"Your traffic is encrypted" shows up on every VPN provider's homepage, and rarely gets explained. Here's what actually happens between a device and a node, without the marketing.
Why a tunnel, specifically
A VPN tunnel isn't just "hide your IP." It's an established channel between your device and a node where all traffic is transformed so that only the other end of that channel can read it.
Before a packet ever leaves your phone or laptop, it's already encrypted — the network it physically travels through afterward only ever sees encrypted bytes.
How the secure connection gets set up
Step one is a handshake: the device and the node exchange data that lets both sides derive a shared session key, without ever sending that key itself across the network in the clear. This relies on asymmetric cryptography — each side holds its own key pair.
After the handshake, both sides switch to the same session key for symmetric encryption, which is faster than asymmetric and better suited to a continuous stream of data rather than a one-time exchange.
Session keys rotate periodically: even if a specific key were ever compromised, it wouldn't expose the whole connection history — only the slice of traffic that used it.
What's actually hidden, and what isn't
Hidden: the content of your traffic from the local network — hotel Wi-Fi, a router, a mobile carrier — which only ever sees an encrypted stream to one address, the VPN node's.
Not hidden by default: the fact that you're using a VPN at all (the network can see you're connected to an external address), and whatever the VPN node itself sees — traffic gets decrypted there before continuing on to the internet. That's why a provider's logging policy matters just as much as its choice of encryption algorithm.
Two protocols in MearVPN, two different encryption stacks
WireGuard uses ChaCha20-Poly1305 for encrypting data and Curve25519 for key exchange — a compact, modern set of algorithms chosen specifically for code simplicity and speed, unlike older protocols with dozens of configurable cipher suites.
VLESS over Xray in MearVPN runs on TLS — the same protocol securing ordinary HTTPS traffic in a browser. Reality, one of the transports inside Xray, reproduces the TLS handshake of a genuine website closely enough that, from the outside, the connection looks like an ordinary HTTPS request.
Which of the two is used is set by the configuration: a VLESS link brings up Xray, a WireGuard configuration brings up WireGuard.
Related questions
If traffic is encrypted, does that mean it can't be broken at all?
Cryptography doesn't deal in absolute guarantees — it deals in computational cost. Algorithms like ChaCha20 and AES, at current key sizes, are secure against brute-force at a scale no realistic amount of computing power can touch. That's not "impossible" so much as "requires resources nobody sane has."
Can a VPN provider technically see my traffic?
At the node, where traffic is decrypted before heading out to the internet — yes, technically. That's why a strict no-logs policy isn't a technical footnote; it's a direct promise not to record what's visible at that point.
Why not just use one protocol instead of two?
WireGuard and Xray play to different strengths: WireGuard is faster and lighter, Xray holds up better on networks that aggressively filter unusual-looking traffic. One lane doesn't cover both situations equally well.