GOpenCNR and the secrecy of telecommunications
What the secrecy of telecommunications protects in GOpenCNR, what hubs, hosted routers and our own systems can and cannot see of your traffic, when flows are sampled, and who may ever receive any of it.
What this covers
GOpenCNR carries communications between its members, so the secrecy of telecommunications protects your traffic in it. This page sets out what that means in practice: what each part of the network can see, what nobody may do, and who is bound. It is read with the GOpenCNR privacy notice, which lists everything we process and for how long, and the GOpenCNR terms.
"We" is Gelhaus Solutions, which operates GOpenCNR as Tier 0. Our details are in the legal notice.
The short version
- Between agent routers, your traffic is encrypted end to end. Hubs forward ciphertext they cannot read, and the keys are made on your router and never leave it.
- Nobody inspects content. Not us, and not any hub or transit operator.
- Hubs keep counters, not records. They count how much, never who talked to whom. Fine-grained counters are kept for 90 days, then only daily totals, up to 12 months.
- Flows are sampled only inside an open abuse case: for at most 7 days, one packet in 1,000, source, destination, port and size, never content, and deleted at the latest when the case closes.
- Where a hub can see more, your device says so. Hosted routers and routers without the agent are labelled for what they are.
- Your endpoint is never public.
- Everyone who runs part of the network is bound, by law and by a written commitment.
- Nothing is passed on except under the authority request policy, and facts protected by the secrecy of telecommunications only where a statute expressly allows it.
What the law protects
The secrecy of telecommunications covers the content of your communications and their closer circumstances, in particular whether you took part in one at all, including attempts that failed (Section 3 TDDDG). It binds us as the operator of a public telecommunications network, and it binds everyone who takes part in providing the service, which includes every hub operator.
Those bound may learn of content or circumstances only as far as running the network and protecting its systems requires, and may use what they learn for nothing else. Passing it on is lawful only where a statute provides for it and expressly refers to telecommunications. The duty continues after someone's role ends, and breaking it is a criminal offence (Section 206 StGB).
What a hub sees
Traffic between members runs in two layers. The outer WireGuard tunnel runs from your router to a hub, which decrypts it. Inside it, an inner WireGuard layer runs end to end between two members' agents, and only members allowed to talk to each other receive each other's inner keys.
What a hub can see depends on how you connect, and every device shows its protection as it is:
- A router running the agent: end to end. The hub sees the address your router connects from, the two routers' addresses in GOpenCNR, and the size and timing of each packet. It cannot see content, and neither can we: nobody but the two routers holds the keys.
- A hosted router: "encrypted to" the hub's operator, "end to end from there". Your phones, laptops and servers connect to it with plain WireGuard, so their traffic is in the clear inside the hosted router before the inner layer starts. On Tier 0's hub, that operator is us; on a certified hub, it is the operator named on the label, who handles your traffic as our processor under the hub operator agreement. Either way the rule is the same: no inspection, nothing kept beyond counters.
- A router without the agent: "hop by hop". A generated configuration (MikroTik, VyOS, FRR, or plain WireGuard and BIRD) has no inner layer, so hubs forward its packets in the clear. They do not inspect them and keep only counters. Such a router never receives closed routes.
Closed prefixes travel only through Tier 0's hub and certified hubs, never through community hubs, transit members or direct sessions, and only members of the audience hold each other's inner keys.
Dedicated and private hubs are run only by Tier 0, on its own servers.
Counters, not records
Each hub counts, per member: bytes, packets and dropped packets by reason, the routes its filters refused and the rule that refused each, sessions held down after flapping, and the bandwidth you use against the fair-use limit. Counters run the fair-use limits, show you what was dropped and why, and tell us when a hub needs more capacity. They say how much, never who talked to whom, and never what was said.
You see your own counters. Tier 0 sees them for every member. The operator of a hub sees them for the members connected to that hub. The public sees aggregates only. Fine-grained counters are kept for 90 days; after that only daily totals per member remain, up to 12 months.
Flow sampling inside a case
Hubs keep no records of flows. The one exception is an open abuse case about traffic from a reported source. Then, and only then, Tier 0 may sample that source's flows:
- only with an open case, and only after recording in the case why sampling is needed;
- for at most 7 days, and Tier 0 ends it sooner once the purpose is met;
- one packet in 1,000;
- recording source, destination, port and size, never content;
- started and ended by Tier 0, both recorded in the case, on the hubs Tier 0 runs;
- seen only by Tier 0, within the case.
The samples are deleted as soon as the case no longer needs them, and at the latest when it closes. What was found in them stays with the case, which is kept for 12 months after it closes. The holder of the sampled source is told when sampling ends that it ran, for how long and why.
The rest of the network
- The route collector and the looking glass see routes, never traffic. Open routes are public, and the collector publishes dumps of them, kept for 2 years. What the collector does not publish (its live feed and raw dumps, closed routes included) is kept for 12 months. A closed prefix itself is public like any other (prefix, holder handle, origin ASN, ROA); only its reachability is closed, and its audience members and the routes to them are never published.
- Your agent's health reports (session state, latency to each hub, MTU probe results, drops by reason, agent version) are seen by you, by Tier 0 and by the operator of your hub, and by the public only as aggregates. They are kept for 12 months.
- The resolver writes no log that links a query to your address. Logs switched on for debugging are deleted within 24 hours.
- Your endpoint, the address your router connects from, is stored encrypted and shown only to Tier 0 and to members you accept for direct peering. It never appears in exports or RDAP. The transparency log holds only a hash of it, made with a random 32-byte salt that is kept encrypted and given only to you and the peers you accept, so nobody can guess your endpoint from the log.
- Interconnected networks (dn42 and NeoNetwork) exchange open routes, and traffic to and from open prefixes, under their own rules. Closed prefixes never cross to them.
Who may look, and how that is controlled
- Every change Tier 0 makes needs a passkey and writes an audit record, and Tier 0's sessions end after 30 minutes without use.
- Hubs are configured only from signed bundles generated from the registry. Nothing is configured by hand on a hub.
- A hub operator sees the sessions, counters and refusals of the members on its own hub, and nothing about anyone else.
- Support views are read-only. Nobody signs in as you.
Who is bound
Everyone with access to a hub, to Tier 0 functions or to traffic data commits in writing to the secrecy of telecommunications before first access: every person holding a Tier 0 role, certified hub operators and transit operators in their agreements, and community hub operators when they enrol their hub. Certified hub operators and audited transit operators handle your data as our processors under Art. 28 GDPR, and those outside the EU/EEA and outside countries with an adequacy decision also sign the EU standard contractual clauses; they report every security incident to us without delay. They are briefed on it before first access and again every year. The commitment covers what this page describes: no inspection, nothing kept beyond counters, nothing passed on unless a statute expressly allows it, and every possible exposure reported at once.
Passing anything on
Courts and authorities receive data only under the authority request policy: German orders, and European Production and Preservation Orders, after checking; other foreign requests only through German mutual legal assistance. You are told unless the law forbids it, and as soon as it no longer does. Every request is counted in the transparency report every six months.
For facts protected by the secrecy of telecommunications, the limit is the statute: they are passed on only where a law provides for it and expressly refers to telecommunications (Section 3(3) TDDDG). The duty to report planned serious crimes under Section 138 StGB takes precedence. The authority request policy's one voluntary disclosure, to prevent an imminent danger to life or limb, never covers your traffic data. Child sexual abuse material is always reported to the police or the Bundeskriminalamt, with what we hold that is not traffic data; traffic data goes to them only under a legal order.
There is little to pass on in any case. No content is stored anywhere, traffic between agents is encrypted with keys we do not hold, and hubs keep counters rather than records.
If something goes wrong
If you believe your traffic or your data in GOpenCNR has been exposed, write to contact@gplatform.org at once. Security reports may also go through the GOpenCNR security and disclosure policy.
We notify every personal data breach in GOpenCNR to the Bundesnetzagentur and the Federal Commissioner for Data Protection and Freedom of Information (Section 169 TKG), and we tell you directly where a breach is likely to affect you seriously. Significant security incidents are reported to the Bundesnetzagentur and the Federal Office for Information Security (Section 168 TKG), and where you can protect yourself against a threat, we tell you how.
The supervisory authority for personal data processed to provide GOpenCNR's telecommunications service is the Federal Commissioner for Data Protection and Freedom of Information (BfDI), Graurheindorfer Straße 153, 53117 Bonn, Germany (Section 29 TDDDG). For everything else it is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover.
Changes
This page changes when GOpenCNR does. Every version is kept in the document archive.