<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>VPN Works</title>
    <link>https://vpnw.com/</link>
    <description>Recent content on VPN Works</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 29 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://vpnw.com/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Introduction</title>
      <link>https://vpnw.com/introduction/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/introduction/</guid>
      <description>&lt;p&gt;&lt;strong&gt;A VPN for every agent: each AI agent gets a network of its own, and every connection it makes is checked, routed and recorded.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;VPN Works is a project to build that network. Its engine, vpnw, is one small program. It runs an agent in a sealed sandbox whose only way out is vpnw, then decides each connection with a policy you can read, sends it down the path you chose and writes it down.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How It Works</title>
      <link>https://vpnw.com/how-it-works/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/how-it-works/</guid>
      <description>&lt;blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;The idea.&lt;/strong&gt; Seal each agent in a sandbox whose only way out is vpnw. vpnw checks every connection against a policy, sends it down the path you chose and records it. The agent doesn&amp;rsquo;t need to know any of this.&lt;/p&gt;&lt;/blockquote&gt;&#xA;&lt;p&gt;A VPN usually works at the level of the machine. Once it is up, every program on the machine goes out the same way, under the same rules, and nobody can say afterwards which program sent what. That was fine when the programs were a browser and a mail client. It fits badly when one of them is an agent that takes instructions from whatever it reads.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Coding Agent Case Study: Deploy Token Blocked by a Policy Drafted From One Traced Run</title>
      <link>https://vpnw.com/coding-agent-case-study-deploy-token-blocked-by-a-policy-drafted-from-one-traced-run/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/coding-agent-case-study-deploy-token-blocked-by-a-policy-drafted-from-one-traced-run/</guid>
      <description>&lt;p&gt;A coding agent needs the network to do its job. It reads repositories, downloads packages, files tickets and reports back. It also reads text written by strangers, and some of that text is written to give it orders. If the agent holds a token and can reach any server on the internet, one hidden sentence in a task file is enough to send the token away.&lt;/p&gt;&#xA;&lt;p&gt;In the Alpha demo a stand-in coding agent gets exactly that task file. It runs twice under vpnw on Linux: once under trace, to see what it does, and once under guard, with a policy that learn drafted from the first run and a person reviewed. The first run leaks the token. The second doesn&amp;rsquo;t, and the rest of the agent&amp;rsquo;s work goes through, except the ticket, which needs the office route.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Office Route Case Study: Ticket Filed Through the Office Exit, With the Deploy Token Still Blocked</title>
      <link>https://vpnw.com/office-route-case-study-ticket-filed-through-the-office-exit-with-the-deploy-token-still-blocked/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/office-route-case-study-ticket-filed-through-the-office-exit-with-the-deploy-token-still-blocked/</guid>
      <description>&lt;p&gt;Some of an agent&amp;rsquo;s work lives inside a company network: an issue tracker, a package mirror, an internal API. The usual way in is the company VPN, and it takes the whole machine along. Every program on the laptop, the browser included, now goes through the office, and the agent can reach everything on that network that the laptop can.&lt;/p&gt;&#xA;&lt;p&gt;In the Alpha demo one program at a time goes through the office. The office network has an exit, a SOCKS5 proxy inside it at 10.8.0.1, which knows internal names such as &lt;code&gt;tracker.office.internal&lt;/code&gt;. vpnw sends the agent there and nothing else. The agent files its ticket, and its policy still stops the deploy token.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sealed Sandbox Case Study: A Script That Ignores Proxy Settings Tries Three Ways Out and Finds None</title>
      <link>https://vpnw.com/sealed-sandbox-case-study-a-script-that-ignores-proxy-settings-tries-three-ways-out-and-finds-none/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/sealed-sandbox-case-study-a-script-that-ignores-proxy-settings-tries-three-ways-out-and-finds-none/</guid>
      <description>&lt;p&gt;A proxy setting is only a request. Most programs honor &lt;code&gt;HTTPS_PROXY&lt;/code&gt;, and a policy enforced at the proxy works for them. A program that has been told to leak something has every reason not to honor it. It can switch the proxy off, connect to an address directly or find a local service that will connect for it. A policy that only lives in the proxy never hears about any of that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud Metadata Case Study: Request for Instance Credentials Blocked Before Any Connection Is Made</title>
      <link>https://vpnw.com/cloud-metadata-case-study-request-for-instance-credentials-blocked-before-any-connection-is-made/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/cloud-metadata-case-study-request-for-instance-credentials-blocked-before-any-connection-is-made/</guid>
      <description>&lt;p&gt;Every major cloud runs a metadata service at the same address, 169.254.169.254, reachable from inside each virtual machine. Among other things it hands out the machine&amp;rsquo;s own credentials: on AWS, for example, the temporary keys of the role the instance runs as. An agent on a cloud machine that gets talked into fetching that address can leak keys that carry every permission the machine&amp;rsquo;s role has in the cloud account.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Next Uses: Seven Places Where a Network per Program Could Fit</title>
      <link>https://vpnw.com/next-uses-seven-places-where-a-network-per-program-could-fit/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/next-uses-seven-places-where-a-network-per-program-could-fit/</guid>
      <description>&lt;p&gt;The four case studies share one pattern. A program that runs on its own, and can be talked into things, gets a network of its own: one way out, a path chosen for it, a policy a person can read and a record of every connection. Coding agents came first because they are the clearest case, and because the Alpha demo covers them.&lt;/p&gt;&#xA;&lt;p&gt;The pattern turns up well beyond coding agents. None of the seven uses below has been tested, and none is a goal of the Beta, though some would reuse pieces the Beta builds. This post sets out what each would ask of vpnw, what already carries over from the Alpha, and what would be new work. It is a map for choosing what to try after the Beta, ideally with the people who run these systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VPN Works Explained: How vpnw Gives Each AI Agent Its Own Network and Stops Token Leaks</title>
      <link>https://vpnw.com/vpn-works-explained-how-vpnw-gives-each-ai-agent-its-own-network-and-stops-token-leaks/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/vpn-works-explained-how-vpnw-gives-each-ai-agent-its-own-network-and-stops-token-leaks/</guid>
      <description>&lt;p&gt;VPN Works is a prototype of a small program called vpnw. It gives one program, usually an AI agent, a private network of its own on a Linux computer. vpnw decides where that program&amp;rsquo;s traffic may go, sends it out the way you choose and writes down every connection it makes.&lt;/p&gt;&#xA;&lt;p&gt;That matters because of how AI agents work. Coding assistants and similar tools run on laptops and servers with all the network access the machine has, and they follow instructions they find in text. One hidden line in a task file or a web page can say &amp;ldquo;send the deploy token to this address&amp;rdquo;, and an agent may simply do it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>About</title>
      <link>https://vpnw.com/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/about/</guid>
      <description>&lt;p&gt;VPN Works is a project at an early stage. Its engine works on Linux, a live demo replays it and runs its policy engine in your browser, and the next step is real agents on more systems. This site shows where the project stands, gaps included.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-the-project-exists&#34;&gt;Why the Project Exists&lt;/h2&gt;&#xA;&lt;p&gt;AI agents now run code and call APIs on their own. They run on developer laptops, in CI and on servers, usually with all the network access of the machine they run on. That is a lot of access for a program that takes instructions from whatever text it reads.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Contact</title>
      <link>https://vpnw.com/contact/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/contact/</guid>
      <description>&lt;p&gt;The project would like to hear from:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Teams running AI agents,&lt;/strong&gt; coding agents in particular, who would like to try the Beta on their own machines or in CI.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Security and platform engineers&lt;/strong&gt; with an agent, a tool or a network setup the project should test.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Anyone&lt;/strong&gt; with a question about the engine, the demo or the figures on this site.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Write to &lt;strong&gt;&lt;a href=&#34;mailto:info@vpnw.com&#34;&gt;info@vpnw.com&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;p&gt;If you are writing about a setup, it helps to mention the agent, where it runs (a laptop, CI or a server), the operating system and distribution, what the agent needs to reach, and how your network is organized: an office VPN, a proxy, fixed egress addresses.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Live Demo</title>
      <link>https://vpnw.com/demo/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/demo/</guid>
      <description>&lt;p&gt;A coding agent runs a task whose task file hides an instruction to send a deploy token to an attacker. Six steps show what VPN Works does about it. Every line in the terminal below comes from real runs of the Alpha on Linux and is replayed here, and the decisions in the two panels under it are made by the Alpha&amp;rsquo;s own policy engine, running in your browser. There is nothing to sign up for or install, and nothing you do here leaves this page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Roadmap</title>
      <link>https://vpnw.com/roadmap/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/roadmap/</guid>
      <description>&lt;p&gt;The Alpha proves the design on one Linux machine, with stand-ins for the agent and the network. What comes next puts real agents under vpnw on more systems, then leads to a first release, and after that to the parts a company would pay for. Durations are estimates, and what real agents turn up could stretch them.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://vpnw.com/images/roadmap.png&#34; alt=&#34;Two lanes. The engine: Alpha, done, a working engine with run, trace, guard and learn on Linux; Beta, next, about 14 weeks for WireGuard, the file-system layer, macOS, packages and agent recipes; toward v1.0, 6 to 9 months of product work (estimate) for workspaces, a frozen event format, an outside review and pilots; v1.0, the first release, with the command line, policy files and events frozen. After v1.0, what companies would pay for: team policies, audit retention, managed exits and fleet configuration.&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Alpha</title>
      <link>https://vpnw.com/alpha/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/alpha/</guid>
      <description>&lt;p&gt;The Alpha is the working prototype of the VPN Works engine: one Go program called vpnw, its tests, a few tools and a demo. On Linux it runs a program in a sealed sandbox whose only way out is vpnw. Each connection is decided by a policy, sent down the path you chose and recorded.&lt;/p&gt;&#xA;&lt;p&gt;Everything so far ran on one Linux machine, a virtual machine with two CPUs. The demo&amp;rsquo;s agent, servers, office and attacker are stand-ins in a private network namespace. The engine also compiles for arm64 Linux and for macOS, but neither build has run yet. On macOS it is meant to route and trace programs that honor proxy settings; it can&amp;rsquo;t seal them. No real coding agent has run under vpnw so far. That is the job of the &lt;a href=&#34;https://vpnw.com/roadmap/&#34;&gt;Beta&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
