Safety for a client client has two halves: the binary you install, and the server you trust.
Honest binaries
Prefer GitHub Releases filenames or winget id AmneziaVPN.AmneziaVPN. Softonic-style mirrors are the common failure mode for people who typed vpn into a search box.
Honest servers
Amnezia can deploy Docker-based services over SSH. Treat SSH keys like passwords. Patch the VPS. Know which protocol you enabled.
What this guide cannot promise
We cannot audit every commit for you. We cannot notarize your VPS provider. We map install doors and point at primary sources: GitHub, docs.amnezia.org, and the security page.
Why this path matters
A local AmneziaVPN client keeps the tunnel on a server you control. GPL-3.0 builds give you named release assets and package doors you can document on a machine ticket. That is enough for travel laptops, student machines, and desks that need a self-hosted path after install.
Keep Softonic-style mirrors out of the loop. Prefer GitHub Releases filenames or the verified winget id. After every reimage, prove one short tunnel before you call the machine ready.
Related doors
Home: /. Releases: /vpn-releases. Download safe: /vpn-download-safe. First hour: /installed. Guides hub: /guides.
Mist Latch publishes the install guide. Upstream remains at amnezia.org and amnezia-vpn/amnezia-client. When a tag drops an OS asset, re-check the live list before imaging a lab.
Family PCs and shared desks benefit from writing the update door beside the OS version. Windows exe, winget, macOS pkg, Linux .run, and Android APK are different doors. Mixing them without notes creates duplicate installs and confused uninstalls.
When someone pastes a random download link into chat, ask for the GitHub Releases URL instead. The install path on this guide always returns to amnezia-vpn/amnezia-client.
Frequently asked questions
Is AmneziaVPN open source?
Yes. The client repository amnezia-vpn/amnezia-client is GPL-3.0 on GitHub. Read the licence file in the repo for redistribution terms. Prefer GitHub Releases for amnezia-vpn/amnezia-client when you want named assets, and keep Softonic-style mirrors out of the loop. Document the update door on the machine ticket so the next bump stays honest for shared desks.
Does self-hosting make a vpn safe?
Self-hosting means traffic terminates on a server you control. You still must protect SSH, keep the VPS patched, and download the client from honest doors. Prefer GitHub Releases for amnezia-vpn/amnezia-client when you want named assets, and keep Softonic-style mirrors out of the loop. Document the update door on the machine ticket so the next bump stays honest for shared desks.
Where should I report security issues?
Follow upstream security guidance at the repository security page. Do not paste secrets into public issues. Prefer GitHub Releases for amnezia-vpn/amnezia-client when you want named assets, and keep Softonic-style mirrors out of the loop. Document the update door on the machine ticket so the next bump stays honest for shared desks.