The recruiter’s message arrived at 12:17 p.m.: Can you join a short introductory call at 12:45? I was working from home, my company laptop was connected to the corporate VPN, and the only other computer nearby had a dead battery. I opened the recruiter’s scheduling page in an Incognito window, then noticed the VPN icon beside the clock. I closed the tab before choosing a time. I had assumed Incognito would keep the visit private. Suddenly, I was not sure private from whom.
That uncertainty has become more common as employers combine VPN sessions, laptop logins, Wi-Fi connections and badge records to understand where and when people work. A 2025 survey found that 69 percent of participating companies monitored office-attendance compliance, up from 45 percent the year before. The U.S. Government Accountability Office has also documented the growth of workplace surveillance through computers, location systems and other digital tools. (Arstechnica) (Gao)
This did not mean someone in HR was watching my screen. It meant I could no longer treat the work VPN as nothing more than a secure route to company files.
Before I used the laptop for anything personal, I needed to know where the company’s visibility ended.
The short answer
My employer could see the corporate VPN connection, including when the work laptop connected and which company resources it reached. If ordinary browsing was routed through the corporate network, the company could also log internet destinations from that laptop. Device-management and security software could create additional records independently of the VPN.
The Work VPN Was Built to Protect Work
A corporate VPN creates a protected connection between the employee’s device and the employer’s network. It allows remote workers to open internal systems without exposing company traffic to everyone on the local Wi-Fi.
But the company controls that connection.
It can normally record when the VPN session starts and ends, which account and device connected, the public IP address it came from and which internal services were accessed. Those records help with security and troubleshooting, but they also reveal working patterns: when the laptop was active, how long it stayed connected and where the connection appeared to originate.
The recruiter’s website raised a different question. Would that page also pass through the company?
Some work VPNs use a full tunnel, sending almost all of the laptop’s internet traffic through the employer’s network. Others use split tunnelling, sending only company-related traffic through the VPN while ordinary browsing uses the home connection. (Microsoft) (Cisco)
The small VPN icon did not tell me which arrangement I had. I could not inspect my employer’s internal routing and logging rules, so there was no reliable way to know whether that specific page would appear in a network record.
That uncertainty was enough to change the decision. The question was no longer whether Incognito could hide one tab. It was whether I should use a company-controlled machine for the task at all.
Disconnecting the VPN Did Not Make the Laptop Personal
I disconnected the corporate VPN and reopened the recruiter’s page.
Almost immediately, the shared drive disappeared. An internal dashboard logged me out. A security prompt asked me to reconnect.
For a few seconds, that felt reassuring. The work tunnel was gone, so perhaps the browser was now private.
But the laptop still belonged to the company.
A managed computer can report information through security and device-management software even when the VPN is disconnected. Depending on the employer’s setup, administrators may receive records about applications, security events, device configuration and visited domains. Microsoft’s enterprise tools, for example, support web-protection reports tied to managed devices. (Microsoft)
Incognito did not change that relationship. It could remove the recruiter’s page from the browser history stored for the next person who opened the laptop. It could not hide activity from software already running on the device.
That was the part I had been overlooking. I was treating the VPN as the boundary when the real boundary was the laptop itself.
Public worker discussions reveal the same mistaken assumption. People frequently ask whether disconnecting the work VPN, opening a private tab or using home Wi-Fi makes personal browsing invisible on a company device. (Reddit)
I did not need another dozen opinions. I needed a device the employer did not manage.
The Real Boundary Was the Device
I plugged in my personal laptop and waited for it to gather enough charge to start.
Both computers were connected to the same home router. That did not give the work VPN automatic access to everything happening on the personal machine. The corporate VPN handled traffic from the device on which it was installed; it did not take over every phone and laptop sharing the household Wi-Fi.
My employer could still see the work laptop connected from my home IP address. It could still see the corporate VPN session and the company services I used. But the recruiter’s page would open on a separate device, outside the company’s accounts, management tools and network tunnel.
That separation mattered more than discovering whether one domain appeared in a split-tunnel rule.
I installed OnlydogVPN on the personal laptop. Basic use did not require a conventional email-and-password account, so I did not have to connect the session to the same address I used for work, shopping and nearly everything else. I selected the private-browsing preset and connected.
Then I reopened the recruiter’s link.
The scheduling page loaded. I chose 12:45, tested the camera and microphone, and joined the call from the personal laptop. The company machine stayed beside it, still connected to the corporate VPN and still showing my normal work applications.
The call was separate from my employer because it never entered the employer-controlled device or network route. The personal VPN added a private connection on the machine I controlled, while the lack of a required email login avoided creating another obvious link to my everyday identity.
That distinction was more useful than trying to outsmart the corporate setup from inside it.
After the call, the recruiter asked for a portfolio link stored on my phone. The service let me connect the second device with a verification code instead of another account and password. I opened the link, sent it and returned to work without putting any part of the conversation on the company laptop.
It was a small follow-up, but it solved the practical reason people end up mixing personal and work activity: the work device is already open, already connected and usually closer.
Now the personal route was nearly as convenient.
What the Employer Could Still See
Once the devices were separated, the answer became much clearer.
My employer could see the corporate VPN connection, including when the work laptop connected and which company resources it reached. If ordinary browsing was routed through the corporate network, the company could also log internet destinations from that laptop. Device-management and security software could create additional records independently of the VPN.
What the employer could not automatically see was every page opened on every personal device connected to my home Wi-Fi.
The work VPN was not a window into the entire house.
Installing a personal VPN on the company laptop would not have created the same clean boundary. It could have conflicted with corporate software, violated company policy or left device-level monitoring untouched. Stacking one VPN on top of another would have made the routing more complicated without changing who owned the laptop.
The stronger move was simpler: keep personal activity on personal hardware.
That principle also matters when an employer asks workers to install a VPN, management profile or security certificate on their own computers. Microsoft’s device-management guidance distinguishes between personal and corporate enrolment because the organisation’s visibility and control can change once a device is registered. (Microsoft) Before accepting that setup, an employee should understand what the company can collect and what remains after work access is removed.
The smaller service does have fewer locations, a shorter public history and fewer independent reviews than the largest consumer VPN providers. For someone choosing a service mainly for broad international coverage, those differences may matter.
They did not decide this problem.
The task was not to find the largest server network. It was to keep a personal conversation outside the technical environment controlled by my employer. The account-light setup and simple second-device connection made that separation easy enough to use under time pressure.
The corporate VPN was doing its intended job: protecting company access on a company machine. It was never designed to protect my personal activity from the organisation operating it.
By the time the recruiter’s call ended, the answer was no longer hidden inside a routing diagram. My employer could see what happened within the work device and its managed connections.
The safest way to keep a personal moment away from the work VPN was not to disguise it inside the company laptop. It was to give that moment a device and connection of its own.
Questions this experience may leave you with
What was actually causing the problem?
My employer could see the corporate VPN connection, including when the work laptop connected and which company resources it reached. If ordinary browsing was routed through the corporate network, the company could also log internet destinations from that laptop. Device-management and security software could create additional records independently of the VPN.
Why did the obvious fixes fail?
My employer could still see the work laptop connected from my home IP address. It could still see the corporate VPN session and the company services I used. But the recruiter’s page would open on a separate device, outside the company’s accounts, management tools and network tunnel.
What should you check first?
The call was separate from my employer because it never entered the employer-controlled device or network route. The personal VPN added a private connection on the machine I controlled, while the lack of a required email login avoided creating another obvious link to my everyday identity.
What finally changed the result?
What the employer could not automatically see was every page opened on every personal device connected to my home Wi-Fi.
What is worth remembering?
By the time the recruiter’s call ended, the answer was no longer hidden inside a routing diagram. My employer could see what happened within the work device and its managed connections.