Security
How Colitu encrypts your traffic, protects your account, and what you should watch out for.
How your traffic is protected
Colitu encrypts all traffic between your device and the Colitu server:
- Hysteria2 and Trojan use TLS 1.3 with Let's Encrypt certificates that renew automatically.
- VLESS Reality uses X25519 key exchange and modern AEAD encryption; the server is authenticated with a pre-shared public key.
- Shadowsocks 2022 encrypts with AES-256-GCM.
People on the same Wi-Fi, your internet provider or a network administrator cannot see which sites you visit or what you send. They can only see that you are connected to a Colitu server.
Server addresses
The apps and the website never show the servers' real IP addresses; connections are made through domain names. This lowers the risk of targeted attacks on the servers.
Account protection
- Passwords are stored irreversibly (Argon2id); nobody can read your password.
- Each device is bound to your account with its own key. When you remove a lost device in Device management, its access ends immediately.
- No more devices than your plan allows can connect; refused attempts are recorded on your account.
- Check the sessions on your account page and end any you do not recognise.
What you should do
- Never share your password or verification code. Colitu staff and Colitu Bot will never ask for them.
- Download the apps only from colitu.com/download.
- Don't share your account with other people; each person needs their own device slot.
Reporting a vulnerability
If you think you have found a security issue, send the details from the Support section of the app or website with "Security" in the subject. We thank researchers who report responsibly; please give us time to fix the issue before making it public.
Still need help?
Colitu Bot answers in seconds and hands you over to live support if it can't solve it.