Architecture
404 processes supported browser traffic on your device. The desktop application manages setup and the selected profile. STATIC handles the local proxy path. On supported Linux paths, Rose provides the runtime for packet handling. Traffic reaches its destination through the network route you chose.
Follow a request
The browser and STATIC run locally. STATIC opens the upstream connection and receives the response before returning it to the browser. The destination sees traffic through your chosen network route; 404 does not provide an exit IP.
- Browser. A supported browser sends a request to STATIC’s local listener.
- STATIC. The proxy uses the active profile to shape supported upstream TLS and HTTP behavior, then connects to the destination through your chosen route.
- Linux packet path, where available. When configured on a supported Linux path, the eBPF component can adjust supported outgoing packet fields. On Windows, the managed distribution uses Rose in WSL2 for this path.
- Response. STATIC receives the response, processes supported headers and eligible page content, and returns it to the browser. Page-visible changes depend on the browser, page, and injection conditions.
The desktop application supervises setup and configuration. It is not a relay for the browsing traffic.
One selected profile
A browser presents signals at several layers: a TLS handshake, HTTP headers, JavaScript-visible properties, and network packets. Changing one value without considering the others can create contradictions. STATIC derives supported application behavior from the active profile. On a supported Linux packet path, lower-level targets can follow that same profile.
The profile provides a coordinated target for supported fields. It does not guarantee that every observable signal matches, or that different sessions cannot be linked.
The local components
Desktop application manages installation, profile selection, updates, local certificate trust, and supported system proxy configuration. On Windows, it operates the Rose-based distribution through WSL2.
STATIC is a local Rust proxy. It terminates supported HTTPS traffic using a local certificate authority, constructs supported upstream TLS and HTTP behavior, and processes eligible responses to coordinate page-visible signals. Its private CA key stays with STATIC.
Rose is the focused Linux distribution and runtime used by the Windows WSL2 path. It starts STATIC and supports the Linux traffic-control/eBPF packet path. Rose does not replace STATIC or act as a separate internet exit.
Boundaries and limits
404 does not provide an exit network or change your public IP address by itself. Websites still receive traffic through your chosen network route. Signing into an account, sending identifying content, or keeping a distinctive browsing pattern can link activity regardless of the selected profile.
Coverage varies by platform, browser, protocol, and release. Browser APIs and page policies can prevent some page-visible changes; packet handling applies only on configured, supported Linux paths. Treat the profile as controlled presentation, not a guarantee of anonymity.