| Version | Supported |
|---|---|
| 1.2.x | ✅ |
| < 1.2 | ❌ |
We take security seriously. If you discover a security vulnerability, please report it responsibly.
DO NOT open a public GitHub issue for security vulnerabilities.
Instead, please send an email to: shinenetvpn@gmail.com
Include the following information:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: We will acknowledge receipt within 48 hours
- Assessment: We will investigate and assess the vulnerability within 7 days
- Resolution: We aim to release a fix within 30 days for critical vulnerabilities
- Disclosure: We will coordinate with you on public disclosure timing
We support safe harbor for security researchers who:
- Make a good faith effort to avoid privacy violations and data destruction
- Only interact with accounts you own or with explicit permission of the account holder
- Do not exploit a vulnerability beyond what is necessary to confirm its existence
- Report vulnerabilities promptly and do not publicly disclose before a fix is available
ShineNET VPN supports multiple industry-standard VPN protocols:
| Protocol | Encryption | Security Level |
|---|---|---|
| VMess | AES-128-GCM / ChaCha20-Poly1305 | High |
| VLESS + XTLS | AES-256-GCM / ChaCha20-Poly1305 | Very High |
| Trojan | AES-256-GCM (TLS 1.3) | Very High |
| Shadowsocks | AEAD Ciphers (AES-256-GCM, ChaCha20) | High |
| Protocol | Description | Security Level |
|---|---|---|
| MASQUE | HTTP/3 tunnel over QUIC | Very High |
| WireGuard | Modern VPN protocol | High |
| WARP-on-WARP | Double-layer encryption | Very High |
- Transport Layer: All connections use TLS 1.3 or QUIC for transport encryption
- Tunnel Layer: VPN traffic is encrypted using the selected protocol's cipher
- No Double Encryption: When using MASQUE/TLS, the protocol does not add redundant encryption layers
- Public Server Configurations: V2Ray server configurations are sourced from publicly available community lists
- TLS Encryption: All V2Ray connections use TLS for transport security
- Multiple Protocol Support: VMess, VLESS, Trojan, Shadowsocks with TLS
- No Server-Side Logging: We do not operate or control the servers; configurations are fetched from public sources
- User Responsibility: Users should verify server trustworthiness before connecting
- Download APK only from official GitHub releases
- Verify APK checksum if provided
- Review app permissions before installation
- Use VPN for all internet traffic when possible
- Avoid accessing highly sensitive services (banking) through VPN
- Check for DNS leaks using tools like dnsleaktest.com
- Update the app regularly to get security patches
- Use VLESS + XTLS or Trojan protocols when available
- Enable "Connect on Boot" for continuous protection
- Use the closest server for better performance and security
ShineNET VPN is fully open source:
- Source Code: Available on GitHub for community review
- No Hidden Code: All VPN logic is visible in the repository
- Community Audits: Independent researchers can verify our security claims
- Regular Updates: Security improvements are released regularly
Since V2Ray server configurations are sourced from public community lists:
⚠️ No Guarantees: We cannot guarantee the trustworthiness of third-party servers- 🔍 User Verification: Users should verify server configurations before connecting
- 🛡️ TLS Protection: All connections use TLS encryption regardless of server source
- 📋 Best Practice: Prefer servers with known operators or use Aether protocols for maximum security
- Real IP addresses (only anonymized region)
- Browsing history or activity
- Connection logs or session data
- Personal identifiable information
- Anonymized IP region (first 3 octets only)
- Device type and Android version
- App version for update checks
- Aggregated server performance metrics
- GDPR: We comply with European privacy regulations
- CCPA: We respect California privacy rights
- Open Source: MIT License ensures full transparency
For security-related inquiries:
- Email: shinenetvpn@gmail.com
- Telegram: @ShineNETVPN
- GitHub Issues: For non-security bugs only
Your security is our priority
ShineNET VPN - Transparent, Secure, Private
