404PrivacyDocs

Understand 404

How 404 fits together

404 is a local processing stack. One selected profile directs supported changes across the browser, application, and, where available, packet layers. It does not provide an exit network or hide an account you sign into.

The local path

The desktop app manages setup and controls. Supported browser traffic goes to STATIC on your device, where it can process TLS, HTTP, and supported page-visible signals. Rose adds supported packet handling on Linux paths. Traffic then follows the network route you configured to the destination.

FIG 01One profile, one local path
Selected profileCoordinates supported browser and network signals
The profile and local CA remain on your device. 404 does not provide an exit IP; the destination receives traffic through the network route you selected.

The diagram shows responsibilities and boundaries, not a guarantee that every observer sees a complete or indistinguishable profile. Feature coverage depends on browser, operating system, protocol, and release.

What each part does

The active profile

A profile supplies a coordinated target for supported signals. Changing one visible value in isolation can create conflicts with the rest of the session; the profile gives supported layers a shared definition.

STATIC

STATIC is the local TLS-terminating proxy. It handles supported handshake, header, and response-stage behavior. To process HTTPS locally, it generates a local certificate authority (CA) that must be trusted by the relevant browser or operating system.

Rose

Rose is the Linux distribution and kernel path used for supported packet handling. Its eBPF component can adjust supported egress fields where configured. Other platforms or unsupported paths retain their native packet characteristics.

Desktop controller

The desktop app manages the operator-facing experience: configuration, updates, local trust, routing, and supported platform setup. On Windows, it manages a Rose-based distribution through WSL2.

Product and code

The 404 Desktop application is the managed product path. The underlying open source stack can be inspected and run separately. Account, licensing, and release delivery services support the managed product; they are separate from the local browsing path.

Local processing boundary404 does not need to relay your browsing traffic through a 404-operated exit. Websites still receive your requests through the route you selected, and your IP address is not changed by 404 alone.

Trust and limits

  • Local CA: Protect the certificate authority's private key and remove its trust when you stop using the local proxy.
  • Supported surfaces: New browser APIs, protocols, and platform behavior can expose signals that the current release does not control.
  • Accounts and behavior: Logging in, distinctive browsing behavior, and the content you send can identify or link sessions.
  • Network path: 404 is not a VPN or anonymity network. Choose a separate routing tool when changing the visible IP address matters.