for all apps on those platforms. All other VPNs also have this constraint.)

We refuse to run personalized ads, even though that reduces the effectiveness of our ad strategy. We believe ad personalization is a severe invasion of privacy, and we do not believe that the data gathered for personalization is truly “anonymized”. We won’t collect your private data, and we won’t use services that use your private data.

We separate our administrative control panel from our main website to ensure absolutely no tracking is done while you’re managing your services and networks. If you allow cookies on our main website, we do report some usage data to Google, but never on the admin page. If you deny cookies on our main website, we report nothing to anybody but ourselves.

We do not use Google fonts directly from Google, because Google also tracks users through font downloads. Instead, we host all our fonts locally. Nobody can learn anything about your use of our websites except us.

Passwords

We do not want to know your password. We do everything we can to avoid learning your password. If you use Apple, Google, or Microsoft as your authentication method, we will never see your password. (If you use Nettica authentication, we still won’t see it, but we’d still prefer to have you use the major services instead.)

We do not support OpenVPN because by default, OpenVPN sends your password in clear text to the server, and if you use OpenVPN’s auto-login feature, stores it in clear text on your device too. The channel is encrypted, but the server receives your credentials in clear text, and may store it in clear text as well. We only support WireGuard, which uses public-key/private-key encryption. Your private key is generated on your device automatically, and never leaves your device. Your public key is only transmitted when necessary. Every packet you send is encrypted with your private key and decrypted with your public key, so no password ever needs to be handled by Nettica endpoints or any endpoints that you create for yourself.

Service management is authenticated with the OAuth2 protocol, which is token-based. Logging in to Apple, Google, or Microsoft grants you a token, and we validate that token and use it to control your access to the service.

You will never see a breach report saying Nettica has exposed your password, because we don’t have it. In the unlikely event that we are compromised, the most that anyone can gather from us is your email address.

Privately Held Company

Nettica is not publicly traded. We do not have any obligation to venture capitalists or anonymous shareholders to “maximize share price at all costs”. We know that it is impossible to serve two masters, and we want to keep it crystal clear in everyone’s minds (especially ours!) that our only focus is you, our customers.

We want Nettica to be a long-term business, and we want to build the company’s value on actual revenue, not on the share price. We believe that transparency and building for the long run is the only way we get to the point where you trust us to protect your data and traffic.

Open Source

Nettica is open source; you can find our codebase on Github. That means you don’t have to just take our word about our security and no-logs policies, you can see for yourself, and monitor us for any changes after you sign up!

Geographical Flexibility

Your IP address tells other computers how to send information to you, and the IP address your ISP gives you can be used to discover exactly where you are. Many large VPN providers do not offer a choice of location (think Google VPN, Cloudflare Warp, etc.).  Their services only provide a VPN from your current or nearby location. Nettica VPN is one of only a few VPN providers that let you choose which geographical region that IP address comes from.

You may be located somewhere that your Internet access is “curated” or restricted; with Nettica VPN’s geographical flexibility, you can bypass those restrictions and see what the Internet looks like from, for example, Canada (for curling fans) or Australia (for Tim Tams fans).

Nettica lets you choose from (as of the time this page was last updated) 22 different regions, spread across 19 countries and 6 continents.

Infinitely Granular Subnet Routing

Nettica VPNs use the “Allowed IPs” field in the service configuration to determine whether Internet connections from the user go through the VPN or not. Requests from the user to any IP address in the “Allowed IPs” list will go through the VPN, while requests to any other IP address will go through the user’s ISP. The “Allowed IPs” field allows any combination of IP address ranges and individual IP addresses. By adding the IP range 0.0.0.0/0, all Internet traffic from users will go through the VPN. By adding or removing the network’s configured IP/DHCP range, you can allow or prevent user devices from communicating with each other. By adding or removing ranges and/or addresses on the VPN’s physical segment, you can allow or prevent user devices from accessing specific resources on your internal network.

In the Wild

If you like the idea of a VPN, but want more control over the actual service, or want to locate your VPN somewhere that Nettica VPN does not have a presence, then you want to use our In the Wild service.

In the Wild is a feature unique to Nettica VPN. Nettica’s admin service is open source, which means you do not have to rely on our infrastructure. You can install and run your own Nettica VPN server and keep your own domain, authentication, and database in your own infrastructure and under your exclusive control. You can add tunnel and relay VPN services directly on your local server. You can run Nettica VPN In the Wild on a device as small as a Raspberry Pi, on your own cloud virtual machine, or on any Linux machine you own. Your users can connect to your In the Wild VPNs exactly the same way they do to VPNs hosted by Nettica. If you’d like to mix and match your own VPN server with Nettica’s regional tunnels or relays, you can add those services to your In the Wild VPN server. (We call it “In the Wild” because by design we don’t know anything about the devices we’re providing service to.)

Docker Containerization

Along with our apps for all the major desktop and mobile platforms, we also publish a plug-and-play Docker container with everything you need to create your own In the Wild VPNs wherever you want.

Tags: