Skip to content
TopRatedVPN
Find VPN
Privacy

Are VPNs safe?

Author
By Amelia Ame
Last checked
Updated September 10, 2026
Reading time
5 min read
Privacy · tested September 2026
Are VPNs safe?5 min read · 42 VPNs tested

The technology is settled; the provider is the variable. Four things you can actually check, and why a police raid beats any audit.

  • Read every provider's actual audit report rather than its marketing page
  • Recorded audit dates, auditors and whether the inspection covered running servers or only policy
  • Ran DNS, IPv6 and WebRTC leak tests on all ten across four platforms
Independently audited Tested
10of 10 we rate

Of the roughly 42 we tested, most could not show one. That is the filter.

6 of 10 also run RAM-only servers, which cannot retain data across a reboot
Audited 2024+
9 of 10
Outside 14-Eyes
6 of 10
Tested in court
2 of 10

Audit dates and jurisdictions read from each provider's published reports

The short answer

The technology is safe — modern VPN encryption is the same class your bank uses and is not the weak point. The question that matters is whether the provider is, because a VPN moves your browsing record from your ISP to them. Check for an independent audit of the running servers, RAM-only infrastructure and a jurisdiction without retention laws.

"Are VPNs safe" is two questions wearing one coat, and they have different answers.

Is the technology safe? Yes, settled, not really debated. Is the company safe? That depends entirely on the company, and it is the question worth your attention.

The technology: settled

WireGuard and OpenVPN are both open-source, both heavily reviewed, and both use encryption that no one is realistically breaking. AES-256 and ChaCha20 are the same primitives protecting your bank's website. "Military-grade encryption" in VPN marketing means AES-256, which is accurate and is also what HTTPS has been using for years.

The one protocol to avoid is PPTP, cryptographically broken for over a decade and still offered by the built-in Windows VPN client and old router firmware. No provider we rate defaults to it. If one only offers PPTP, that tells you what you need to know about the provider.

So the encryption is not where this goes wrong. What goes wrong is implementation and trust.

The real question: is the provider safe?

Here is the thing most VPN pages skate past.

Without a VPN, your internet provider can see every domain you connect to. In some countries it is legally required to retain that; in the US it has been permitted to sell it since 2017.

With a VPN, your ISP sees an encrypted tunnel — and the VPN provider is now the party in a position to see the destinations.

That is still an improvement, for a specific reason: an ISP's business does not depend on discretion, and a VPN provider's entirely does. But it is a transfer of trust, not an erasure of the record, and any page that describes a VPN as making your browsing "disappear" is misleading you about the mechanics.

Which makes "does this provider actually keep nothing?" the whole question.

The four things that answer it

1. An independent audit — of the servers, not the policy

Anyone can write "no logs" on a homepage. What matters is whether an outside firm has inspected the running infrastructure and published what it found.

Check three details: who audited it (Deloitte, KPMG, Securitum, Assured and Cure53 are the names that recur), when — anything older than two years describes a system that may no longer exist — and what was inspected. A review of a privacy policy document is not the same as an inspection of live servers.

2. RAM-only servers

A server running entirely from memory cannot retain data across a reboot. Seize it, and there is nothing on it.

This is the difference between a no-logs policy that is a matter of configuration and one that is a matter of physics. Six of the ten VPNs we rate run RAM-only.

3. Jurisdiction

Where the provider is incorporated — not where the server is. That does not change when you click a different flag in the app.

Switzerland, Panama, the British Virgin Islands and Romania come up repeatedly because none mandates data retention for VPNs. The Fourteen Eyes countries — including the US, UK and Canada — are a worse starting point, though not disqualifying: Private Internet Access is US-based and has produced nothing in response to subpoenas more than once, which is stronger evidence than a good address.

4. Clean leaks and a working kill switch

The best privacy policy in the world is irrelevant if your DNS lookups go to your ISP anyway. This is implementation rather than trust, and it is testable in about two minutes — the checking guide has the routine.

How the ten we rate compare

VPNLast auditBased inRAM-only serversKill switch
Mullvad logoMullvadAssured, 2024SwedenYesYes
Proton VPN logoProton VPNSecuritum, 2024SwitzerlandNoYes
NordVPN logoNordVPNDeloitte, 2024PanamaYesYes
Surfshark logoSurfsharkDeloitte, 2025NetherlandsYesYes
ExpressVPN logoExpressVPNKPMG, 2024British Virgin IslandsYesYes
Private Internet Access logoPIADeloitte, 2024United StatesYesYes
PureVPN logoPureVPNKPMG, always-onBritish Virgin IslandsNoYes
CyberGhost logoCyberGhostDeloitte, 2024RomaniaYesYes
Windscribe logoWindscribePacketlabs, 2024CanadaNoYes
IPVanish logoIPVanishLeviathan, 2022United StatesNoYes
All ten hold an audit — that was the filter for being rated at all. What separates them is how recent it is, what the jurisdiction adds, and whether the infrastructure can retain anything in the first place.

The strongest evidence is not on that table, because only two providers have it. Mullvad's Gothenburg offices were searched by Swedish police in 2023 and they left with nothing. PIA has been subpoenaed more than once and produced nothing usable. An audit is an inspector confirming nothing is recorded; a raid is the claim being tested. The second is worth more.

Free VPNs: where the answer is actually no

Running a server network costs real money. If you are not paying, someone is.

Several free VPNs have been found logging and selling traffic data. Several have operated as residential proxy networks — your connection routes other people's traffic in exchange for routing yours through theirs, meaning requests you know nothing about appear to come from your home address. This is usually disclosed somewhere in a terms document nobody reads.

Being in the App Store or Play Store is not a privacy audit.

The exception is a free tier funded by a paid business, with the same audited policy applied to it. Proton VPN's is the one we rate: no data cap, three countries, no streaming, same no-logs guarantee as the paid plan.

Two practical safety questions

Banking. Safe, and safer than not on public Wi-Fi. The nuisance is that some banks block VPN IP ranges as fraud prevention. Do not turn the VPN off — use split tunnelling to send the banking app outside the tunnel and leave everything else protected.

Legality. Legal in most countries and entirely ordinary. A handful restrict or prohibit them — China, Russia, Iran, the UAE and Turkey among them, with rules ranging from licensing to outright bans, and the details change. Using a VPN does not make an otherwise illegal activity legal anywhere.

The honest summary

The technology is safe. Nobody is breaking the encryption.

The provider is the variable, and the four checks above — audit, RAM-only, jurisdiction, clean leaks — turn that from a matter of faith into a matter of evidence.

Most free VPNs fail those checks, and some fail them in ways that make you worse off than having no VPN at all.

That is a narrower claim than most of this industry makes, and it is the one that holds up.

Common questions

Are VPNs safe to use?

The technology is. Modern VPN protocols use the same class of encryption as online banking, and it is not where things go wrong. What varies is the provider: you are moving your browsing record from an internet provider that may be required to keep it to a company that promises not to. Whether that promise is worth anything is what the audit, the jurisdiction and the infrastructure tell you.

Can a VPN provider see my browsing?

Technically it is in a position to, which is exactly why the no-logs policy matters and why an unaudited one is worthless. A provider running RAM-only servers has nothing that survives a reboot; one with an independent audit of its live systems has had an outside firm confirm nothing is recorded. Both are checkable. A claim on a homepage is not.

Are free VPNs safe?

Usually not, and often the answer is worse than 'not'. A service with no revenue from you is earning it somewhere — several free VPNs have been found logging traffic, and several have operated as residential proxy networks, meaning strangers' traffic leaves your connection. The exception is a free tier funded by a paid business with the same audited policy, like Proton VPN's.

Is it safe to use a VPN for banking?

Yes, and on public Wi-Fi it is safer than not. Your bank's own encryption protects the session either way; the VPN adds a layer and hides the destination from the network. The practical problem is that some banks block VPN IP ranges as fraud prevention — the fix is split tunnelling, sending that one app outside the tunnel, rather than turning the VPN off.

Are VPNs legal?

In most countries, yes, and using one is ordinary. A small number of countries restrict or ban them — China, Russia, Iran, the UAE, Turkey and a few others have rules ranging from licensing requirements to outright prohibition, and the details change. Using a VPN does not make an otherwise illegal activity legal anywhere.

What makes one VPN safer than another?

Four checkable things, in order: an independent audit of the running servers within the last two years; RAM-only infrastructure, so a seized machine holds nothing; a jurisdiction without mandatory data retention; and clean leak tests with a working kill switch. A fifth counts double when it exists — a documented case where the provider was asked for records and had none.

Written by Amelia Ame and last checked September 10, 2026. Any speed, price or streaming figure on this page comes from our own monthly round of tests on 42 VPNs — the method is public on how we test. Spotted something out of date? Tell us and we'll re-check it.
Try it yourselfWebRTC leak testWebRTC leak test