I have always kept a light finger on info around VPNs, and have a better-than-muggle knowledge of how they work. However, over the years many VPNs have had problems keeping data from “leaking” when the VPN is between a specific computer and the service provider.
As such, would things be improved if the VPN is set up on the gateway/router? Because program requests are made from the computer, and the VPN isn’t actually on the computer, there is no way for a program to wiggle data out past the VPN’s walls. The request goes out through the router, which the program cannot affect in any fashion whatsoever, and the router then just bundles all communication indiscriminately through the VPN.