BoltVeil is a VPN and residential proxy service. This page explains how we protect your account, your payments and your connection details. It describes what is in place today, not plans. What we store about your use of the VPN, and what we never store, is listed in the No-logs Policy.
Where your data lives
- Hosting: our website, API and database run on servers at Hetzner Online GmbH in Germany (European Union).
- Connections to us: the website, your dashboard and the API our apps use are served only over HTTPS (TLS), with HSTS.
- VPN servers: run by our network partner under contract with us, in the countries listed on the server page. We do not own or operate them. The No-logs Policy explains what the partner keeps and what it does not.
What we store, and how
| Data | How it is stored |
|---|---|
| Your password | Hashed with bcrypt. Nobody at BoltVeil can read it |
| Your VPN password and WireGuard private key | Encrypted at rest (AES-256), decrypted only to build your configuration or show your login details to you |
| Your proxy password | Encrypted at rest (AES-256) |
| Two-factor authentication | The secret is encrypted at rest; recovery codes are kept only as one-way hashes |
| Sign-in tokens of the browser extension and apps | Only a SHA-256 hash. The token itself is shown to the device once |
| Device sign-in codes | Only a hash. Each code expires after 10 minutes |
| Card details | Never reach our website or database. Card payments are handled by Stripe |
| Crypto payments | Handled by CCPayment. We keep the order, the amount and the status |
| Websites you visit, DNS queries, traffic content | Never stored. See the No-logs Policy |
Your account
- Passwords must be at least 10 characters and are checked against known data breaches. Only the first five characters of a one-way hash of your password leave our server for that check, never the password itself.
- Sign-in, sign-up, password reset and the app API are rate limited against guessing.
- You confirm your email address before you can connect or collect Bolts.
- Two-factor authentication works with any authenticator app (Google Authenticator, 1Password, Authy), with one-time recovery codes. Each code works only once.
- Changing or resetting your password signs out the browser extension and apps linked to your account.
- You can see every linked device and remove it at any time from the Devices page.
- Deleting your account in Settings deletes your data and closes your VPN and proxy accounts at our partners.
Our team
- The admin panel requires two-factor authentication.
- Every action our team takes on a customer account (premium time, Bolts, plan changes, flags, suspensions, refunds) is recorded in an audit log with who did it and when.
- Signing in as a customer to help with a support request requires the admin to confirm their password again, and is recorded too.
Application security
- Security headers on every response: no framing by other sites, no content sniffing, a strict referrer policy, a restrictive permissions policy and HSTS.
- Payment notifications from Stripe and from our crypto processor are verified by signature, and crypto payments are checked again with the processor before anything changes on your account.
- Rewards reported by our offerwall partner are accepted only with a secret key shared with that partner.
- Our public website loads no advertising, analytics trackers or third-party fonts.
- Errors and service health are monitored around the clock, with automatic alerts to our team. Live checks are public on the status page.
Your connection
- BoltVeil uses WireGuard and OpenVPN, two open-source VPN protocols, in their official apps. Your configuration files and login details are created for your account and delivered over HTTPS.
- The kill switch and leak protection are features of those apps and of your device's VPN settings. Our setup guides show where to turn them on.
- Firewall mode is OpenVPN over TCP port 8080, for networks that block the usual VPN ports.
Reporting a vulnerability
Found a security problem? Email security@boltveil.com with the steps to reproduce it. We reply within 2 business days, keep you updated while we fix it and credit you if you wish. Please do not access other customers' data, run denial-of-service tests or use automated scanners against production. Our machine-readable contact is at /.well-known/security.txt.
Questions about security or privacy: support@boltveil.com.