Extended VPN comparison with 20+ providers verified 2024-2025. Privacy scoring, feature matrix, jurisdiction analysis, modern protocol breakdown (post-quantum, REALITY, AmneziaWG), payment OPSEC, decision guide. Ruthless on ownership chains, intelligence ties, and court-tested no-logs claims.
Filter and compare 20+ VPN providers by privacy criteria, features, and trust indicators. Privacy score is calculated from anonymous signup, cash/crypto payment, jurisdiction (5/9/14 Eyes), audit recency, RAM-only servers, open source clients, court-tested no-logs, parent company, and scandal history.
For a focused Mullvad-centric comparison with 7 providers side-by-side, see the Mullvad VPN Trust Comparison widget. For per-provider scandal breakdowns and ownership mapping, see the Mullvad VPN sheet.
| Provider | Jurisdiction (Eyes) | Parent | Protocols | Port Fwd | Sim. | Obfuscation | Tor | WG Impl | RAM-only | PQ status | Open client | Court-tested |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mullvad | Sweden (14) | Mullvad/Amagicom (independent) | WG, OpenVPN | None (removed 2023) | 5 | Shadowsocks, obfs4 bridges | SOCKS5 | Native kernel | Yes | Default 2025.2 (ML-KEM-768 + McEliece) | Yes (GPL) | Yes (Sweden 2023) |
| IVPN | Gibraltar | IVPN Limited (independent) | WG, OpenVPN | Yes (static) | 2 / 7 Pro | V2Ray, obfs4 | No | Native | Yes | Evaluating | Yes (GPL) | Untested (no demands) |
| ProtonVPN | Switzerland | Proton AG / Proton Foundation | WG, OpenVPN, IKEv2, Stealth | No | 1-10 | Stealth (WG-in-TLS) | Tor-over-VPN | Native | Partial (Secure Core) | Research | Yes (GPL) | Mail side only (2021) |
| OVPN.com | Sweden (14) | OVPN Integritet AB (independent) | WG, OpenVPN | Yes | 4-8 | OpenVPN/TCP | No | Native | Yes | None | Partial | Yes (Sweden 2020) |
| AirVPN | Italy (14) | Air Srl (independent) | WG, OpenVPN | Yes (static) | 5 | SSH, SSL/stunnel | Tor-over-VPN | Native | Partial | None | Yes (Eddie GPL) | Untested |
| AzireVPN | Sweden (14) | Netbouncer AB (independent) | WG, OpenVPN | Yes | 5 | None | No | Native | Yes (blind operator) | None | Partial | Untested (canary) |
| Riseup VPN | USA (5) | Riseup Networks (501c) | OpenVPN (LEAP) | No | n/a | None | Yes | None | Yes | None | Yes (GPL) | NSL handled, no data |
| Calyx VPN | USA (5) | Calyx Institute (501c3) | OpenVPN (LEAP) | No | n/a | None | Yes | None | Yes | None | Yes (GPL) | Founder beat NSL gag |
| Mozilla VPN | USA (5) | Mozilla Corp (uses Mullvad infra) | WG only | No | 5 | None | No | Mullvad native (reseller) | Yes (Mullvad fleet) | Yes (Mullvad fleet) | Yes (GPL) | Untested (reseller front) |
| TorGuard | USA (5) | VPNetworks LLC | OpenVPN, WG | Yes (static, dedicated IP) | 8-12 | Stealth proxy (stunnel) | No | Native | No | None | No | 2022 BitTorrent ISP block settlement |
| NordVPN | Panama (op. Lithuania, 9) | Nord Security / Tesonet | OpenVPN, NordLynx (WG) | No | 10 | XOR-OpenVPN servers | Onion-over-VPN | NordLynx wrapper (closed) | Yes | Linux 2025 PQ NordLynx | Partial | Yes (Panama Oct 2024, payment only) |
| Surfshark | Netherlands (9) | Nord Security | OpenVPN, WG, IKEv2 | No | Unlimited | Camouflage | No | Native | Yes | None | Partial | Untested |
| TunnelBear | Canada (5) | McAfee / US | OpenVPN, WG, IKEv2 | No | Unlimited | GhostBear (obfs4) | No | Native | No | None | No | Untested |
| Windscribe | Canada (5) | Windscribe Ltd (independent) | OpenVPN, WG, IKEv2, WStunnel, Stealth | Yes (ephemeral) | Unlimited | WStunnel, stunnel | No | Native | Now (post-2021 fix) | None | Yes (GPL) | Yes (Ukraine 2021, keys leaked) |
| Hide.me | Malaysia (Labuan) | eVenture Ltd | OpenVPN, WG, IKEv2, SSTP, SoftEther | Yes | 10 | SoftEther, SOCKS | No | Native | Yes | None | Partial | Claimed |
| PIA | USA (5) | Kape Technologies | OpenVPN, WG | Yes | Unlimited | Shadowsocks | No | Native | Yes | None | Yes (GPL) | Yes (US 2016, 2018, pre-Kape) |
| ExpressVPN | BVI | Kape Technologies | Lightway, OpenVPN | No | 8 | Lightway obfuscation | No | None (Lightway only) | TrustedServer | Research | Lightway core only | Yes (Turkey 2016) |
| CyberGhost | Romania | Kape Technologies | OpenVPN, WG, IKEv2 | No | 7 | None | No | Native | Yes | None | No | Untested |
| ZenMate | Germany (14) | Kape Technologies | OpenVPN, IKEv2 | No | Unlimited | None | No | None | No | None | No | Untested |
| IPVanish | USA (5) | Ziff Davis | OpenVPN, WG, IKEv2 | No | Unlimited | Scramble (XOR) | No | Native | No | None | No | LOGS HANDED OVER (2016) |
| HMA | UK (5) | Gen Digital | OpenVPN, WG, IKEv2 | No | 10 | None | No | Native | Yes | None | No | LOGS HANDED OVER (2011) |
| HotspotShield / Aura | USA (5) | Aura | Hydra (proprietary), OpenVPN | No | 5-10 | Hydra wrapper | No | None | No | None | No | FTC complaint 2017 |
| VyprVPN | USA (was Switzerland) | Certida LLC (Texas) | OpenVPN, WG, Chameleon | No | 5-30 | Chameleon (XOR-derived) | No | Native | Yes | None | No | Untested (jurisdiction silently moved 2023) |
| VPN Unlimited | USA | KeepSolid | OpenVPN, IKEv2, WG, KeepSolid Wise | No | 5-10 | Wise (TLS wrap) | No | Native | No | None | No | Policy contradicts marketing |
| TorGuard | USA (5) | VPNetworks LLC | OpenVPN, WG, IKEv2 | Yes | 12 | Stunnel, OpenConnect | No | Native | No | None | No | Settled with film studios 2022 (US-server torrent block) |
Court-tested no-logs (or independent founders with public legal stance), audited infrastructure, anonymous payment.
| Provider | Strength | Weakness | Verdict |
|---|---|---|---|
| Mullvad | Numeric account (no email, no username, no password - unique in the industry since 2009), cash-by-post (SEK/EUR to Gothenburg), XMR, raid-tested April 2023 (six Swedish NOA officers entered Gothenburg office with a warrant tied to a German request, left empty-handed - no data to seize), Cure53 infrastructure audit June 2024 + Assured AB web app + Radically Open Security 2023 + X41 D-Sec 2024, default post-quantum (ML-KEM-768 + Classic McEliece hybrid via wgephemeralpeer) since release 2025.2 (9 Jan 2025), no affiliate program, Mullvad Browser co-developed with Tor Project (April 2023), DAITA traffic shaping. Note: the raid is an operational test (no data existed), not a court ruling on architecture - for the strongest judicial ruling, see OVPN.com 2020 below. | Removed port forwarding 2023 (anti-abuse). Sweden = 14 Eyes nominal, but no mandatory VPN data retention + 2 court precedents (Mullvad raid + OVPN ruling) explicitly protecting VPN operators. | RECOMMENDED |
| IVPN | Founder-owned (Nick Pestell, Royal Holloway ISG - one of Europe's top InfoSec programmes), previously risk management at RBS and Network Rail. 100% sole-owner since 2009, zero external investors, zero acquisitions. Gibraltar (not in Eyes - IVPN's own analysis confirmed by SafetyDetectives and independent researchers). Refuses affiliate marketing since 2019. Cure53 no-logs audit 2019 + 6 app audits. Anonymous account IDs (no email required), port forwarding still on. Warrant canary consistently maintained: zero warrants served, zero disclosures. Dev team distributed across Europe (CTO Fedir Nepyivoda in Ukraine). Note: vpnMentor (owned by Kape) features a "Keep This in Mind Before Buying" warning on IVPN - expected bias given Kape owns competing VPNs. | Smaller server count (~80 vs Mullvad's ~700). Not court-tested (zero demands received, so no proof of resistance under pressure unlike Mullvad/OVPN). No post-quantum tunnel (evaluating Mullvad's approach). Gibraltar is a British Overseas Territory (UK handles foreign affairs) which is a theoretical diplomatic pressure channel, though no precedent exists. Score gap vs Mullvad (75 vs 95) is entirely explained by courtTested (0 vs 10) + postQuantum (0 vs 10) + ramOnly (5 vs 10), NOT by any trust concern. | RECOMMENDED |
Solid technical posture, audited, but with notable jurisdictional or audit gaps.
| Provider | Strength | Weakness | Verdict |
|---|---|---|---|
| ProtonVPN | Swiss, Securitum no-logs audit 4 years running (2022-2025), majority owned by non-profit Proton Foundation since 2024, Stealth protocol works in Iran/Russia, free tier with no data cap. | ProtonMail logged a Youth-for-Climate activist's IP in 2021 under Swiss court order (mail not VPN, but precedent stands). VÜPF revision threat almost passed Dec 2024. | STRONG |
| OVPN.com | Won 2020 Swedish Patent and Market Court case against Rights Alliance (representing Svensk Filmindustri + Nordisk Film): the court examined OVPN's architecture in depth (founder David Wibergh testified + submitted affidavits), accepted that the no-logs architecture made the demand impossible to satisfy, and ordered the movie studios to pay 108,000 SEK in legal fees. This is legally stronger than the Mullvad 2023 raid - the raid proved no data existed on-site but produced no judicial ruling on the architecture itself; the OVPN case is an actual court judgment validating no-logs as a technical fact. RAM-only, owned servers in key POPs. Founded 2014 by David Wibergh, OVPN Integritet i Sverige AB (Stockholm), fully independent. | Smaller network (~30-40 servers vs Mullvad ~700), no free tier, less known due to zero marketing (deliberate choice to avoid becoming an acquisition target). No PQ tunnel. | STRONG |
| AirVPN | Trust-by-transparency, real-time public server stats, founder Paolo Brini answers in forum, refuses Italian Piracy Shield, blocked Italian payments rather than comply. | No third-party audit ever. Italian jurisdiction (14 Eyes, 6-year telecom retention does not bind VPNs but climate is hostile). | STRONG with caveats |
| AzireVPN | "Blind operator" diskless servers, ephemeral keys, warrant canary, founder-run since 2012. | No public audit. If you trust Mullvad/OVPN there is no reason to pick this over them. | STRONG with caveats |
Donation- or membership-funded, US jurisdiction (which is the worst possible) compensated by zero-data architecture and legal expertise.
| Provider | Strength | Weakness | Verdict |
|---|---|---|---|
| Riseup VPN | Volunteer collective (Seattle), zero IP/DNS logs, anonymous LEAP token bridges, has actually received and processed FBI warrants (2017 transparency report). | USA, NSL/FISA exposure. Slow, small network, not general purpose. | RECOMMENDED for activists |
| Calyx Institute VPN | Founder Nicholas Merrill won Doe v. Ashcroft, the first successful US court challenge to an NSL (gag fully lifted 2015 after 11 years). Free for Calyx members, LEAP platform, OpenVPN. | USA, NSL/FISA. Pair with Tor for high-stakes work. | RECOMMENDED for activists |
Functional, sometimes audited, but with ownership, breach disclosure, or jurisdiction issues that disqualify them from a serious threat model.
| Provider | Strength | Weakness | Verdict |
|---|---|---|---|
| NordVPN | PwC no-logs audits 2018-2024, NordLynx (WG with double-NAT), large network, Panama Oct 2024 warrant produced only payment data (no traffic logs), shipped PQ NordLynx on Linux 2025. | Operationally run from Lithuania via Tesonet (data scraping/proxy network parent). 2018 Finland datacentre breach disclosed only October 2019 (18 months late, after Twitter rumours). Affiliate marketing dominance. | CAUTION |
| Surfshark | Deloitte no-logs audits 2023/2024, Cure53 server audits, unlimited devices. | Merged with Nord Security Feb 2022, undercommunicated to users. De facto Nord conglomerate. Netherlands 9 Eyes. | CAUTION |
| TunnelBear | Cure53 annual public audits since 2017 (industry-leading at the time), well-engineered, friendly UX. | Owned by McAfee (US) since March 2018. Canada 5 Eyes + US parent = stacked surveillance exposure. | OK for cafe wifi only |
| Windscribe | Generous free tier, R.O.B.E.R.T. blocking, WStunnel obfuscation, ephemeral port forwarding. | June 2021 Ukraine seizure exposed UNENCRYPTED OpenVPN private keys with deprecated cipher. Founder Yegor Sak admitted publicly. Fixed (RAM-only as of July 2021), but the failure was severe. Canada 5 Eyes. | CAUTION |
| Hide.me | Malaysia (no Eyes), 10 devices, free tier, Securitum 2024 no-logs audit, court-tested claims. | Less audit history than top tier. Section 233 CMA used aggressively against Malaysian dissent. | OK |
Critical trust failures: ownership scandals, intelligence ties, broken no-logs claims, or undisclosed jurisdiction moves.
| Provider | Reason to AVOID |
|---|---|
| ExpressVPN | Owned by Kape Technologies (formerly Crossrider, identified as adware distribution platform 2015 by UC Berkeley/Google). Ultimate beneficial owner Teddy Sagi (Israeli-Cypriot, convicted of bribery 1996 in Israel, took Kape private June 2023 via Unikmind). CIO Dec 2019 - July 2023 Daniel Gericke signed a Sept 2021 DOJ deferred prosecution agreement admitting Project Raven (UAE DarkMatter) work targeting journalists/activists, $335k fine, lifetime US clearance ban. ExpressVPN knew when hiring. Kape also owns vpnMentor and Wizcase via Webselenese ($149M, March 2021), the review sites that rank Kape products top. |
| CyberGhost | Kape since March 2017 (~$10.5M). Same Crossrider ancestry, same Webselenese review-site capture. Romanian jurisdiction is the only positive and does not offset corporate parent. |
| ZenMate | Kape since 2018 (~$5M). Weakest of the Kape stack, German jurisdiction (14 Eyes), no notable audits. |
| PIA (post-Kape) | Kape since November 2019 ($127M). Pre-Kape PIA had two genuine US court no-logs wins (2016 FBI bomb-threat subpoena, 2018 hacking investigation). Acquisition permanently changes the trust calculus. |
| IPVanish | May 2016 Homeland Security case: under then-owner Highwinds, IPVanish first claimed it could not assist (no logs), then handed over detailed connection logs identifying a Comcast user in a child exploitation investigation. THE cleanest documented case of a "no-logs" VPN lying. Now owned by Ziff Davis. Brand permanently tainted. |
| HMA (HideMyAss) | September 2011 LulzSec/Cody Kretsinger case: UK court order, FBI request, HMA handed over connection logs that convicted Kretsinger. Marketed as anonymity tool while logging. Now owned by Gen Digital (NortonLifeLock+Avast merger 2022, parent of Jumpshot data-selling scandal). UK 5 Eyes. |
| HotspotShield / Pango / Aura | August 2017 CDT FTC complaint (with Carnegie Mellon researchers): free product shared user data with ad networks, injected JavaScript via iframes for advertising, intercepted/redirected HTTP requests to partner e-commerce sites. Closed source, US, AES-128 default. |
| VyprVPN | In 2023 silently moved from Golden Frog GmbH (Switzerland) to Certida LLC (Austin, Texas). No press release, no user notification. The entire marketing was Swiss jurisdiction. Bad faith. |
| VPN Unlimited / KeepSolid | New York USA, R&D Odessa. Privacy policy historically retains time-stamped connection metadata while marketing claims "zero log". Marketing/policy contradiction is a textbook do-not-trust signal. |
| TorGuard | March 2022 settlement with film studios (same plaintiffs that won $10M default vs LiquidVPN). Agreed to block BitTorrent on all US servers. Implies per-server protocol identification capability. US, no compelling reason over audited alternatives. |
| Provider | Monthly | Annual (per mo) | Best Deal | Anonymous Payment |
|---|---|---|---|---|
| Mullvad | EUR 5 flat | EUR 5 | EUR 5 (no discount) | Cash by post (SEK/EUR), XMR, BTC, BTC-LN |
| IVPN | $6 / $10 Pro | $5 / $8.33 | $4.5 / $6 (3yr) | Cash, XMR, BTC |
| ProtonVPN | Free / $10 Plus | $5 (Plus) | $4 (Plus 2yr) | Cash by post (USD/EUR/CHF to Geneva HQ), BTC, card, PayPal |
| OVPN.com | $11 | $4.99 | $4.5 (2yr) | Cash, XMR, BTC |
| AirVPN | $7.50 | $4.64 | $2.75 (3yr) | XMR, BTC, cash voucher |
| AzireVPN | $5 | $3.25 | $3.25 (annual) | XMR, BTC, cash |
| Riseup VPN | Donation | Donation | Donation | n/a |
| Calyx VPN | Free for Calyx members | $500/yr (org) | Membership | Donation / membership |
| Windscribe | $9 | $5.75 | $5.75 | BTC, XMR, Ethereum, Dogecoin, paysafecard, Hashed Login (no email) |
| Hide.me | Free / $10 | $5 | $2.59 (2yr) | BTC, XMR, card |
| Mozilla VPN | $10 | $5 | $5 | Card only |
| NordVPN | $13 | $4.59 | $3.09 (2yr) | Crypto, gift cards |
| Surfshark | $16 | $3.99 | $2.19 (2yr) | Crypto, gift cards |
| TunnelBear | $10 | $3.33 | $3.33 (3yr) | Card only |
| PIA | $12 | $3.33 | $2.03 (3yr) | Crypto, gift cards |
| ExpressVPN | $13 | $8.32 | $6.67 (2yr) | BTC |
| CyberGhost | $13 | $4.29 | $2.19 (2yr+) | BTC |
| Alliance | Countries | Risk |
|---|---|---|
| 5 Eyes (UKUSA) | US, UK, Canada, Australia, New Zealand | Highest. NSL, FISA 702, IPA 2016, CLOUD Act, TOLA 2018 |
| 9 Eyes | + Denmark, France, Netherlands, Norway | High. Wiv 2017 (NL), bulk cable interception |
| 14 Eyes (SSEUR) | + Germany, Belgium, Italy, Sweden, Spain | Moderate. SIGINT sharing, BND-NSA, FRA cable taps |
| Non-Eyes | Switzerland, Iceland, Panama, BVI, Gibraltar, Malaysia, Romania | Lower. MLAT and political pressure still apply |
| Event | Date | What it means |
|---|---|---|
| Swiss VÜPF revision | Killed Dec 10 2024 | Federal Department of Justice draft would have forced any service with 5,000+ users (incl. VPN/email) to log IPs for 6 months, mandate ID verification, retain decryption capability. Proton, Threema, NymTech publicly threatened to leave Switzerland. Federal Parliament accepted Gapany motion 10 Dec 2024 killing the draft and ordering an independent impact assessment. Close call. |
| UK Online Safety Act 2023 | Enforcement 2024-2025 | Section 122 "spy clause" empowers Ofcom to issue notices requiring "accredited technology" to scan E2EE content. Government deferred enforcement to "technically feasible" but the power remains. Age verification began 25 July 2025, ProtonVPN reported 1800% UK signup spike. |
| UK IPA 2024 amendments | Passed 2024 | Expanded technical capability notice scope, bulk dataset categories. Apple publicly opposed. |
| USA RISAA 2024 (FISA 702 reauth) | 20 April 2024, sunset 20 April 2026 | "ECSP expansion" language extended compelled-assistance reach to any "custodian" of equipment through which communications transit (commercial landlords, datacentre owners). EFF and Brennan Center criticized; narrowing amendments only partial. |
| EU Chat Control proposal | 2025 status: stalled | Council failed to find QM in 2024 and 2025. Belgian and Polish presidencies pushed; Germany, Netherlands, Czechia blocking. Not law as of early 2026. |
| Romania Constitutional Court precedent | 2009 + 2014 (still binding) | Decision 1258/2009 and Decision 440/2014 struck down national data retention. Romania has not attempted a replacement law. EU-leading jurisprudence. |
| Iceland Electronic Communications Act 70/2022 | In force | Imposes 6-month metadata retention on telecom operators. Does NOT apply to VPN providers (not classified as electronic communications service operators). Important distinction vs the Iceland-as-haven myth. |
| Italy Piracy Shield | Live 2024 | AGCOM can order ISP IP/domain blocks within 30 minutes, no judicial review. AirVPN blocked Italian payment methods rather than comply. |
| Canada Bill C-26 cybersecurity | In Senate early 2025 | Grants CSE power to issue secret cyber security directions to telecoms with non-disclosure obligations. |
| Microsoft PPTP/L2TP deprecation | October 2024 blog | Windows Server RRAS no longer accepts incoming PPTP or L2TP. Both protocols formally retired server-side. |
| Rank | Jurisdiction | Why | Caveats |
|---|---|---|---|
| 1 | Romania | Constitutional court struck down data retention twice (2009, 2014), no replacement attempted, EU GDPR + CJEU backstop | CyberGhost (the only Romanian-HQ provider) is Kape-owned |
| 2 | Sweden | LEK statutory gap excludes VPNs from telecom retention, court-tested no-logs (Mullvad raid April 2023 + OVPN 2020 court case), EU CJEU backstop | 14 Eyes via FRA cable taps; replacement retention bills pending |
| 3 | BVI / Gibraltar | No retention, low MLAT volume, GDPR-equivalent (BVI DPA 2021) | UK Overseas Territory: GCHQ adjacency theoretical; Kape parent for ExpressVPN |
| 4 | Panama | No retention applicable to non-licensed VPNs, distant from EU/US criminal pipelines, NordVPN Oct 2024 warrant produced only payment data | NordVPN operationally Lithuanian; FATF grey list pressure |
| 5 | Switzerland | Strong reputation, Proton legal team, FADP 2023 | VÜPF 2024 fight shows the state actively wants VPN retention; ProtonMail 2021 Youth-for-Climate IP order shows compliance culture |
| 6 | Netherlands | No retention for VPNs since 2015 (Hague District Court), Perfect Privacy 2016 Rotterdam seizure produced nothing | 9 Eyes, Wiv 2017 bulk interception |
| 7 | Iceland | Strong press freedom (IMMI), no Eyes membership | 6-month telecom metadata retention is real (Act 70/2022) but does not bind VPNs |
| Rank | Jurisdiction | Why |
|---|---|---|
| 1 | United Kingdom | IPA 2016 ICR 12-month retention, OSA Section 122 scanning, 5 Eyes core, GCHQ bulk interception, CLOUD Act direct service, HMA 2011 actual log handover. Single worst G7 jurisdiction for operators. |
| 2 | United States | 5 Eyes core, NSL gag orders (18 USC 2709), FISA 702, RISAA 2024 ECSP expansion, CLOUD Act issuer. PIA cases prove no-logs is defensible; silent compelled assistance is the permanent risk. |
| 3 | Australia | TOLA Act 2018 technical assistance and capability notices explicitly targetable at operators. 5 Eyes core. |
| 4 | Italy | 6-year telecom retention, Piracy Shield 2024 bypass on judicial review, 14 Eyes. AirVPN dropped Italian payments rather than comply with Piracy Shield. |
| 5 | Canada | 5 Eyes core, Bill C-26 secret CSE directions, parent-company capture of TunnelBear by McAfee. |
| 6 | Estonia | 1-year retention under Electronic Communications Act, longer than Sweden/Germany. "Digital republic" branding masks stronger SIGINT cooperation than its reputation. |
| Rank | Method | Anonymity | Accepted By | Notes |
|---|---|---|---|---|
| 1 | Cash by post (envelope of bills) | Maximum (zero digital trail) | Mullvad (SEK/EUR), IVPN, OVPN.com, ProtonVPN (USD/EUR/CHF to Geneva HQ) | Literal banknotes mailed to a PO box or HQ address. The ONLY method with zero digital footprint. Risk: postal interception (low). Proton requires username on the slip so the account can be credited. |
| 2 | Monero (XMR) | Very High | Mullvad, IVPN, AirVPN, OVPN.com, AzireVPN, Hide.me, Windscribe, TorGuard | Ring signatures + stealth addresses + RingCT. Strongest privacy coin. As of 2025 no public chain-analysis breakthrough. Forks intact, no protocol downgrade. ProtonVPN does NOT accept XMR (BTC only among crypto options). |
| 3 | Bitcoin (BTC) | Pseudonymous | Most providers | Public ledger, traceable via clustering. Improve with cash-bought BTC (ATM with no KYC, increasingly rare), CoinJoin (Wasabi/Samourai - both under DOJ pressure 2024-2025), or LN. |
| 4 | Bitcoin Lightning | Better than on-chain | Mullvad, others | Off-chain hops, less trivially graph-able. |
| 5 | Prepaid gift cards | Moderate | NordVPN, Surfshark, PIA | Buy with cash to break the bank link. WARNING: Target, Walmart, Best Buy USA now require ID for gift card purchases above ~$300, and many require ID even for smaller amounts at register. CCTV at point of purchase remains. |
| 6 | Card / PayPal | None | All providers | Full identity linked. Defeats the purpose. |
| Method | To VPN | To Processor | Blockchain Traceable |
|---|---|---|---|
| Cash by post | Nothing | n/a | No |
| Monero | Nothing (random subaddress) | n/a | No (ring sigs) |
| Bitcoin | Wallet address | n/a | Yes (chain analysis) |
| Lightning | Invoice (short-lived) | n/a | Partial |
| Gift card | Card number | Purchase location (CCTV, ID since 2024) | No |
| Card / PayPal | Name, address | Full identity + VPN purchase pattern | No |
| Feature | WireGuard | OpenVPN (DCO) | IKEv2/IPsec | Lightway (Rust) |
|---|---|---|---|---|
| LoC | ~4,000 (kernel + userland) | ~100,000 + 500k OpenSSL | strongSwan ~400k, Libreswan ~250k | ~2,000 C, similar Rust |
| Crypto | Noise_IKpsk2, ChaCha20-Poly1305, Curve25519, BLAKE2s, HKDF | AES-256-GCM, TLS 1.3, X25519/secp384r1 | AES-256-GCM or ChaCha20-Poly1305, X25519/P-384 | DTLS 1.3 via wolfSSL, X25519, ChaCha20 |
| Algo agility | None (by design) | Full | Full | Limited |
| Speed (2025) | Fastest baseline | Within 10-15% with DCO; ~700 Mbps vs WG ~600 Mbps on Mudi 7 router | Fast | Fast (Lightway Turbo multi-lane) |
| Audits | Donenfeld+Milner (2018), Dowling+Paterson (2018), Inria machine-checked (2019). No critical findings 2018-2025. | Cryptography Engineering 2017, OSTIF/Quarkslab 2017, no full re-audit at scale; bug bounty driven. | strongSwan piecemeal; CVE-2023-41913 charon-tkm. | Cure53 Oct-Nov 2022, retest Feb 2023, Cure53 + Praetorian on Rust rewrite 2024. |
| UDP/TCP | UDP only natively (TCP via udp2raw, wstunnel, AmneziaWG) | Both | UDP 500/4500 (TCP RFC 9329 rare) | UDP default, TCP fallback |
| Mobile roaming | Excellent (stateless, endpoint re-resolution) | Poor (TCP breaks on rebind) | Best in class via MOBIKE RFC 4555 | Good (connection IDs) |
| DPI resistance | None (recognizable handshake type bytes 0x01/0x02). Dead in Russia since mid-2025 TSPU rollout without obfuscation. | Weak (opcode byte fingerprint). Always wrap. | Zero (UDP 500/4500 trivial). Blocked in CN/IR/RU. | Low (DTLS handshake recognizable). |
| Post-quantum | Mullvad wgephemeralpeer (ML-KEM-768 + Classic McEliece via PSK), default desktop since 2025.2 (Jan 9 2025). NordLynx PQ on Linux 2025. | Experimental OQS-OpenSSL only, no commercial deployment. | Draft-ietf-ipsecme-ikev2-pqc-hybrid-keys in progress. None shipped. | Research, not shipped. |
| Open source | GPLv2 | GPLv2 | GPLv2 | GPLv2 (lightway-core, lightway-core-rs) |
| Privacy gotcha | Static public key persists identity if leaked once; no traffic padding | Heavy attack surface | Closed-source native clients on iOS/macOS/Win | Single-vendor (ExpressVPN/Kape) |
| Protocol | Status | Why |
|---|---|---|
| PPTP | BROKEN since 2012 | MS-CHAPv2 broken by Marlinspike + Marsh Ray at DEF CON 20 (2012) using chapcrack + CloudCracker (~2^56 DES brute force, ~24h for $200). Microsoft formally deprecated server-side October 2024. Apple/Google dropped client support 2016-2021. NEVER USE. |
| L2TP/IPsec | DEAD | Microsoft formally deprecated server-side October 2024 (Windows Server 2025 RRAS). Pre-shared key mode dominates consumer use; PSKs published on provider help pages enable offline brute force. Snowden suggests NSA may have weakened IPsec parameters. BlastRADIUS CVE-2024-3596 affected RADIUS-authenticated IPsec stacks. |
| SSTP | Legacy Windows-only | TCP 443 looks like HTTPS to passive observer, but ClientHello fingerprintable and inner PPP detectable by ML classifiers. China blocks. Microsoft Azure VPN Gateway phasing out. |
| CVE | Date | Impact |
|---|---|---|
| CVE-2024-27459 | March 2024 | Windows client, chainable with others |
| CVE-2024-24974 | March 2024 | Windows interactive service privilege escalation |
| CVE-2024-27903 | March 2024 | Windows client, plugin loading |
| CVE-2024-1305 | March 2024 | TAP-Windows6 driver, chainable RCE+LPE on Windows |
| CVE-2024-8474 | 2024 | OpenVPN Connect Android logs private key in cleartext via ADB debug |
| CVE-2025-2704 | 2025 | tls-crypt-v2 dynamic DoS, affects 2.6.1 through 2.6.13 |
| CVE-2024-3596 (BlastRADIUS) | July 2024 | RADIUS response-auth MD5 collision; affects L2TP/IPsec stacks using RADIUS (Sophos and others patched) |
NIST released the first three finalized post-quantum standards on August 13 2024:
FIPS 206 (FN-DSA / Falcon) still in draft end-2025.
| Provider | PQ Implementation | Algorithm(s) | Production status 2025 |
|---|---|---|---|
| Mullvad | wgephemeralpeer over WireGuard PSK | ML-KEM-768 + Classic McEliece (hybrid) | DEFAULT on all desktop since release 2025.2 (Jan 9 2025). iOS/Android opt-in. |
| NordVPN | NordLynx extension | Unspecified (likely ML-KEM-768 via PSK) | Linux first, rolling out 2025 |
| ProtonVPN | Research | TBD | Not shipped |
| ExpressVPN (Lightway) | Research | TBD | Not shipped |
| IVPN | Evaluating Mullvad's approach | TBD | Not shipped |
| Everyone else | None | - | Not shipped |
Critical correction: any 2024 cheatsheet claiming "no VPN ships post-quantum yet" is now wrong. Mullvad's hybrid is on by default and has been since 9 January 2025; NordVPN shipped Linux PQ NordLynx in 2025. The "harvest now, decrypt later" defense has a concrete answer: Mullvad on desktop.
Mullvad's design: client establishes vanilla WireGuard tunnel, runs ephemeral key exchange inside it using ML-KEM-768 + Classic McEliece, derived shared secret becomes WireGuard PSK for a new tunnel that replaces the first. PSK discarded at teardown -> forward secrecy against future quantum adversary. Source: github.com/mullvad/wgephemeralpeer.
| Tech | Role | DPI / probing resistance | Adoption |
|---|---|---|---|
| REALITY (XTLS, VLESS+Vision) | TLS handshake delegated to a real third-party site (microsoft.com, cloudflare.com, gateway.icloud.com). Active probers see the real site's cert and HTML. No custom cert, no fingerprint. | Highest active-probing resistance available 2025. Some Iran blocking via IP+SNI heuristics, not protocol detection. | Self-hosted only (Xray-core, sing-box, Hiddify). NO commercial VPN ships REALITY. |
| AmneziaWG 2.0 (AGPLv3, 2024-2025) | WireGuard fork: randomised junk packets pre-handshake (Jc/Jmin/Jmax), randomised header magic bytes (S1/S2/H1-H4), per-config random padding, dynamic header ranges, continuous cover-packet stream. | Currently the working WireGuard inside Russia. Vanilla WireGuard dead in Russia since TSPU rollout late 2024 / mid 2025. Holds under GFW so far. | Amnezia VPN self-host. Tailscale issue #13119 requesting pluggable obfuscation. No mainstream commercial adoption. |
| Shadowsocks 2022 / SIP022 | AEAD-2022 with BLAKE3 KDF, mandatory full replay protection, per-message type byte, per-session UDP IDs. EIH multi-user. | Strong active probing resistance (server silently drops bad packets). Still recognisable random-bytes flow without obfs4/Cloak wrapping. | Self-hosted (shadowsocks-rust, Xray, sing-box). Minimum acceptable Shadowsocks variant in 2025. |
| VLESS+Vision | Stateless redesign of VMess. No inner encryption, relies on outer TLS. Lighter and cleaner than VMess, which ML-DPI detects since 2020. | High when paired with REALITY. | Self-hosted (Xray-core). |
| Trojan | TLS mimicry, SHA-224 password auth | Now detected by TLS-in-TLS classification + inner-packet-size ML (mid-2025). Trojan-go deprecated. | Declining. Use VLESS+REALITY instead. |
| Hysteria 2 | QUIC + custom "Brutal" congestion control that ignores packet loss/RTT, sends at fixed declared rate | Survives Chinese ISP UDP throttling (which artificially drops packets). HTTP/3 mimicry. Real Let's Encrypt cert. | Self-hosted, sing-box. |
| TUIC v5 | QUIC 0-RTT, BBR-plus, Full Cone NAT for UDP relay | Similar to Hysteria. Faster handshake than TCP+TLS proxies. | Self-hosted, sing-box, Clash Meta. |
| Cloak | HTTPS multiplexer wrapping Shadowsocks/etc, uTLS Chrome/Firefox fingerprints, fake-website fallback for unauthenticated probes | Good probing resistance. | Self-hosted, common SS pair. |
| Mieru | XChaCha20-Poly1305, no TLS, random padding, replay detection | Hides as random bytes. Vulnerable if GFW tightens entropy classification. | Self-hosted, Chinese audience. |
| NaiveProxy | Extracts Chromium network stack (~4% of Chrome) for authentic Chrome TLS+H2 fingerprints. Tunnels HTTP/2 or H/3 CONNECT through Caddy with forwardproxy. | Excellent against TLS fingerprinting and traffic classification. The front server is real Caddy serving a real site. | Self-hosted. Uncommonly blocked by GFW. |
| WStunnel (Windscribe) | OpenVPN/WG inside a WebSocket over TLS, optional Cloudflare fronting | High - looks like a WebSocket upgrade. | Windscribe + self-host. |
| stunnel | Generic TLS wrapper around OpenVPN | Distinguishable by active probing and TLS-in-TLS timing. | AirVPN, Windscribe Stealth, others. |
| obfs4 / lyrebird | Tor PT, also generic SS/OpenVPN pre-wrapper. Curve25519 ntor handshake, AES-CTR-128 + HMAC-SHA256. | Per-session probing resistance high (shared secret). Public bridges enumerable. ~5% throughput loss. | Tor Browser, Snowflake fallback, Mullvad Bridges, Amnezia. |
| Protocol | Provider | Base | Notable |
|---|---|---|---|
| Lightway | ExpressVPN | DTLS 1.3 / wolfSSL, ChaCha20 or AES-256-GCM | Rewritten in Rust 2024, re-audited Cure53 + Praetorian, DTLS 1.3 upgrade shipped, Lightway Turbo multi-lane 2024. |
| NordLynx | NordVPN | Vanilla WireGuard + double-NAT layer | Solves WG persistent identity by giving every client the same local IP at interface 1, dynamic NAT at interface 2. Proprietary service layer. PQ rolling out Linux 2025. |
| Stealth | ProtonVPN | WireGuard inside outer TLS 1.3 over TCP 443 | Open-sourced clients, server side closed. Works in Iran and most of Russia 2025. Less probing-resistant than REALITY because TLS terminates locally. |
| Hydra (Catapult) | Hotspot Shield / Pango / Aura | Closed source, TLS 1.2 RSA-2048 + AES-128-GCM default | AnchorFree refused external audit historically. Below 2025 best practice. |
| Chameleon | VyprVPN | OpenVPN with scrambled headers, randomized sizes, dummy bytes | Eroded by ML-DPI; no longer reliable against GFW 2025. |
| Use case | Primary | Alternative | Reasoning |
|---|---|---|---|
| Maximum anonymity | Mullvad | IVPN | Numeric account, cash by post, raid-tested April 2023, default ML-KEM-768 PQ |
| Red team / opsec infrastructure | Mullvad | IVPN | Multi-account isolation, no email, default PQ, multihop, court-tested |
| Post-quantum threat model (harvest now, decrypt later) | Mullvad | NordVPN (Linux only, 2025) | Mullvad ships hybrid ML-KEM-768 + Classic McEliece by default since 2025.2 |
| Journalists / sources | ProtonVPN | Mullvad | Swiss, Secure Core multihop, free tier, but note 2021 ProtonMail incident |
| General privacy | IVPN | Mullvad | Best balance of features, port forwarding, transparency |
| Free / budget | ProtonVPN free | Windscribe free | Proton free has no data cap. Windscribe 10 GB/mo |
| Activist / at-risk | Riseup VPN | Calyx Institute VPN | Non-profit, donation-funded, NSL-handled, anonymous tokens |
| Torrenting with port fwd | AirVPN | OVPN.com / IVPN | Static port forwarding, SSH/SSL tunnels (Mullvad removed PF 2023) |
| Russia GFW evasion | Self-host AmneziaWG 2.0 | Hysteria 2, NaiveProxy | Vanilla WireGuard dead in Russia since mid-2025 TSPU. AWG 2.0 working replacement |
| China GFW evasion | Self-host REALITY (Xray-core / sing-box, VLESS+Vision+REALITY) | NaiveProxy, Hysteria 2 | REALITY delegates TLS to real third-party site; probers see Microsoft cert |
| Iran censorship circumvention | ProtonVPN Stealth | Hysteria 2 / NaiveProxy self-host | Stealth and Hysteria still mostly working in Iran 2025 |
| Court-proven no-logs needed | Mullvad | OVPN.com | Sweden 2023 raid + 2020 Patent and Market Court ruling |
| Mobile roaming priority | Mullvad (WG) | Anything IKEv2 with MOBIKE | WG handles rebinds; IKEv2 best for iOS native |
| Unlimited devices, mainstream | Surfshark | Windscribe | Both unlimited, but Surfshark = Nord Security, Windscribe = Canada |
| Cafe wifi only (low threat) | TunnelBear | Mozilla VPN | Audited, easy UX. Both fail serious threat models. |
Abstract patterns to watch for when evaluating ANY VPN. These are signals, not specific accusations. For named conglomerates and current-state ownership, see Ownership Consolidation Map.
| Pattern | Why it matters |
|---|---|
| Affiliate marketing as primary revenue | Listicle rankings driven by commission, not user trust. ~80% of consumer VPN review sites are affiliate-funded. |
| "Lifetime" subscriptions | Unsustainable cashflow model. Often precedes shutdown, sale, or quiet degradation. |
| Closed-source clients, no third-party code audit | No way to independently verify logging, encryption, or kill switch behaviour. |
| "No-logs audit" that actually only covers a mobile app | App audits are not infra audits. The provider conflated them deliberately. |
| Silent jurisdiction change | Provider moves entity from Switzerland to Texas without disclosure (see Avoid tier). The behaviour itself is the signal. |
| Ownership change without notification | Acquisition by a parent in a different jurisdiction or with adjacent business interests. |
| No warrant canary, or canary that "evolves" wording | Either never had legal pressure or is no longer in a position to deny it. |
| "Anonymized" metadata logging | Timestamps + bandwidth + connection duration = correlation attack input. There is no anonymization at this resolution. |
| Marketing/policy contradiction | The website says "zero logs", the privacy policy itemises retained metadata (KeepSolid pattern). Trust the policy. |
| Aggressive 90%+ discount marketing | Multi-year lock-in with inflated phantom monthly price. Business risk if provider degrades. |
| Free tier with no clear funding model | Either donation-funded (Riseup), cross-subsidized (ProtonVPN, Calyx), or you are the product (HotspotShield free). |
| No port forwarding AND no public reason | Some legitimate (Mullvad removed for abuse, documented). Most just lacking the engineering. |
| Owns or is owned by review sites | Direct conflict of interest. Kape/Webselenese is the canonical case. |
Concrete current state of the consumer VPN industry. For abstract evaluation patterns see Red Flags.
| Parent | VPNs Owned | Review Sites Owned | Key Personnel |
|---|---|---|---|
| Kape Technologies | ExpressVPN, CyberGhost, PIA, ZenMate | vpnMentor, Wizcase | Koby Menachemi (Unit 8200), Teddy Sagi (1996 bribery conviction) |
| Nord Security | NordVPN, Surfshark, Atlas VPN (dead Apr 2024) | - | Okmanas + Sabaliauskas (Tesonet) |
| Gen Digital | HMA, Avast SecureLine, Norton VPN, AVG VPN | - | Jumpshot data-selling scandal 2019-2020 |
| Ziff Davis | IPVanish, StrongVPN, Encrypt.me | - | IPVanish 2016 logging lie |
| Aura | HotspotShield, Betternet, Ultra VPN, VPN360 | - | 2017 FTC complaint (CDT + Carnegie Mellon) |
| McAfee | TunnelBear | - | Canada + US = double 5 Eyes |
| Certida LLC (Texas) | VyprVPN | - | Silent move from Switzerland 2023 |
| Parent | Product | Notes |
|---|---|---|
| Proton AG (Geneva, Foundation majority since 2024) | ProtonVPN, ProtonMail, ProtonDrive, ProtonCalendar | Non-profit governance. Independent. |
| Mullvad VPN AB / Amagicom AB (Gothenburg) | Mullvad VPN | Founders Stromberg + Berntsson 2009. No investors. |
| IVPN Limited (Gibraltar) | IVPN | 100% Nick Pestell. Refuses affiliates since 2019. |
| OVPN Integritet AB (Stockholm) | OVPN.com | David Wibergh. Court-proven 2020. |
The empirical backbone of every "no-logs" trust claim is the handful of cases below. Marketing copy is not evidence; legal compulsion under court order is.
| Date | Provider | Case | Result |
|---|---|---|---|
| Sept 2011 | HMA | LulzSec / Cody Kretsinger (Sony Pictures). UK court order on FBI request. | LOGS HANDED OVER. Connection logs identified him. Convicted. |
| May 2016 | IPVanish | Homeland Security summons (child exploitation). Highwinds ownership. | LOGS HANDED OVER despite "no-logs" marketing. Brand permanently tainted. |
| Date | Provider | Case | Result |
|---|---|---|---|
| June 2021 | Windscribe | Ukraine server seizure. | Keys NOT encrypted. Deprecated cipher config on disk. Potential MITM. Fixed to RAM by July 2021. |
| Date | Provider | Case | Result |
|---|---|---|---|
| 2020 | OVPN.com | Swedish Patent and Market Court. Rights Alliance tried to force IP disclosure. | Court examined architecture, accepted no-logs. Studios ordered to pay 108k SEK. Strongest judicial ruling in VPN history. |
| Apr 2023 | Mullvad | Swedish NOA raid (6 officers, Gothenburg, German warrant). | Left empty-handed. No data to seize. Strongest operational test. |
| 2016 | PIA (pre-Kape) | Russia encryption ban server seizure. | No data recovered. PIA withdrew from Russia. |
| Mar 2016 | PIA (pre-Kape) | FBI bomb-threat subpoena (Preston McWaters). | Returned only "east coast cluster" granularity. |
| 2018 | PIA (pre-Kape) | FBI hacking investigation. General counsel testified under oath. | Court accepted no-logs claim. Strongest US proof. (Pre-Kape.) |
| Dec 2016 | ExpressVPN | Turkey Karlov assassination investigation. Server seized. | Forensic exam found no logs. (Pre-Kape.) |
| Aug 2016 | Perfect Privacy | Netherlands (Rotterdam I3D). 2 servers seized. | Provider says no data. No court ruling tested the claim. Weakest evidence. |
| Oct 2024 | NordVPN | Panama. First public compelled-process. | Payment data + account existence only. No traffic logs (none exist). |
| Date | Provider | Case | Result |
|---|---|---|---|
| Sept 2021 | ProtonMail (mail, not VPN) | Swiss DOJ order via Europol from French authorities. Climate activist. | Proton logged and disclosed IP. ProtonVPN legally distinct, untested. |