Bitdefender built a VPN that hides your AI agent, not you

Security can no longer stop at protecting the person behind the screen. It has to extend to the agent itself acting on their behalf.

Ciprian Istrate said that on Tuesday. He runs consumer operations at Bitdefender, and the Romanian company was launching a VPN built for AI agents rather than for people.

It is a public beta, it costs nothing, and it runs on macOS only. Bitdefender announced it from Bucharest and San Antonio.

It works nothing like a normal VPN

A conventional VPN holds one tunnel open for everything on the machine. This one sleeps until an agent asks for it.

When that happens, it spins up a disposable container for that single prompt. The request leaves through a Bitdefender server. The container dies when the prompt ends, and no cookies, cache or session state carry over to the next one.

The rest of the device keeps its normal connection. Your browser carries on exactly as before.

The plumbing is a Model Context Protocol server. Google used the same protocol last week to open its Home platform to outside agents. It has become the standard way anything attaches to an assistant.

Four clients work at launch: Claude Desktop, Cursor, Codex and OpenCode. Each one restarts once to pick up the configuration, and the user consents to telemetry on first run.

The five things it claims to do

Bitdefender lists them, and each applies to every request the agent routes through its tools.

It masks the agent’s IP, so a site sees the exit server rather than a home address. It opens an encrypted tunnel per request, so whoever runs the coffee shop Wi-Fi cannot read what the agent sends.

It isolates sessions, so a site receiving two requests has no network-level way to tell they came from the same prompt. It gives a clean, non-residential exit address. And it can route a single request through a chosen country.

The company suggests three uses. Checking that a geolocalised page renders correctly for another market, running a research agent from a conference network, and stopping a site correlating dozens of daily requests back to one household.

What it covers, and what it does not

Bitdefender puts the limits on the product page rather than burying them, which is rarer than it should be.

It protects network transport and IP exposure. It leaves prompt content alone, so the model behind the agent still receives everything it normally would, including account identity.

It is not device-wide and not always on. It covers only traffic the agent routes through Bitdefender’s own tools, so anything an agent fetches with its built-in browsing goes out unprotected.

If a tunnel fails, the request dies inside the container. Nothing falls back silently to the user’s real address.

That last detail matters more than it sounds. Apple shipped a bug last month in which Private Relay leaked real IP addresses through WebKit, which is the precise failure this design refuses to allow.

Two documents, two answers on geo-blocking

The announcement says agents can work past geo-blocks and region-locked content without exposing a user’s identity.

The product page says something narrower. It states plainly that the tool will not bypass a site’s terms of service, rate limits or an existing IP ban, and that using it for that can cost a tester their beta access.

Both are Bitdefender’s words, published the same day. The gap between them is the one every agent product currently stands in.

Sites are already fighting back

That fight is live. Amazon blocked Meta’s Muse from its store on Sunday night, and it is suing Perplexity over shopping agents.

Payments reached the same question from the other end. Visa, Mastercard and Ant International have been building Know Your Agent schemes, on the principle that a merchant should know what is buying from it.

Bitdefender argues the opposite case for consumers. An agent should be able to work without dragging its owner’s home address behind it.

The numbers behind the pitch

Bitdefender leans on two outside findings.

Pew Research Center found that 71% of US adults think more AI use will make their personal information less secure.

The Cloud Security Alliance puts agents in what it calls an identity grey area. They borrow workload identities, shared service accounts, or the credentials of whoever is running them.

That produces the consequence Bitdefender sells against. Without separation, every network an agent touches ties back to its owner’s IP address.

What it takes to run

The requirements run heavier than a normal VPN, because containers do the isolating.

It wants macOS 13 or later on Apple silicon, at least 8GB of memory and around 10GB of free disk. It does not support Intel Macs. The download itself is 31MB.

The beta allows four exit locations at once, or eight on the recommended configuration. Bitdefender will publish latency figures after the beta, which it started on 16 September and plans to run for a month.

There are no team features. No single sign-on, no device management, no central configuration. The company says this release targets individual developers and freelancers.

Bitdefender promises Windows and gives no date. It has not set a price either, and says it will wait for usage data first.

Why this company

Bitdefender started in Bucharest in 2001 and is Romania’s largest cybersecurity company. It says it holds more than 580 patents and has customers in over 170 countries.

Britain moved the other way on this technology last year, when it dropped its plan to restrict consumer VPNs under the Online Safety Act. That argument was about whether people should be able to hide an IP address. This product asks it about software instead.

Original source Bitdefender built a VPN that hides your AI agent, not you

Back to home