Read this first
If you want to watch a film that is not shown in your country, any of these will do and you can stop reading. Just do not count on Netflix, which checks for VPNs now.
If your aim is privacy, and especially privacy from a government, this page matters to you. An advert is a poor guide, and trusting one can end in a knock on the door, or worse. Read it carefully and be sure you understand what is at stake.
Disclosure
I use ExpressVPN. It is the tool I use myself, and it is scored here like the other eight, with its owner's links counted against it like anyone else's. This is not a paid advert. Nobody sponsored this page. There are no affiliate links, referral codes, advertising revenue, commissions or commercial arrangements with any VPN named here.
Every VPN name linked on this page goes directly to the provider's public website. The links contain no affiliate or referral tracking. No special price, discount, free period or other deal is being offered through this page, and none should be expected. Following a link earns this site nothing.
I wrote it because I am tired of creators on YouTube and other platforms selling low quality, and sometimes dangerous, security products that are not fit for purpose. In my view many of them check nothing beyond what the sponsor pays for the slot.
This is not a VPN review site. It is a bullshit filter: a barebones comparison designed to strip away the sales pitch and put all nine providers against the same evidence. I am not scoring app design, streaming performance, brand reputation or marketing polish. I am pulling back the curtain on what matters if privacy is the reason you are using a VPN: server design, independent audits, real-world seizure or court tests, jurisdiction, ownership and intelligence-sharing exposure. The aim is not to sell you a winner. It is to show the balance of strengths and weaknesses once the advertising is removed.
Why the advert tells you nothing useful
An advert is bought. The company pays, the presenter reads the script, and the script is written to sell. It will say encryption and no logs. It will not say where the company is registered, who owns it, or which country's courts can order it to act. Those three facts decide whether a knock on the door is possible.
Ownership is the first thing hidden. Kape Technologies, formerly Crossrider, a company linked to adware distribution, owns ExpressVPN, CyberGhost and Private Internet Access. Its media arm has also run VPN review sites such as vpnMentor and Safety Detectives. Three of the nine providers in this article share one owner, and that owner has run sites that rank them.
No logs is a claim, and claims fail when they are tested. Court documents reported in 2016 showed IPVanish giving US Homeland Security a customer's name, email address, IP address and connection logs, after first saying it had no data. In 2017 the FBI used records from PureVPN in a cyberstalking case, when its policy said it kept no logs that could identify a user's activity. In May 2026 French and Dutch police seized 33 servers in 27 countries belonging to a service called 1VPNS, which advertised no logs, and reportedly identified 506 users.
The same test has gone the other way. A server seized from ExpressVPN in Turkey in 2017 reportedly gave nothing usable. Swedish police raided Mullvad in 2023 and left empty handed. PIA says it was subpoenaed for logs in 2016 and 2017 and had none. A Greek court dismissed charges against Windscribe's founder in 2025.
Surfshark shows the middle ground. In April 2026 it says it complied with a legally binding warrant from the Amsterdam District Court. It could not provide browsing history, traffic or IP logs because it says it does not keep them, but it did confirm the account existed and handed over payment-related information that it still held. No activity logs does not mean no identifying data exists anywhere in the company.
What separates the providers is not the advert. It is what the company stores, what can identify an account, and who can order it to store or disclose more.
Providers that refuse paid endorsements.
IVPN and Mullvad both publicly distance themselves from the paid-endorsement model commonly used to promote VPN services.
IVPN says it closed its affiliate programme in protest at paid reviews and misleading recommendations by “best VPN” websites. That wording does not establish whether those recommendations were favourable or unfavourable to IVPN, only that IVPN regarded the practice as misleading. It says it does not buy endorsements, on the view that influencers and YouTube creators without relevant information-security expertise should not recommend VPN services in exchange for payment. This is exactly why this page exists, because I also subscribe to that same philosophy. IVPN also says it rejects surveillance advertising, countdown timers, expiring deals and fake reviews.
Mullvad takes a similar position. It says it has no affiliate programme and does not pay reviewers or influencers to recommend its service. It does buy conventional advertising, including on YouTube, search engines and app stores, but distinguishes paid advertising from paying a reviewer or influencer for an endorsement.
For coverage, IVPN says it provides journalists and reviewers with demo accounts without compensation and may financially support creators it considers qualified to evaluate privacy and security technology. Mullvad says it does not pay for reviews or influencer endorsements. These are the providers’ own stated policies. Marketing practice is not included in the scoring system used in this article.
For coverage, IVPN says it gives journalists and reviewers demo accounts with no compensation, and that it financially supports creators it judges to have the background to evaluate VPNs. Those are IVPN's own statements of policy. The scores in this article do not count marketing practice.
What providers say on their own sites about paid promotion
| Provider | Position stated on its own site |
|---|---|
| IVPN | Says it closed its affiliate programme, does not buy endorsements, and avoids countdown timers and expiring deals. |
| Mullvad | Says it has no affiliates and pays for no reviews or influencers. It does buy adverts, including on YouTube, search engines and app stores. |
| ExpressVPN | Lists Affiliates and Influencers programmes in its site footer. |
| NordVPN | Says it partners with creators and influencers who share codes with their audiences, and names several well-known ones. |
| Surfshark | Lists Affiliate, YouTube creators and Referral programmes in its site footer. |
| CyberGhost | Lists Affiliates and Refer a friend programmes in its site footer. Its pricing page carries an "offer ends" banner. |
Only providers whose own pages state a position are listed here. These are statements of policy, not independent audits of what any provider pays.
The point is not that advertising automatically makes a VPN unsafe, or that refusing affiliate marketing automatically makes one secure. It is that paid endorsements introduce a financial incentive that has nothing to do with whether the service will actually protect a user when legal pressure arrives. A presenter can be paid to repeat “military-grade encryption”, “no logs” and “complete privacy” without examining the operator, jurisdiction, ownership, logging architecture, audit history or what happens when a government comes knocking.
That is why marketing practice is kept separate from the scores in this article. It is useful context, but the security assessment rests on technical design, independent evidence and legal exposure, not on who has the slickest advert or the largest sponsorship budget.
What you are actually buying
At its simplest a VPN is a relay. Websites see the VPN company's address instead of yours, and your internet provider sees an encrypted connection to the VPN instead of the sites you visit. That is relocation. It moves where you appear to be, and it moves who can see your traffic, from your internet provider to the VPN company.
For watching something from another country's catalogue, that is all you need. It is not, on its own, protection of your identity. Whether the company that now sees your traffic can be made to hand it over, or to start recording it, depends on the five things scored below. It does not depend on the price or on the advert.
Five, Nine and Fourteen Eyes
The Five Eyes is an intelligence-sharing arrangement between five countries. Four more join to make the Nine Eyes, and five more make the Fourteen Eyes. Membership does not force a VPN company to log anything. It does mean the agencies share what they collect, and a company based in a member state answers to that state's law.
Five Eyes
- United States
- United Kingdom
- Canada
- Australia
- New Zealand
Nine Eyes
The five above, plus:
- Denmark
- France
- Netherlands
- Norway
Fourteen Eyes
The nine above, plus:
- Germany
- Belgium
- Italy
- Spain
- Sweden
So a VPN based in one of these countries is not automatically unsafe, but it can be ordered to act by a government that has partners. That is what the jurisdiction score measures.
Two kinds of government request
Requests about the past
A subpoena, a warrant, a raid or a formal request from a foreign police force asks for what a company already holds. The defence is engineering: nothing stored, so nothing to hand over.
RAM-only servers are the strongest form of it. Memory only holds live connections, and it is wiped when the server is powered off or rebooted. ExpressVPN says its servers wipe on every reboot, and one review reports they reboot every one to two weeks. Memory freed when a session ends is reused by new connections, so on a busy server old sessions get overwritten.
To get anything out of one, investigators would have to seize it while it is switched on, keep it running, capture the memory intact and preserve it as evidence. Even then it would show only the connections live at that moment, not anyone's history.
There is also time. A request from abroad has to go through a formal process in the provider's own country. For a British Virgin Islands operator, that means a written request to the islands' Attorney General. It takes time, and by the time it lands, past sessions have gone from memory.
Orders about the future
A different order asks a company to record from now on. RAM does not help, because the server can write down what happens next. Only the law of the country the company sits in decides whether that can be forced.
The United States has court orders that make a communications provider install and monitor a pen register for up to 60 days. A pen register collects metadata, not content, and the order can be sealed so the provider cannot tell the user. In the Netherlands, the intelligence services can order communication providers to help with live interception, and refusing is a criminal offence.
This is why jurisdiction gets its own scores. Engineering covers the past. Jurisdiction covers the future.
How the scores work
Every VPN here is marked on five things. Each has a fixed rule, so the same facts always give the same score. In every column, high is good and low is bad.
RAM-only servers, 3 points
It carries the most weight because it protects you against past requests whatever the law says. All servers RAM-only scores 3. Disks with full-disk encryption scores 1. Plain disks score 0.
Independent audits, 2 points
A named firm auditing the no-logs claim or the servers earns 1. A repeat audit adds 0.5, and so does a latest audit under 24 months old. An audit is a snapshot, which is why repeats and recent dates count. None published scores 0.
Seizure or court test, 1 point
A claim is worth more when it has been tested. A court case or subpoena on record where nothing usable was found earns 0.5. A seizure or raid confirmed by someone other than the company earns another 0.5. None found scores 0.
Operator's jurisdiction, 2 points
Where the company that runs the service sits. Outside the fourteen scores 2. Fourteen Eyes only scores 1. Nine Eyes scores 0.5. Five Eyes scores 0.
Intel protection, 2 points
Counts the links pulling a provider towards an intelligence-sharing state. A link is a parent or holding company in a Five, Nine or Fourteen Eyes state, or a move or pending law that pulls the company or its servers into one. It only counts if it adds a state beyond the operator's own. No links scores 2, and each link costs a point, so two or more scores 0.
Two worked examples
Mullvad. All servers RAM-only (3). Repeated qualifying infrastructure audits, but the latest was completed in June 2024 and is now over 24 months old (1.5). A raid by Swedish police that found nothing (0.5). Operator in Sweden, in the Fourteen Eyes only (1). No links beyond Sweden (2). Total 8.0.
PIA. All servers RAM-only (3). Audited (2). Subpoenas that PIA says found nothing (0.5). Operator in the USA (0). One link, because Kape adds the UK (1). Total 6.5.
Both run RAM-only servers and both have a record under pressure. The 1.5-point gap comes from the audit recency rule, where the operator sits and who else has a hand on it.
The scores
Jurisdiction cells are shaded to match the rings at the top: teal is outside the alliances, sand is the Fourteen Eyes, orange is the Nine Eyes, and red is the Five Eyes.
| Metric | Pts | High (good) | Low (bad) |
|---|---|---|---|
| RAM-only servers | 3 | All RAM-only: 3. Disks with full-disk encryption: 1 | Plain disks: 0 |
| Independent audits | 2 | Named firm 1, repeat +0.5, latest under 24 months +0.5 | None: 0 |
| Seizure or court test | 1 | Court case or subpoena, nothing found +0.5. Confirmed seizure or raid +0.5 | None found: 0 |
| Operator's jurisdiction | 2 | Outside the fourteen: 2. Fourteen Eyes: 1. Nine Eyes: 0.5 | Five Eyes: 0 |
| Intel protection | 2 | No links: 2. Each link costs a point | Two or more links: 0 |
| VPN | RAM /3 | Audit /2 | Test /1 | Jurisdiction /2 | Intel /2 | Total /10 | Verdict |
|---|---|---|---|---|---|---|---|
| ExpressVPN | 3 | 2 | 0.5 | 2 British Virgin Islands |
1 | 8.5 | Strong |
| Mullvad | 3 | 1.5 | 0.5 | 1 Sweden |
2 | 8.0 | Strong |
| CyberGhost | 3 | 2 | 0 | 2 Romania |
1 | 8.0 | Strong |
| Surfshark | 3 | 2 | 0 | 0.5 Netherlands |
2 | 7.5 | Acceptable |
| IVPN | 1 | 1.5 | 0 | 2 Gibraltar |
2 | 6.5 | Acceptable |
| NordVPN | 3 | 2 | 0 | 0.5 Netherlands (registered in Panama) |
1 | 6.5 | Acceptable |
| PIA | 3 | 2 | 0.5 | 0 USA |
1 | 6.5 | Acceptable |
| Windscribe | 3 | 1 | 0.5 | 0 Canada |
2 | 6.5 | Acceptable |
| ProtonVPN | 1 | 2 | 0 | 2 Switzerland |
1 | 6.0 | Weak |
How to read the scores: in every column, high is good and low is bad. The total is the five score columns added together. Verdicts: 8 to 10 strong, 6.5 to 7.9 acceptable, below 6.5 weak.
Jurisdiction: Gibraltar, the British Virgin Islands, Romania and Switzerland are outside the Five, Nine and Fourteen Eyes (2). Sweden is in the Fourteen Eyes only (1). The Netherlands is in the Nine Eyes (0.5). The USA and Canada are Five Eyes founders (0).
The links behind the intel scores
- ExpressVPN, CyberGhost: Kape, with a London headquarters, adds the UK (1 link).
- PIA: Kape adds the UK on top of the US (1 link).
- NordVPN: its UK-registered holding company, Nordsec Ltd, adds the UK on top of the Netherlands (1 link).
- ProtonVPN: the pending Swiss logging rule could push it towards Germany or Norway, where it is already building servers (1 link).
- IVPN, Mullvad, Surfshark, Windscribe: no links beyond the operator's own state (0 links).
A link is a parent or holding company in a Five, Nine or Fourteen Eyes state, or a move or pending law that pulls the company or its servers into one. It only counts if it adds a state beyond the operator's own.
Provider by provider: what the exposure really is
IVPN, 6.5, Gibraltar
IVPN uses LUKS full-disk encryption across its main gateway network, with only a small RAM-only pilot, so under this page's fixed rule it scores 1 of 3 for RAM-only servers. Cure53 audited its VPN gateway infrastructure in 2023. IVPN has published newer audits of other parts of its service, but the latest qualifying gateway or no-logs audit is now over 24 months old, so the audit score is 1.5 rather than 2. No email is needed to sign up. You can pay by card, PayPal, Bitcoin, Bitcoin Lightning, Monero or cash. Cash is only taken on plans of one to three years and is not refundable. Gibraltar is a British Overseas Territory with its own legal system, and foreign requests go through its own process. It scores 0 on the seizure test only because no public case was found, which is a gap in the record, not a failing.
One incident to know about. In August 2026 IVPN disclosed that an attacker exploiting a flaw in BTCPay Server, the software it hosts to take Bitcoin payments, extracted its Lightning node credentials and moved out its operating funds. IVPN says no customer data or customer funds were affected, its VPN infrastructure was not involved, and Lightning payments were down from 7 to 10 August. The scoring rules have no line for incidents, so it does not change the score.
Its privacy policy lists what it keeps. At sign-up: an account ID, the creation date, the plan and the device limit. For each payment: the amount, currency, timestamp and a transaction ID linked to the account. While you are connected: a temporary record that the account is logged in, deleted when the session ends. Accounts and their linked data are deleted 90 days after they end, and payment records are kept without a link to any account.
IVPN says it will comply with a court order from an authority with jurisdiction over it, but cannot hand over what it does not hold. If it were ever forced to keep connection logs, it says it would try to tell customers and then move jurisdiction or close. It says it operates 58 locations in 41 countries, and that its ownership, company structure and team are public.
It also says it uses no advertising or social trackers and no third-party analytics. Its privacy policy discloses one thing to know: a self-hosted Matomo script that records browser details and an IP address with the last two octets dropped.
ExpressVPN, 8.5, British Virgin Islands
RAM-only, and audited by PwC, KPMG and Cure53. A server seized in Turkey in 2017 reportedly gave nothing usable. The exposure is Kape, which owns it and is listed with a London headquarters. UK orders can only be served on people in London, and it matters only if they can reach ExpressVPN's systems. No evidence was found that they can. Kape's owner is reported to live in Cyprus and holds it through an Isle of Man company.
Mullvad, 8.0, Sweden
RAM-only, with an account that is just a random number and no email, and cash accepted. Mullvad has repeated infrastructure audits, including a fourth infrastructure audit by Cure53 completed in June 2024. That qualifies for the named-firm and repeat points, but it is now more than 24 months old, so the audit score is 1.5 rather than 2. Newer audits have covered its apps and web systems, not the VPN infrastructure measured by this scoring rule. In April 2023 Swedish police raided its Gothenburg office at the request of a German investigation and left with nothing. The exposure is simple: it is a Swedish company, Sweden is in the Fourteen Eyes, so Swedish orders can be served on it directly.
CyberGhost, 8.0, Romania
RAM-only, with three Deloitte Romania audits: 2022, 2024 and a third announced in February 2026. The operator is Romanian, outside the fourteen. The exposure is the same as ExpressVPN's: Kape has owned it since 2017, and its London headquarters adds the UK.
Surfshark, 7.5, Netherlands
RAM-only, with Deloitte no-logs assurance reports in 2023 and 2025, so it now receives the full 2 audit points. It moved from the British Virgin Islands to the Netherlands in October 2021, and customers who signed up since then contract with Surfshark B.V. Dutch intelligence law lets the services order communication providers to help with live interception, and refusing is a criminal offence. Those orders can be served on it directly. In April 2026 Surfshark says it complied with a legally binding warrant from the Amsterdam District Court: it had no browsing, traffic or IP logs to provide, but it did disclose confirmation that the account existed and payment-related information. Under this page's fixed seizure or court rule, that does not earn the 0.5 point for "nothing found". It has shared a group with NordVPN since 2022.
NordVPN, 6.5, Netherlands (registered in Panama)
RAM-only, with Deloitte and PwC audits reported. The operating company, nordvpn S.A., is registered in Panama, and Nord says Panama has no mandatory data retention law. But the company is listed in a credit database with an establishment in Amsterdam, and the group holdings sit in the Netherlands and in a UK-registered company, Nordsec Ltd. The founders and Nordsec's director live in Lithuania. It is scored at the Dutch tier, and its one link is the UK holding company.
PIA, 6.5, USA
RAM-only according to its own transparency report, with Deloitte audits reported for 2022, 2024 and 2025. PIA says it was subpoenaed for logs in 2016 and 2017 and had none. The exposure is where it sits. It is a US company, and US law provides sealed monitoring orders that run forward. It is also owned by Kape.
Windscribe, 6.5, Canada
RAM-only, after it rebuilt its network following a 2021 incident. A Greek court dismissed charges against its founder in 2025. Windscribe says Dutch authorities seized a server and found only a stock install, but only the company has confirmed that, so it counts for half a point. Its infrastructure was audited by PacketLabs in 2024, but reviews report no published independent audit of its no-logs policy. It is a Canadian company, and Canada is in the Five Eyes.
ProtonVPN, 6.0, Switzerland
The best jurisdiction on paper: Switzerland is outside every alliance, and its law does not force VPN providers to log today. Four annual Securitum audits are reported for 2022 to 2025. But Proton says it uses hard disks with full-disk encryption instead of RAM-only servers, so it scores 1 of 3 there. And its jurisdiction is under threat, as the Swiss section below explains. Its total is the lowest here.
What they cost, and what the discounts really mean
Prices are US dollar prices taken from each provider's own site in late September 2026, and the scores are the locked ones from the table above. Where a cell names another source, that figure is not stated on the provider's own page. UK prices differ and include VAT, and offers change week to week, so check the provider's own page before you pay.
| VPN | Score /10 | One month | Advertised long-term deal | Renewal |
|---|---|---|---|---|
| ExpressVPN | 8.5 | Not shown. Its crossed-out list price works out at $14.99 | Basic $2.99 a month: $83.72 for 2 years plus 4 months. Advanced $4.49, Express Pro $7.49. | Basic $99.95 a year, about $8.33 a month. Advanced $119.95, Express Pro $199.95 a year |
| Mullvad | 8.0 | €5 | None. A flat €5 a month, with no discounts. | Same, €5 a month |
| CyberGhost | 8.0 | $12.99 | $2.19 a month: $56.94 for 2 years plus 2 months. Six months $6.99 a month. | $56.94 a year, about $4.75 a month |
| Surfshark | 7.5 | $16.45 (Starter) | Starter $2.49 a month on the 24-month plan. One $2.79, One+ $4.49. | Not stated on the plans page. Reviews report $79 a year for Starter |
| IVPN | 6.5 | $6 | Standard $60 a year, about $5 a month. Plus $80 and Pro Suite $100 a year. No free months. | Not stated on the pricing page |
| NordVPN | 6.5 | $14.99 (Basic) | Basic $3.49 a month: $94.23 for 2 years plus 3 months. Complete $4.49, Prime $7.49. | Basic $139.08 a year, about $11.59 a month |
| PIA | 6.5 | $11.95 | $2.03 a month for 3 years plus 3 months. One year $3.99 a month. | $79 every 3 years, about $2.19 a month. The one-year plan renews at $47.88 |
| Windscribe | 6.5 | $9 | Pro $69 a year, about $5.75 a month. Build-a-Plan from $3 a month. Free plan with 2 to 10GB a month. | Same, per Windscribe |
| ProtonVPN | 6.0 | $9.99 (Plus) | Plus $2.99 a month: $71.76 for 24 months. One year $3.99 a month. Free plan on one device. | $83.88 a year, about $6.99 a month, per a review site quoting Proton's terms |
| Plan | Includes | Devices | 1 week | 1 month | 1 year |
|---|---|---|---|---|---|
| Standard | Core VPN service with multi-hop, obfuscation protocols and a SOCKS5 proxy, plus AntiTracker | 5 | $2 | $6 | $60 |
| Plus | Standard, plus added DNS and email privacy: modDNS and Mailx | 5 | $3 | $8 | $80 |
| Pro Suite | Plus, and Portmaster Pro (Linux, Windows), a firewall and network monitor operated by IVPN | 10 | $4 | $10 | $100 |
IVPN needs no email to sign up and gives a 30-day refund window. You can pay by card, PayPal, Bitcoin, Bitcoin Lightning, Monero or cash. Cash is only taken on plans of one to three years and is not refundable. Its server page says it runs 89 bare-metal gateways in 58 locations across 41 countries.
How a free month works
Free months come on top of the paid term, and the advertised monthly price is the total bill divided by every month, free ones included. NordVPN's Basic bill of $94.23 is $3.49 a month over 27 months. CyberGhost's $56.94 is $2.19 a month over 26 months. ExpressVPN's Basic bill of $83.72 is $2.99 a month over 28 months. The multi-year prepayment is the sale, and the renewal is the price.
ExpressVPN's Basic renews at about $8.33 a month. NordVPN's Basic renews at about $11.59, and CyberGhost's at about $4.75. PIA is the exception among the big discounters: its 3-year plan renews at $79 every 3 years, about $2.19 a month. Mullvad does not discount at all, and Windscribe says its price stays the same on renewal.
Cheap is not the tell
It would be neat to say the cheapest are the weakest. The scores say otherwise. PIA has the lowest advertised price in the table and scores Acceptable. CyberGhost is next and scores Strong. ExpressVPN advertises the most free months, four, and also scores Strong. Windscribe has one of the higher advertised monthly prices and scores Acceptable. Across these nine, the advertised price and the score are barely related, so a big discount is not a warning sign and a high price is not a guarantee.
What the price can tell you is different. Mullvad and IVPN sell at one flat rate with no free months and no multi-year promotion. And one review site's price index says it plainly: price reflects marketing and promotions as much as quality.
Where cheap does get dangerous
Free and lifetime offers. One review site's summary of the market says most free VPNs cap your data, inject adverts or collect and sell your browsing data to pay for themselves, and that lifetime deals often compromise on security. When the product is free, the company is paid somewhere else.
What the low price is paying for
On a good provider, a low price pays for scale and a long lock-in. On a bad one it pays for nothing you can see. The advert cannot tell you which, because the five things that matter are not on the price page. The headline is the number that sells, and the renewal sits in the terms. Ask what year three costs, then ask the five questions.
EU GDPR: what it does and what it does not
GDPR is the EU's data protection law and has applied since 25 May 2018. It covers how companies handle the personal data of people in the EU. It reaches beyond the EU: a company anywhere that offers services to people in the EU, or monitors their behaviour, has to follow it and must appoint a representative in the EU. Fines can reach 20 million euros or 4 percent of annual worldwide turnover, whichever is higher.
For a VPN user that means rights over your own data, such as access and erasure, and a duty on the company to collect no more than it needs. Sweden, the Netherlands and Romania are EU states, so it applies directly to Mullvad, Surfshark and CyberGhost. It also reaches providers outside the EU that sell to people in it.
What it does not do is stop a government. Processing for national security sits outside EU law, and police use of personal data is covered by a separate law, the Law Enforcement Directive. GDPR governs how a company treats you. It does not switch off an intelligence agency's own powers, and it does not stop the Dutch interception orders described above.
The UK left the EU and now has its own version, the UK GDPR, built on the same rules.
What Switzerland is doing
Switzerland is outside the EU and all the eyes, and for years that made it the default answer for privacy. Its current law does not force VPN providers to log. That is now under threat.
The Swiss government has proposed rewriting the ordinance on surveillance of post and telecoms traffic, known by its German initials VÜPF. The draft would apply to VPN, email and messaging providers with as few as 5,000 users. They would have to identify customers with a government document, keep IP addresses and connection data for six months, and be able to decrypt what they have encrypted. It is an ordinance issued by the government, not a law passed by parliament.
The first consultation closed on 6 May 2025 with a near-uniformly hostile response. In February 2026 the justice department said it had commissioned an external risk impact assessment and would prepare a second consultation. As of June 2026 there was no binding timetable, and the Federal Council had not said the project was dead. A paused law is not a buried one.
Proton, the best known Swiss provider, froze new Swiss data-centre spending and put the servers for its new AI assistant in Germany, with facilities also being built in Norway. It says its headquarters, legal entity and core Mail and VPN infrastructure stay in Geneva. Its chief executive has said the company would leave if the amendment passes.
That leaves ProtonVPN exposed either way. If the rule passes and Proton stays, it has to log. If it leaves, the places it is already building servers, Germany and Norway, are inside the alliances, and the company and its data would still sit under alliance-state law. That is why it scores 1 point on intel protection, and why having no RAM-only servers matters.
What to do with this
Read the advert as what it is: a paid script. Then ask the same five questions of any VPN, the ones in the table. Does it run RAM-only servers? Has a named firm audited it, recently and more than once? Has its no-logs claim been tested by a seizure or a court? Which country is the operator in? Who else, in which country, owns it or can pull it?
Then look at what it costs in year three, not year one. The deal in the advert is the introductory price.
No provider scores 10, and every one loses points somewhere. Nobody here is out of reach of every possible order, so pick on evidence, not on the advert.
About these ratings: the method is this site's own. It is based on public sources and company statements, checked on 28 September 2026. Companies change owners, servers and laws, so check current details before you rely on any of this. This page is information, not legal advice.
Sources
- Kape Technologies and its brands: Wikipedia
- IPVanish and PureVPN cases: IAPP, PCWorld
- 1VPNS takedown: Tom's Hardware
- ExpressVPN Turkey statement: ExpressVPN; trust centre: ExpressVPN
- Mullvad raid: TechRadar
- Windscribe Dutch seizure: TechRadar
- PIA transparency report: Private Internet Access
- US pen register and gag orders: Wikipedia, Electronic Communications Privacy Act
- Dutch provider duty to cooperate: AIVD
- BVI request route: Government of the Virgin Islands
- NordVPN holding company in the UK: Companies House, Nordsec Ltd
- GDPR territorial scope: IAPP; law enforcement and national security: CNIL
- Swiss VÜPF proposal: Tuta, Opsec Insider, heise online
- Prices and claims, from each provider's own site: IVPN pricing and IVPN servers, ExpressVPN pricing and TrustedServer, Mullvad terms and Mullvad policy on reviews and affiliates, CyberGhost pricing, Surfshark plans, NordVPN pricing and NordVPN cost guide, PIA pricing, Windscribe pricing, Proton VPN pricing
- Other price sources: Coppers VPN pricing index, HighSpeedInternet on Proton's renewal terms
- Free and lifetime VPNs: TheBestVPN
- Changed audit evidence: IVPN 2023 gateway infrastructure audit, Mullvad audit record, Surfshark 2025 Deloitte no-logs assurance
- Surfshark April 2026 warrant disclosure: Surfshark transparency report
- IVPN in its own words: ethical guidelines, privacy policy
- IVPN payments and the August 2026 incident: IVPN pricing, IVPN cash payments, IVPN blog
- Proton on RAM-only servers: Proton VPN