<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>VPN Works</title>
    <link>https://vpnw.com/</link>
    <description>Recent content on VPN Works</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 29 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://vpnw.com/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Introduction</title>
      <link>https://vpnw.com/introduction/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/introduction/</guid>
      <description>&lt;p&gt;&lt;strong&gt;A VPN for every agent: each AI agent gets a network of its own, and every connection it makes is checked, routed and recorded.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;VPN Works is a project to build that network. Its engine, vpnw, is one small program. It runs an agent in a sealed sandbox whose only way out is vpnw, then decides each connection with a policy you can read, sends it down the path you chose and writes it down.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How It Works</title>
      <link>https://vpnw.com/how-it-works/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/how-it-works/</guid>
      <description>&lt;blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;The idea.&lt;/strong&gt; Seal each agent in a sandbox whose only way out is vpnw. vpnw checks every connection against a policy, sends it down the path you chose and records it. The agent doesn&amp;rsquo;t need to know any of this.&lt;/p&gt;&lt;/blockquote&gt;&#xA;&lt;p&gt;A VPN usually works at the level of the machine. Once it is up, every program on the machine goes out the same way, under the same rules, and nobody can say afterwards which program sent what. That was fine when the programs were a browser and a mail client. It fits badly when one of them is an agent that takes instructions from whatever it reads.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Coding Agent Case Study: Deploy Token Blocked by a Policy Drafted From One Traced Run</title>
      <link>https://vpnw.com/coding-agent-case-study-deploy-token-blocked-by-a-policy-drafted-from-one-traced-run/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/coding-agent-case-study-deploy-token-blocked-by-a-policy-drafted-from-one-traced-run/</guid>
      <description>&lt;p&gt;A coding agent needs the network to do its job. It reads repositories, downloads packages, files tickets and reports back. It also reads text written by strangers, and some of that text is written to give it orders. If the agent holds a token and can reach any server on the internet, one hidden sentence in a task file is enough to send the token away.&lt;/p&gt;&#xA;&lt;p&gt;In the Alpha demo a stand-in coding agent gets exactly that task file. It runs twice under vpnw on Linux: once under trace, to see what it does, and once under guard, with a policy that learn drafted from the first run and a person reviewed. The first run leaks the token. The second doesn&amp;rsquo;t, and the rest of the agent&amp;rsquo;s work goes through, except the ticket, which needs the office route.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Office Route Case Study: Ticket Filed Through the Office Exit, With the Deploy Token Still Blocked</title>
      <link>https://vpnw.com/office-route-case-study-ticket-filed-through-the-office-exit-with-the-deploy-token-still-blocked/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/office-route-case-study-ticket-filed-through-the-office-exit-with-the-deploy-token-still-blocked/</guid>
      <description>&lt;p&gt;Some of an agent&amp;rsquo;s work lives inside a company network: an issue tracker, a package mirror, an internal API. The usual way in is the company VPN, and it takes the whole machine along. Every program on the laptop, the browser included, now goes through the office, and the agent can reach everything on that network that the laptop can.&lt;/p&gt;&#xA;&lt;p&gt;In the Alpha demo one program at a time goes through the office. The office network has an exit, a SOCKS5 proxy inside it at 10.8.0.1, which knows internal names such as &lt;code&gt;tracker.office.internal&lt;/code&gt;. vpnw sends the agent there and nothing else. The agent files its ticket, and its policy still stops the deploy token.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sealed Sandbox Case Study: A Script That Ignores Proxy Settings Tries Three Ways Out and Finds None</title>
      <link>https://vpnw.com/sealed-sandbox-case-study-a-script-that-ignores-proxy-settings-tries-three-ways-out-and-finds-none/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/sealed-sandbox-case-study-a-script-that-ignores-proxy-settings-tries-three-ways-out-and-finds-none/</guid>
      <description>&lt;p&gt;A proxy setting is only a request. Most programs honor &lt;code&gt;HTTPS_PROXY&lt;/code&gt;, and a policy enforced at the proxy works for them. A program that has been told to leak something has every reason not to honor it. It can switch the proxy off, connect to an address directly or find a local service that will connect for it. A policy that only lives in the proxy never hears about any of that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud Metadata Case Study: Request for Instance Credentials Blocked Before Any Connection Is Made</title>
      <link>https://vpnw.com/cloud-metadata-case-study-request-for-instance-credentials-blocked-before-any-connection-is-made/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/cloud-metadata-case-study-request-for-instance-credentials-blocked-before-any-connection-is-made/</guid>
      <description>&lt;p&gt;Every major cloud runs a metadata service at the same address, 169.254.169.254, reachable from inside each virtual machine. Among other things it hands out the machine&amp;rsquo;s own credentials: on AWS, for example, the temporary keys of the role the instance runs as. An agent on a cloud machine that gets talked into fetching that address can leak keys that carry every permission the machine&amp;rsquo;s role has in the cloud account.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Next Uses: Seven Places Where a Network per Program Could Fit</title>
      <link>https://vpnw.com/next-uses-seven-places-where-a-network-per-program-could-fit/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/next-uses-seven-places-where-a-network-per-program-could-fit/</guid>
      <description>&lt;p&gt;The four case studies share one pattern. A program that runs on its own, and can be talked into things, gets a network of its own: one way out, a path chosen for it, a policy a person can read and a record of every connection. Coding agents came first because they are the clearest case, and because the Alpha demo covers them.&lt;/p&gt;&#xA;&lt;p&gt;The pattern turns up well beyond coding agents. None of the seven uses below has been tested, and none is a goal of the Beta, though some would reuse pieces the Beta builds. This post sets out what each would ask of vpnw, what already carries over from the Alpha, and what would be new work. It is a map for choosing what to try after the Beta, ideally with the people who run these systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Next VPN Works Prototype: A 14-Week Beta That Puts Real AI Agents Under vpnw</title>
      <link>https://vpnw.com/the-next-vpn-works-prototype-a-14-week-beta-that-puts-real-ai-agents-under-vpnw/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/the-next-vpn-works-prototype-a-14-week-beta-that-puts-real-ai-agents-under-vpnw/</guid>
      <description>&lt;p&gt;The Alpha answered one question. Can a small program seal an AI agent in and control every connection it makes? On Linux, on one machine, with a stand-in agent, the answer was yes. The next prototype, the Beta, takes on the harder question: does it hold up with real agents doing real work, on the machines where agents actually run?&lt;/p&gt;&#xA;&lt;p&gt;The Beta is planned at about 14 weeks with two or three people. It keeps the same engine and the same four commands: run, trace, guard and learn. What it adds is what real use needs, from a WireGuard route and limits on files to more systems and packages that install in one step. Then three coding agents that developers use every day work under it for four weeks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VPN Works Explained: How vpnw Gives Each AI Agent Its Own Network and Stops Token Leaks</title>
      <link>https://vpnw.com/vpn-works-explained-how-vpnw-gives-each-ai-agent-its-own-network-and-stops-token-leaks/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/vpn-works-explained-how-vpnw-gives-each-ai-agent-its-own-network-and-stops-token-leaks/</guid>
      <description>&lt;p&gt;VPN Works is a prototype of a small program called vpnw. It gives one program, usually an AI agent, a private network of its own on a Linux computer. vpnw decides where that program&amp;rsquo;s traffic may go, sends it out the way you choose and writes down every connection it makes.&lt;/p&gt;&#xA;&lt;p&gt;That matters because of how AI agents work. Coding assistants and similar tools run on laptops and servers with all the network access the machine has, and they follow instructions they find in text. One hidden line in a task file or a web page can say &amp;ldquo;send the deploy token to this address&amp;rdquo;, and an agent may simply do it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Where the Money Is in VPN Works: One Policy and One Log for Every AI Agent a Company Runs</title>
      <link>https://vpnw.com/where-the-money-is-in-vpn-works-one-policy-and-one-log-for-every-ai-agent-a-company-runs/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/where-the-money-is-in-vpn-works-one-policy-and-one-log-for-every-ai-agent-a-company-runs/</guid>
      <description>&lt;p&gt;VPN Works is a prototype today, so its business case is a plan to test with customers. Here is the short answer to where the money is. The engine that seals one agent on one machine is the part that earns trust. The money comes from companies that run many agents and need one policy and one log across all of them, on every laptop, CI runner and server, plus exits they control. That&amp;rsquo;s worth a monthly fee per developer. There&amp;rsquo;s also a faster route: over the past year, security and network vendors paid between $180 million and $400 million each for AI and agent security startups.&lt;/p&gt;</description>
    </item>
    <item>
      <title>About</title>
      <link>https://vpnw.com/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/about/</guid>
      <description>&lt;p&gt;VPN Works is a project at an early stage. Its engine works on Linux, a live demo replays it and runs its policy engine in your browser, and the next step is real agents on more systems. This site shows where the project stands, gaps included.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-the-project-exists&#34;&gt;Why the Project Exists&lt;/h2&gt;&#xA;&lt;p&gt;AI agents now run code and call APIs on their own. They run on developer laptops, in CI and on servers, usually with all the network access of the machine they run on. That is a lot of access for a program that takes instructions from whatever text it reads.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Contact</title>
      <link>https://vpnw.com/contact/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/contact/</guid>
      <description>&lt;p&gt;The project would like to hear from:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Teams running AI agents,&lt;/strong&gt; coding agents in particular, who would like to try the Beta on their own machines or in CI.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Security and platform engineers&lt;/strong&gt; with an agent, a tool or a network setup the project should test.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Anyone&lt;/strong&gt; with a question about the engine, the demo or the figures on this site.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Write to &lt;strong&gt;&lt;a href=&#34;mailto:info@vpnw.com&#34;&gt;info@vpnw.com&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;p&gt;If you are writing about a setup, it helps to mention the agent, where it runs (a laptop, CI or a server), the operating system and distribution, what the agent needs to reach, and how your network is organized: an office VPN, a proxy, fixed egress addresses.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Live Demo</title>
      <link>https://vpnw.com/demo/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/demo/</guid>
      <description>&lt;p&gt;A coding agent runs a task whose task file hides an instruction to send a deploy token to an attacker. Six steps show what VPN Works does about it. Every line in the terminal below comes from real runs of the Alpha on Linux and is replayed here, and the decisions in the two panels under it are made by the Alpha&amp;rsquo;s own policy engine, running in your browser. There is nothing to sign up for or install, and nothing you do here leaves this page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Roadmap</title>
      <link>https://vpnw.com/roadmap/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/roadmap/</guid>
      <description>&lt;p&gt;The Alpha proves the design on one Linux machine, with stand-ins for the agent and the network. What comes next puts real agents under vpnw on more systems, then leads to a first release, and after that to the parts a company would pay for. Durations are estimates, and what real agents turn up could stretch them.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://vpnw.com/images/roadmap.png&#34; alt=&#34;Two lanes. The engine: Alpha, done, a working engine with run, trace, guard and learn on Linux; Beta, next, about 14 weeks for WireGuard, the file-system layer, macOS, packages and agent recipes; toward v1.0, 6 to 9 months of product work (estimate) for workspaces, a frozen event format, an outside review and pilots; v1.0, the first release, with the command line, policy files and events frozen. After v1.0, what companies would pay for: team policies, audit retention, managed exits and fleet configuration.&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Alpha</title>
      <link>https://vpnw.com/alpha/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/alpha/</guid>
      <description>&lt;p&gt;The Alpha is the working prototype of the VPN Works engine: one Go program called vpnw, its tests, a few tools and a demo. On Linux it runs a program in a sealed sandbox whose only way out is vpnw. Each connection is decided by a policy, sent down the path you chose and recorded.&lt;/p&gt;&#xA;&lt;p&gt;Everything so far ran on one Linux machine, a virtual machine with two CPUs. The demo&amp;rsquo;s agent, servers, office and attacker are stand-ins in a private network namespace. The engine also compiles for arm64 Linux and for macOS, but neither build has run yet. On macOS it is meant to route and trace programs that honor proxy settings; it can&amp;rsquo;t seal them. No real coding agent has run under vpnw so far. That is the job of the &lt;a href=&#34;https://vpnw.com/roadmap/&#34;&gt;Beta&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
