Guide · reviewed September 30, 2026

Tor, VPN and network isolation

Check actual network state before relying on a privacy mode.

Development documentation; it does not represent a public ISO or hardware validation.

Different functions

Tor, a kill switch and an airgap address different problems. The sovereignty package includes neo-tor, neo-killswitch and neo-airgap. Read the help and check which interfaces and services will be affected before selecting a mode.

Verify the rules

Use system diagnostics and inspect nftables rules. An enabled-mode indicator does not prove that all traffic follows the expected path. Testing also depends on DNS, additional interfaces and VPN endpoints.

Isolation limits

Vault mode attempts to disable interfaces, radios and network services. The installed system root remains on disk. Verify the result on the target hardware; there is no promise of absolute anonymity or security.

Inspection commands

Run on a compatible Neovanguard OS installation. Check the installed tool's help; these commands inspect state or list options.

Terminal
neo-tor --help
neo-killswitch --help
neo-airgap --help
sudo nft list ruleset

Technical source (private repository; authorized access required): soberania.md.