Business VPN: how small teams protect their traffic
Updated on
A business VPN, in the sense that matters to a small team, is an encrypted tunnel on each person's device, protecting customer data as it crosses coworking, hotel and airport networks. It is not remote access to an office network. This guide covers what it solves and how small teams use it.
What is a business VPN?
The term covers two different products. One is remote access to a company's internal network, built and run by an IT department. The other is protection for the traffic of a team working from home, coworking spaces and hotels. SuaVPN is the second: it does not reach your office servers.
The classic corporate VPN connects an employee's laptop to the office network, so they can reach the file server, internal systems, and the printer as if they were at their desk. That requires a VPN concentrator at the company, integration with the user directory, and someone to administer it all. It makes sense for organizations with an internal network and an IT team.
Most small businesses have neither. Work happens in cloud tools: email, shared spreadsheets, a CRM, accounting software, online banking. There is no internal network to reach, just a team spread across cities, each person on a different network, opening customer data from wherever they are.
For that scenario, a business VPN means something else: an encrypted tunnel between each team member's device and a trusted server, so the local network, whether at a coworking space, a hotel, or a cafe, cannot read or tamper with the traffic. That is what SuaVPN provides. It does not reach your company's internal servers; it protects the path between your team and the internet. The guide on what a VPN is covers the basics.
The real risk: coworking, hotel, and airport Wi-Fi
A shared Wi-Fi network sees more than people assume, even with HTTPS everywhere: the IP addresses you connect to, the site names in your DNS lookups, and, on most connections, the server name at the start of the TLS handshake. Whoever runs the network knows that your bookkeeper opened the bank's website and that sales spent the afternoon in the CRM, even if the content stays encrypted.
In a coworking space, the network is run by a third party and shared with companies you have never met. Hotels and airports add two more risks: rogue networks that borrow the official name, and manipulated DNS that leads to cloned login pages. None of this takes a sophisticated attacker; being on the same network is enough.
With the tunnel active, the local network sees only encrypted packets headed for the VPN server. Sites, DNS lookups, and timing patterns stop being visible, and a rogue network can no longer read or redirect anything. What changes is who you trust: the VPN provider instead of every network you sit on, which is why its logging policy matters so much. The public Wi-Fi guide covers this scenario in depth, including hotel login portals.
Does a VPN make your company GDPR or LGPD compliant?
No. Those laws require appropriate technical and organizational security measures, and encrypting traffic on third-party networks is one of them, not all of them. Two-factor authentication, disk encryption on laptops, a password manager and timely updates are still required, and a VPN replaces none of them.
The GDPR in Europe, the LGPD in Brazil, and similar laws elsewhere apply to anyone processing personal data, and many require notifying the regulator and affected people after a breach that creates risk. Small companies often get simplified obligations, not an exemption from protecting what they collect.
Encrypting traffic on third-party networks is one of those measures. It answers a question from client contracts and vendor security questionnaires: how does customer data travel when the team is outside the office? "Each device uses its own WireGuard tunnel and key" is a concrete answer; "we use the coworking Wi-Fi" is not.
What a VPN does not do matters just as much. It does not replace two-factor authentication, full-disk encryption on laptops, a password manager, or timely updates. It will not stop anyone from opening a malicious attachment, does not protect a spreadsheet shared through a public link, and does not make a company "compliant" on its own. It closes one exposure path, the trip across the network, and only that one.
How small teams use the Family plan today
SuaVPN has no business plan. The three plans differ only in device count: Basic covers 3, Pro 5, and Family 10; protocol and locations are identical. Up to ten devices fit on Family; beyond that you need more than one subscription. Current prices are on the plans page, payment is by card through Stripe from anywhere, the subscription renews automatically, and you can cancel at any time.
One person owns the account, picks the plan, and registers each piece of hardware under Devices in the dashboard, naming each after the person and the machine ("ana-laptop", "finance-phone"). For every device, the dashboard generates its own WireGuard configuration, a .conf file for computers or a QR code for phones, which the team member imports into the official WireGuard app. SuaVPN has no app of its own; the setup guide covers each operating system, with detail for Windows and Mac, and the apps page has the official links.
Each device carries its own key pair, which is what makes this workable for a team. When someone leaves or loses a phone, the account owner deletes that device in the dashboard, its configuration stops working, and nobody else is affected. Devices can also use different locations, chosen from those listed on the status page.
The limits, stated plainly: a single account, with no separate administrator profiles and no per-person usage reports; no dedicated IP; no split tunneling to keep part of the traffic outside the tunnel; no browser extension. If your team needs any of those, this is not the right tool yet. Questions before you pay go to support, and teams that travel will want the VPN for travel guide too.
Ground rules that work without an IT department
Setting this up takes no custom software, no server at the office, and no support contract. It takes one account owner, a few minutes per device for the initial setup, and a device list that stays clean. Under Brazilian consumer law, online purchases can be refunded within 7 days, which works as a trial period.
A small team does not need a twenty-page security policy. It needs half a dozen rules everyone understands:
- One configuration per device, never shared. Sending the same .conf file to three people means you can no longer revoke one of them without cutting off the others.
- Device names that identify both the person and the hardware, so removal on someone's last day is immediate and unambiguous.
- Tunnel on by default outside the office: "Always-on VPN" on Android, on-demand activation on iPhone, and on Windows the WireGuard client option that blocks all traffic outside the tunnel.
- In coworking spaces and hotels, accept the captive portal first, then turn the tunnel on and leave it on.
- Review the device list in the dashboard whenever someone leaves or swaps hardware, and delete anything no longer in use.
- Remember that printers and other devices on the local network can become unreachable while the tunnel is active on some systems; switch it off for a moment to print, then back on.
Frequently asked questions
Does SuaVPN offer a business plan?
No. The plans are Basic (3 devices), Pro (5), and Family (10), and small teams use Family. Above 10 devices you need more than one subscription. There is no per-user billing and there are no administrator profiles.
Does a business VPN give access to the office network?
Not this one. SuaVPN protects each device's traffic on its way to the internet. Reaching internal servers requires a remote-access VPN installed and managed by your own company.
Does using a VPN make my company GDPR or LGPD compliant?
Not by itself. These laws require technical and organizational security measures, and encrypting traffic on third-party networks is one of them. Two-factor authentication, disk encryption, and access control are still required.
Can I send the same .conf file to the whole team?
No. Each device should have its own configuration and its own key, created in the dashboard. That is the only way to revoke one person's access without affecting everyone else.
How do I remove access for someone who left?
In the dashboard, under Devices, delete that person's device. Their configuration stops working and the slot is freed for another device.
Does it work on coworking Wi-Fi with a login page?
Yes. Connect to the Wi-Fi, accept the login portal with the tunnel off, then turn the VPN on. After that it can stay on the whole time.
Try SuaVPN
WireGuard, a card subscription, several devices per subscription and cancellation whenever you want.
See plans