Trust Center

Plain facts about who we are and how we handle your data

VPN purchases are trust purchases. This page is where KloxVPN (operated by Secuno LLC) states ownership, jurisdiction, logging, vendors, payments, legal process, and audit status — without marketing filler or borrowed certifications.

Company identity and ownership

Product
KloxVPN
Legal entity
Secuno LLC
Registered address
30 N Gould Ste, Sheridan, Wyoming, USA - 82801
General contact
[email protected]
Business / compliance
[email protected]

KloxVPN is owned and operated by Secuno LLC. We are not a white-label shell of another consumer VPN brand. For enterprise documentation, see Enterprise VPN.

Jurisdiction

Secuno LLC is incorporated in Wyoming, United States. US law applies to the company. The United States is part of the Five Eyes intelligence-sharing alliance.

Jurisdiction matters for legal process. Our defense against activity disclosure is not “offshore secrecy” — it is that we do not retain VPN activity logs that could identify what you did online. If there are no activity logs, there is nothing of that kind to produce.

Account and billing records may still be subject to valid legal process. See Law-enforcement requests below.

Clear logging policy

What “no logs” means here

We do not collect, store, or correlate data that identifies your browsing, DNS queries, or traffic content on the VPN. We enforce this through internal reviews by our security team. We do not claim a third-party no-logs audit.

Full detail lives in the Privacy Policy and Security & data handling.

Data collected and not collected

We may hold

  • Account email and password hash
  • Billing records and subscription status (via payment processors)
  • Support tickets and messages you send us
  • Basic website cookies / analytics needed to run the site (see Cookie Policy)

We do not collect

  • Browsing history or destinations visited through the VPN
  • DNS queries resolved over the VPN
  • Traffic content or packet payloads
  • Connection timestamps tied to your account
  • Your real IP address while connected (we do not retain session IPs linked to you)
  • Bandwidth usage per user for tracking activity

Infrastructure architecture

  • VPN plane: Encrypted tunnels using WireGuard, OpenVPN, IKEv2, and OpenConnect. OpenVPN uses AES-256; WireGuard uses ChaCha20.
  • Server footprint: 60+ countries, 100+ servers in commercial data centers with physical and logical access controls.
  • Control plane: Account, billing status, and app/config delivery run on separate systems from the VPN data path. We do not store VPN traffic.
  • Access: Administrative access is restricted, reviewed, and limited to people who need it to run the service.
  • Enterprise options: Dedicated infrastructure and white-label deployments are available on request.

Third-party vendors

We use a limited set of subprocessors to run payments, hosting, email, and support. Enterprise customers can request a current list under NDA.

Vendor / categoryRoleNotes
StripeCard payments and billingCard data is handled by Stripe; we do not store full card numbers.
Cryptocurrency processorsCrypto payments where offeredProcessed by the payment provider; we receive payment confirmation, not wallet secrets.
Cloud / hosting providersWebsite, API, and related hostingMay hold account or operational data as needed to run the service.
Data center operatorsVPN server colocationPhysical and network hosting. They do not receive your browsing logs from us — we do not keep those logs.
Email / CRM (e.g. Brevo)Transactional and marketing email (opt-in)Used for support replies and newsletter signup where you subscribe.
Customer support toolsTickets and chatOnly what you submit in support conversations.

Payment-data handling

  • Card payments are processed by Stripe (or equivalent). We do not store full card numbers or CVV on our servers.
  • We retain what we need for subscription status, invoices, refunds, fraud prevention, and accounting.
  • Crypto payments are confirmed through the payment provider; we do not need your private keys.
  • Consumer purchases include a 7-day money-back guarantee for first-time purchases only — see the Refund Policy.

Law-enforcement request policy

We respond only to valid legal process (for example, a court order or lawful subpoena) as required by applicable law. We do not volunteer VPN activity data we do not have.

  • Activity / traffic: We cannot produce browsing history, DNS logs, or connection timelines tied to your VPN use — we do not retain them.
  • Account / billing: Where legally required and validly served, we may be compelled to disclose limited account or payment records we actually hold.
  • Notice: Where the law allows, we attempt to notify the affected user before disclosure. Some orders prohibit notice.

Transparency report

Last updated: July 19, 2026. We publish what we can verify. We will not invent request statistics to look impressive.

VPN activity / traffic / DNS logs producedNone — not retained
Account / billing disclosures under legal processNot yet published as counts*
Public numerical LEA reportIn progress

*We will add annual counts once we maintain a consistent public logging process for legal requests. Until then, the structural fact remains: we cannot produce VPN activity logs we do not keep.

Service status

We do not currently operate a separate public status page with automated probes. Inventing a fake “all green” badge would undermine trust.

  • For outages or regional issues, contact Support or email [email protected].
  • Significant incidents that affect availability or personal data will be communicated as required by law and, where practical, to affected customers.

Security contact

Report security issues to [email protected] with subject line starting with [SECURITY].

For product support (not vulnerabilities), use /support or [email protected].

Vulnerability disclosure policy

  1. Email [email protected] with a clear description, steps to reproduce, and impact.
  2. Give us a reasonable window to investigate before public disclosure (typically 90 days; we will confirm receipt).
  3. Do not access other users’ data, disrupt service, or violate the law while testing.
  4. We will not pursue legal action against good-faith researchers who follow this process.
  5. We may credit researchers who want attribution; we do not currently run a paid bug bounty.

Audit and compliance status

What we are

  • SOC 2–aligned controls / SOC 2 compliant practices (we maintain requirements)
  • GDPR-aligned data handling practices
  • HIPAA-ready discussions for enterprise (not “HIPAA certified”)
  • No-logs policy enforced by internal security-team reviews

What we are not (yet)

  • Not SOC 2 certified — no formal third-party SOC 2 attestation report
  • Not independently audited for no-logs by a named third-party firm
  • Not ISO 27001 certified

Enterprises can request our SOC 2–style questionnaire (control mapping, not a certification report) at [email protected].

Vendor compliance vs KloxVPN compliance

Cloud hosts, payment processors, and data centers often hold their own certifications (for example, a provider’s SOC 2). That is their attestation for their systems.

It does not mean KloxVPN or Secuno LLC is SOC 2 certified. We will not answer “Is KloxVPN SOC 2 certified?” with a vendor’s certificate.

When we say we are SOC 2 compliant / aligned, we mean we maintain controls consistent with common SOC 2 themes in how we run our product — not that an auditor has issued a Type I/II report for us.

Related documents

Prefer a written questionnaire? Email [email protected].

Cookie Settings

We use cookies to enhance your experience, analyze traffic, and personalize content. By clicking "Accept", you consent to our use of cookies.