The Android app registers a unique device ID, authenticates with a secure device credential, requests a server, and then establishes a real WireGuard tunnel from the NexsolLink backend.
VPN status, selected server, device ID, data used, and subscription state are shown in the app. When the device is suspended or revoked, access is denied.