About
VPN Works is a project at an early stage. Its engine works on Linux, a live demo replays it and runs its policy engine in your browser, and the next step is real agents on more systems. This site shows where the project stands, gaps included.
Why the Project Exists
AI agents now run code and call APIs on their own. They run on developer laptops, in CI and on servers, usually with all the network access of the machine they run on. That is a lot of access for a program that takes instructions from whatever text it reads.
The risk has a well-known shape. An agent that can read private data and also reads untrusted text can be talked into sending that data out. A web page or an issue only has to carry the right instruction. Models can’t reliably tell data from instructions, so the practical defense sits outside the model: control where the agent’s traffic may go, and keep a record of where it went.
Machine-wide tools don’t fit that job. A VPN or a firewall applies to the whole machine and every program on it, and it has no idea which program asked for a connection, so it can’t keep a record of what one agent did. VPN Works gives each agent a network of its own.

What the Project Is Building
- The engine. One binary that runs a program in a sealed sandbox whose only way out is vpnw, with four commands: run, trace, guard and learn. How it works
- Paths you already have. Direct, an office proxy, a regional exit and, in the Beta, WireGuard. One agent can use the office network while the rest of the machine does not.
- Policies people can read. Small text files, drafted by learn from a real run and reviewed by a person.
- A record of every run. Every connection with its decision, as text while it happens and as JSON Lines for tools.
- Later, the team layer. Shared policies, fleet configuration, audit retention and managed exits: the parts companies would pay for. The roadmap
How the Project Works
- Measure, then say it. Every figure on this site was measured on the Alpha, or is marked as an estimate. The scripts that reproduce each number are kept with the Alpha’s source.
- Say what is simulated. The demo’s agent, servers and attacker are stand-ins in a private network. The engine is real, and so is every line it printed.
- Fail closed. When vpnw cannot enforce a policy, it refuses to run the program. When the chosen path is down, nothing starts. It never falls back to a direct connection.
- Small by default. One binary, no daemon, no account, no third-party code.
License and Availability
The engine is not public yet. The license will be chosen before the first public release. The plan is a proprietary engine, with an open-source branch under consideration. Until then the prototype is marked “all rights reserved”, and the live demo is the way to see it run.
Questions People Ask
Can I download the engine?
Not yet. It will be available once the license is chosen, around the first public release. The live demo replays real runs of the Alpha and runs its policy engine in your browser. A Linux demo kit is available on request.
Is the demo real?
The engine is real. Every line in the demo’s terminal comes from real runs of the Alpha on Linux, and the decisions in its two panels are made by the Alpha’s own policy code, compiled for the browser. The agent, the servers, the office and the attacker are stand-ins that ran in a private network namespace.
Is VPN Works a VPN?
It is a virtual private network for one program at a time. Instead of connecting the whole machine to another network, it gives one agent a sandbox whose only way out is vpnw, and vpnw sends each allowed connection down the path you chose. That path can be an office proxy or, in the Beta, a WireGuard tunnel, so vpnw works with the VPNs a company already runs.
Does it read my traffic?
Not the content. For HTTPS, vpnw sees where each connection goes (host name, address and port) and counts bytes. It never opens TLS, so HTTPS stays encrypted from the agent to the server. A plain http:// request passes through vpnw as through any web proxy, which reads the request’s first line and headers to forward it. Its records keep hosts, addresses, ports, byte counts and decisions, never URL paths, headers, environment variables or passwords.
Can an agent get around it?
Not over the network, by any route the Alpha’s tests tried. Inside the sandbox a program has no network interface except loopback, so a direct connection, UDP, a DNS lookup or a raw socket has nowhere to go. A seccomp filter also stops it from opening Unix sockets, so it cannot ask a local service such as Docker to connect for it. The Alpha lists every route tested, and what is still untested, such as IPv6 on a machine that has it. The file system is the open gap: a sealed program can still write files that another program runs later, outside the sandbox. Limits on files are Beta work.
Which programs work inside?
Programs that honor the usual proxy settings. curl and Python’s urllib have run under vpnw. wget, git, pip, requests, httpx, Go’s net/http and Node.js from versions 22.21 and 24.5 honor the same settings and are expected to work (vpnw sets the variable Node needs); the Beta tests them as part of its agent recipes. A program with its own network stack that ignores those settings cannot connect at all when sealed, and nothing it sends gets out.
Does it run on macOS or Windows?
Sealed runs need Linux in the Alpha. On macOS vpnw compiles and is meant to route and trace programs that honor proxy settings, but it hasn’t been run on a Mac yet, and it cannot seal programs there, so guard refuses to run. A macOS sandbox is Beta work. Windows comes later.
How is it different from Anthropic’s sandbox or Bitdefender’s VPN for AI agents?
Anthropic’s open-source sandbox runtime, built for Claude Code, limits files as well as the network and is further along; for the network it allows or denies domains, and every connection goes straight out. Bitdefender’s VPN for AI agents, a free Mac beta for desktop AI tools, sends agent traffic through Bitdefender’s own servers. VPN Works puts a path of your choice, a policy and a record around any program that honors proxy settings, on networks you already have. The Alpha compares them in detail.
Is it open source?
Not decided yet. The license will be chosen before the first public release. The plan is a proprietary engine, with an open-source branch under consideration.
Get in Touch
Teams running agents that need network limits, and anyone with a question or a use the project should test, are welcome to write.