Built for Control

Every feature in Nera VPN is designed to give you absolute control over your privacy, traffic, and network — without compromising speed.

DNS Protection

Void

An AI-powered DNS threat detection engine that intercepts every DNS query on your device. Beyond static blocklists, Void uses a heuristic analysis model to detect never-before-seen malware domains — including zero-day threats that no blocklist has cataloged yet.

  • Blocks 300,000+ ad, tracking, and malware domains
  • AI heuristic engine detects zero-day DGA malware domains
  • DNS queries routed through encrypted VPN tunnel — invisible to your ISP
  • Works independently of VPN connection
Void
Active
312K
Domains Blocked
6-Feature
AI Model
Zero-Day Detection

AI Threat Intelligence

Most VPNs block known threats from a list. Nera goes further — a 6-feature heuristic model analyzes every domain in real-time, detecting algorithmically generated malware domains (DGA) that have never been seen before. Based on peer-reviewed research from IEEE and Cisco Umbrella.

  • Shannon entropy analysis — measures character randomness
  • Bigram frequency scoring — compares character pairs to linguistic norms
  • Consonant clustering and vowel ratio analysis
  • Multi-signal convergence boost for high-confidence verdicts
  • Runs entirely on-device — your queries never leave
DGA Analysis
xk7qz9bn4m.ru INTERCEPTED
Entropy
0.92
Bigram
0.88
Vowel Ratio
0.75
Digit Ratio
0.81
⛔ MALICIOUS — DGA DETECTED BLOCKED
Traffic Obfuscation

Obfuscation / DPI Bypass

Disguises your VPN traffic to look like regular HTTPS web traffic. Bypasses Deep Packet Inspection (DPI) used by restrictive networks, firewalls, and ISPs that throttle or block VPN connections.

  • Wraps WireGuard traffic in TLS — looks like normal HTTPS
  • Bypasses corporate firewalls and network restrictions
  • Defeats ISP throttling of VPN protocols
  • Works in restrictive environments (hotels, airports, schools)
Obfuscation Mode
TLS Wrapped
WireGuard → stunnel → TLS 443
DPI sees: HTTPS traffic
Leak Protection

Kill Switch

Automatically blocks all internet traffic the moment your VPN connection drops. Prevents your real IP address and DNS queries from ever leaking — even for a millisecond.

  • Instant traffic block on VPN disconnect
  • Prevents IP and DNS leaks during connection drops
  • Windows Firewall-level enforcement
  • Re-enables automatically when VPN reconnects
Kill Switch
Armed
VPN drops → ALL traffic blocked
VPN reconnects → traffic restored
Per-App Routing

Split Tunneling

Choose which apps go through the VPN tunnel and which connect directly. Perfect for keeping your banking app on local network while routing your browser through the VPN.

  • Per-application VPN routing control
  • Whitelist or blacklist specific apps
  • Uses Windows Filtering Platform for reliable enforcement
  • No performance penalty — only selected apps are tunneled
Split Tunnel
3 Apps Tunneled
Chrome.exe VPN ✓
Discord.exe VPN ✓
Steam.exe Direct ↗
Coming Soon

Port Forwarding

Port forwarding is planned, but it is not enabled in the current release yet. Once available, it will cover peer-to-peer apps, game hosting, and self-hosted services behind the VPN.

  • Not enabled in the current release
  • Coming soon in a future release
  • Planned desktop app controls for viewing and managing the assigned port
  • Will remain session-bound and automatically released on disconnect
Release Status
PORT TBD

Ready for Total Control?

Core privacy features ship now. Additional advanced tools roll out as they clear release review.

Get Protected →