ExpressVPN
Security
Usability
Rank 16 of 68 in the register
Virgin Islands (UK) · Commercial VPN
Exits in 106 countries
Head to head
The gap
The security score is not a total of good things. It starts at 100 and eight channels each take a share of what is left, so one channel can settle a record on its own. Both records are drawn here on the same scale — the model’s own cap of 0.9 — rather than on a scale fitted to this pair, which would make every comparison look equally dramatic.
Line by line
Every field the contract publishes about a provider, in the contract’s own groups, including the rows where the two agree — a table that printed only differences would invent a disagreement, and one that printed only the interesting rows would be us choosing what is interesting. Open a group to read its rows; each one says how many it holds and how many of them the two records answer differently.
A green cell means the methodology itself prices that value below the other one, not that we prefer it. Rows the model does not price carry no mark at all: price is never marked, because nothing in the model says cheaper is safer, and neither is coverage, platform count or devices. Where a value was never established the cell says so instead of showing a zero.
What actually happened
Other pairs
Pairs within the top ten get a page — 80 comparisons in all. Records below that are not paired here: a comparison earns a page where the choice between the two is a real one, and that choice is made near the top of the register.
Security
Usability
Rank 16 of 68 in the register
Virgin Islands (UK) · Commercial VPN
Exits in 106 countries
1 documented demand, none of which produced data
Security
Usability
Rank 43 of 68 in the register
Norway · Browser proxy
Country list not published
No demand on the public record
Recent changes
3 changes logged, the latest on 13 Sep 2026
Open questions
Still open on this record.
The pentest, and the one not done. The pentest field is backed by Cure53's October-November 2024 review of the Lightway protocol, which found an unauthenticated-data-fragment denial of service rated High alongside four lesser items. ExpressVPN's trust centre lists a long series of such engagements, so the cadence is real; what it does not contain is an infrastructure pentest of the server fleet separate from the KPMG no-logs engagement.
The two prices, corrected. The pricing page now sells three separate plan lengths — 1-month, 12-month and 2-year — rather than the 24-28-month-only structure read on 2026-08-29. U04_price_monthly=14.99 is the Basic 1-month plan, autorenewing at the same $14.99. U04b_price_yearly=59.85 is what the Basic 12-month plan (billed as 12 months plus a 3-month bonus) actually charges for its first term; it autorenews at $99.95/year afterward, the figure the previous record had mistakenly stored as the yearly field itself.
The transparency report. P05/P06/P08/P09 now rest on ExpressVPN's biannual transparency report (Jul–Dec 2025: 155 government/law-enforcement requests, 0 disclosures, 3 warrants listed separately) reached via the Trust Center — the earlier run missed both.
The canary, and the rest of the block. No ExpressVPN warrant canary could be found and no primary statement denies one, so P07 stays unknown. P02/P03=none_known rest on the transparency series and the privacy policy's litigation stance; P11=none_known on the policy's statement that all demands run through BVI courts. P04=withdrew_physical is the June 2022 India exit.
What is never published. Subscriber count (M08) and total server count (U03) are not published. Server hardware ownership (C08: owned vs leased) and app-level device identifiers (C12) could not be established from any page checked.
106 countries against a claim of 113. U02_server_countries reflects the 105 country-landing pages in ExpressVPN's own sitemap plus China (confirmed 'Available - Virtual Locations' on the live /vpn-server page but lacking a dedicated landing page) — 106 codes total, against the site's own marketing claim of '113 Countries'; the live server-location page is a very large per-protocol table that was not exhaustively parsed, so the gap between 106 and 113 is reported rather than resolved.
An audit finding between two categories. V11_audit_findings is recorded as session_metadata rather than none_linkable or aggregates_only: the 2025 KPMG report describes a structured per-connection record (country, ISP, date, protocol, data volume, a stable salted-hash pseudonym) that is more than a pure aggregate but lacks IP and precise time — a genuinely ambiguous case for this field's four middle categories.
Not checked this pass. Whether ExpressVPN's coverage exists outside affiliate sites (X08), its affiliate payout tier (X10), and whether owner-run review media flags the ownership tie (X11) were not checked in this pass.
P2P, looked for and absent. U12a_p2p_allowed stays unknown for a different reason than the rest: it was looked for and is not published. Neither sitemap (578 page and support URLs) nor the terms of service mentions P2P, BitTorrent or file sharing anywhere, while every other catalogued provider states its position in its own documents. A support article or a terms clause would close it; a review site saying it works would not.
Still open on this record.
The owner group's record. X04 is the deliberate hole. The Form 20-F establishes that Opera itself is not party to any material proceeding, but the field asks about the owner group, and Kunlun's own record was not chased to a primary document this run.
The two proceedings nobody opened. The reported CFIUS-mandated divestiture of Grindr and the 2020 securities class action that followed a short-seller report are both widely described and neither was opened here. Grindr's first post-listing Form 10-K does not recount it.
Why the score does not turn on it. Both clean and unknown price at 0.000, so nothing in the score turns on this; what is missing is the record, not the number, and the next run should start at the Kunlun filings and the federal docket rather than at a summary of them.
The report that would move four fields. The Deloitte report is the other document that would move several fields at once: V04, V07, V11 and V15 are all unknown only because it is not published, and V11 in particular is the field the whole no-log claim rests on.
What has no document. U07 has no document and neither does C13 behind it: Opera names AES-256 and a "secure tunnel" and never a protocol, so the weakest transport on offer is unestablished. U08, U09 and U12b are unfilled for the same reason - the feature comparison table on the product page marks rows with ticks that the fetched markup does not carry, and reading ticks off a rendered image is not a source.
Servers described, not evidenced. C02, C06 and C08 have nothing behind them: Opera says the servers are physical and its own, which settles neither disk nor DNS nor who owns the hardware. C09b cannot be answered while U02 is unknown.
One store, not two. Only the Google Play data-safety form was read; the App Store privacy labels for the iOS browser were not, so X12 rests on one store rather than the worse of two.
Two readings rather than statements. Linux in U01 is inferred from the desktop help manual, which documents the VPN and covers Windows, macOS and Linux together without splitting by platform; Android and iOS are named explicitly in the audit announcement. U10 is unlimited because there is no account and no device cap to enforce one, which is a reading of the product rather than a stated figure.
Notes
On the record as a whole.
Express Technologies Ltd., incorporated in the British Virgin Islands since 2009, owned by Kape Technologies plc since the September 2021 acquisition ($936M, Kape's own about-us page). TrustedServer RAM-only architecture has been audited annually by KPMG (ISAE (UK) 3000 Type I, most recently 28 Feb 2025) since 2022 for privacy-policy compliance, plus PwC Switzerland (2019, TrustedServer) and Cure53 (2019 browser extensions; 2021 Lightway protocol, open-sourced).
The 2025 KPMG report was read directly (confidence A): the server writes one pseudonymous event per connection (date without time, salted/hashed username, country+ISP GeoIP, data volume, location group, protocol) but never logs IP address or exact timestamp; builds are described as reproducible across two independently operated build systems.
In 2017, Turkish authorities seized an ExpressVPN server investigating the assassination of Russian Ambassador Andrei Karlov and found no usable logs (TorrentFreak, which carries a sponsorship notice for ExpressVPN — noted, not excluded, since the facts are externally checkable and ExpressVPN's own statement page has since returned HTTP 410 with no Wayback Machine snapshot).
In September 2021 the DOJ's Deferred Prosecution Agreement with Daniel Gericke, ExpressVPN's Chief Information Officer, over his prior 2016-2018 role in the UAE's 'Project Raven' hacking operation became public; the primary DPA document itself never names ExpressVPN (it covers only his earlier UAE employment) — the ExpressVPN link comes from ExpressVPN's own and press statements. ExpressVPN kept Gericke employed and published a public defense of that decision.
C12 is resettable_ad_id on the provider's own prose rather than on a store category. The privacy policy's marketing paragraph states that an Installation ID and an XV User ID are always collected and that advertising identifiers — IDFA or the Android Advertising ID — follow on explicit consent, all of it reaching AppsFlyer; the Play data-safety form independently declares Device or other IDs for advertising or marketing.
The consent gate and a mitigation nobody else here offers — AppsFlyer-bound traffic routed through a dedicated ExpressVPN IP pool so attribution cannot correlate by IP — are real and are recorded here, because the floor prices what can be held, not how well it is explained.
U07_protocols carries the whole picker: Lightway UDP and TCP as vendor_open, beside WireGuard, OpenVPN UDP/TCP and IKEv2. Lightway is ExpressVPN's own protocol and its source is published with independent review behind it (Cure53, 2021 and 2024), which is the distinction vendor_open exists for — proprietary prices the impossibility of telling whether a transport is weak, and here it can be told.
PPTP is retired on ExpressVPN apps by the provider's own protocol page, and L2TP and SSTP are explained there without being offered.
On the record as a whole.
Scope. This record is Opera's free VPN built into the browser, which is what makes it a browser_proxy: Opera states plainly that it "only protects your browsing within the Opera browser, and not your entire device".
The paid sibling VPN Pro is a different product and is not scored here - the privacy statement says VPN Pro "is provided by a third-party service provider which owns, operates, and maintains the infrastructure", it costs from $4 a month, covers up to six devices and 48 countries, and the free VPN by contrast runs on Opera's own infrastructure.
Who that third party is has moved: the 2024 audit announcement says VPN Pro servers are "provided in collaboration with Nord", and the 2026 explainer says VPN Pro is "equipped with the next-gen Lightway protocol", which is ExpressVPN's. Neither document says the arrangement changed.
X02 is the load-bearing finding, and both documents behind it are Opera's own. The 2024 announcement quotes Deloitte's opinion as "the configuration of IT systems and management of the supporting IT operations was suitably designed and implemented, in all material respects, based on the criteria described in Opera's Management Assertion, as of 10th August 2024", and separately attributes the sentence "There is no data logging functionality built into the VPN service, and no data whatsoever is collected" to Opera's own Management Assertion.
The 2026 post re-tells the same engagement as Deloitte having done the finding: "we gave Deloitte's team complete access to our VPN and server infrastructure, and they were able to verify our claim ... In fact, a data logging function is not even built into the VPN in the first place." The same post upgrades a window the 2024 post dates as 18 June to 10 August 2024 into "complete access".
Opera is describing its own assertion as its auditor's conclusion. That is why the VERIFY block splits the way it does. V01 is yes_verified on the strength of a report actually opened - Cure53's own published management summary of its March 2022 assessment - not on the strength of the Deloitte announcement.
The Deloitte report itself is not published anywhere, so V02 is press_only, and every field that is a finding of that report rather than a fact about the engagement stays unknown: fleet coverage (V04), assurance standard (V07), what the report states is retained (V11) and the strength of the opinion (V15).
Engagement facts - the firm, its category, the date, what was listed as tested - are taken from the announcement. A vendor that has demonstrably re-characterised this audit once is not a source for what the audit concluded. C01 is none_linkable because that is the declaration in the privacy statement; V11 is the finding, and there is no finding to read.
Cure53's report is real and is the reason V14 is yes_verified: seven testers, twenty-four person-days, white-box across four work packages covering the VPN clients, the server configuration and infrastructure, and the Opera Mini protocol used to deliver VPN config. Fourteen security-relevant issues, eight of them actual vulnerabilities, five rated high severity and none critical.
As of March 2022 nine were fixed with the fixes verified, one partly fixed, three risk accepted, one a false alert and one still in progress. Opera's blog says the seven items relating directly to the browser VPN were "all subsequently resolved", and the table bears that out - the residue sits in the Opera Mini work package, not in the VPN itself.
Ownership is fully disclosed and ends in a mandate country, which is why X03 and C11 point in opposite directions without contradicting each other.
The data controller named in Opera's own privacy statement is Opera Norway AS, a Norwegian company, and the transparency report is filed in that name.
The holding company is Opera Limited, an exempted company incorporated in the Cayman Islands in March 2018 with no substantive operations of its own. The Form 20-F for 2025 names Hong Kong Kunlun Tech Holding Limited as principal shareholder at 68.0%, a subsidiary of Kunlun Tech Co., Ltd. incorporated in the PRC, and states that Kunlun "is the ultimate parent of Opera and is controlled by Opera's executive chairman".
So M06 is NO and C10 is no, while M11 is CN and C11 is yes.
C12 is the sharpest gap between the VPN's declaration and the application it lives inside. The VPN section of the privacy statement declares no logging; a different section of the same document says that when an Opera application is installed "a random installation ID is generated. We collect this identifier, as well as Machine ID, hardware specifications (model, release date, etc.), operating system, environment configuration, and feature usage data", retained for up to three years.
A Machine ID is hardware-derived, so the identifier the provider holds is persistent_hardware_id and not an app-scoped random one, whatever the tunnel does or does not log.
X12 compares two documents Opera filed itself. The Play data-safety form for com.opera.browser declares Installed apps collected for Analytics, and the privacy statement never mentions collecting the applications installed on the device at all. Installed apps is behaviour, not an identifier, hence undisclosed_behaviour.
The same form declares Device or other IDs shared with other companies for advertising, which is what puts C07a at ads. C07b rests on something narrower and is marked B for it: the only third-party host in the markup served for the product page is Google Tag Manager, and what that container loads at run time was not enumerated.
U02 is unknown by design of the product, not by failure of the search: the free VPN offers three regions - Opera names them America, Asia and Europe - and never a country. C09 and C09b follow from that and cannot be settled while it holds.
X05 is ads_supported on Opera's own explainer, which lists advertising first among three revenue lines and describes Opera Ads collecting a randomly-generated user ID, city or country and broad categories of sites browsed, retained for up to a year; together with U05 = unlimited_free this is exactly the case R15 exists to flag.
X06 is the 2026 post's claim that AES-256 "would take a hacker with even the fastest computer more than a billion years to break". X09 is self_disclosed_prompt on two 2026 posts in which Opera published vulnerabilities that outside researchers had reported to it, along with the analysis and the fixed version - these are browser vulnerabilities rather than VPN incidents, and no VPN incident is known.
C05 is not_sold. The free VPN has no payment step at all - no subscription, no account - so there is nothing to pay anonymously or otherwise.
This record was first written as none, which reads as "only identified payment methods are offered" and is false here, because the vocabulary had no token for a service that takes no money; unknown would have claimed the search failed, which was also false, and between two wrong readings the one that errs against the provider was recorded. The token exists now and prices at nothing, which is the honest answer: where there is no payment there is no payment identity to leak.
13 Sep 20261 changes
Why this provider is in the catalogueM14_inclusion_basis
hand_picked, adverse_record changed to adverse_record
12 Sep 20263 changes
Security scoresecurity.score
15 changed to 14
Security verdictsecurity.verdict
insufficient changed to not_recommended
Yearly plan price USD, first term as chargedU04b_price_yearly
99.95 changed to 59.85
30 Aug 20261 changes
Weakest protocol still offeredC13_weakest_protocol
wireguard changed to not on the record
13 Sep 20261 changes
Why this provider is in the catalogueM14_inclusion_basis
hand_picked changed to adverse_record
12 Sep 20261 changes
Security scoresecurity.score
5 changed to 4
30 Aug 20261 changes
Anonymous payment optionsC05_payment_anonymous
empty changed to not_sold
ExpressVPN and Opera VPN were assessed by the HushFleet team and both placed in the Not recommended band: ExpressVPN scores 14/100 for security, Opera VPN 4/100. They share an independent audit. The 10-point gap opens widest on Jurisdiction — “Can someone compel what exists, without the provider getting a say?” — taking 0% from ExpressVPN and 48% from Opera VPN.
| ExpressVPN | Opera VPN | |
|---|---|---|
| Security | 14 not recommended · rank 16 of 68 | 4 not recommended · rank 43 of 68 |
| Usability | 70 out of 100 | 75 out of 100 |
| Record completeness | 84% usability 92% | 77% usability 45% |
| ExpressVPN | Opera VPN | |
|---|---|---|
| Who operates the exit | Run by the provider itself provider_operated | Run by the provider itself provider_operated |
| Retention as declared | Session metadata session_metadataBexpressvpn.com · | Nothing that links traffic to a person none_linkableAopera.com · 2 sources · |
| RAM-only diskless servers | Yes, checked by someone independent yes_verifiedAexpressvpn.com · | — not establishedno source published |
| IP allocation model | Dedicated address offered as an option dedicated_optionBexpressvpn.com · 2 sources · | Exit address shared between users sharedBopera.com · 2 sources · |
| Signup without email | No, an email address is required noBexpressvpn.com · | Yes, on the provider's word yes_declaredAblogs.opera.com · 2 sources · |
| Anonymous payment options | Cryptocurrency through a processorBexpressvpn.com · | The service takes no payment at allBopera.com · 2 sources · |
| Own DNS inside the tunnel | Yes, on the provider's word yes_declaredBexpressvpn.com · | — not establishedno source published |
| Worst third-party SDK category in the app | Install attribution attributionBexpressvpn.com · | Advertising adsAplay.google.com · |
| Worst third-party tracker category on the site | Advertising adsBexpressvpn.com · | Analytics analyticsBopera.com · |
| Who owns the hardware | — not established | — not established |
| Offered countries that sit under a logging mandate | 7 United Arab Emirates, Belarus, China, India, Kazakhstan, Turkey, VietnamBexpressvpn.com · | — not establishedno source published |
| Hosting in the mandate countries it offers | Virtual locations only, hardware elsewhere virtual_onlyBexpressvpn.com · | — not establishedno source published |
| Incorporation country mandates retention | No such mandate no | No such mandate no |
| Beneficial owner sits under a retention regime | No such regime nono source published · | Yes, the owner sits under a retention regime yesAsec.gov · |
| Persistent device identifier | A resettable advertising identifier resettable_ad_idBexpressvpn.com · 2 sources · | A permanent hardware identifier persistent_hardware_idAopera.com · |
| Weakest protocol still offered | — the question does not ariseBexpressvpn.com · 3 sources · | — not establishedno source published |
| What the exit does to passing traffic | — not established | — not established |
| ExpressVPN | Opera VPN | |
|---|---|---|
| At least one independent audit | Yes, and the report was read yes_verified | Yes, and the report was read yes_verified |
| How the report is published | The full report is published full_pdfAexpressvpn.com · | Press coverage only press_onlyAblogs.opera.com · |
| Subject of the audit | The no-logs claim itself · The infrastructure | The no-logs claim itself · The infrastructure |
| Server fleet coverage | The whole fleet all_fleetAexpressvpn.com · | — not establishedno source published |
| Auditor name |
| ExpressVPN | Opera VPN | |
|---|---|---|
| Server seizure by law enforcement | Seized, and nothing usable was on it seizure_no_dataCtorrentfreak.com · | No seizure on record none_knownAsecurity.opera.com · 2 sources · |
| Actual disclosure history | No disclosure on record none_known | No disclosure on record none_known |
| Court record of compelled production | No court record none_known | No court record none_known |
| Response to a national logging mandate | Pulled its servers out rather than comply withdrew_physicalBexpressvpn.com · | — not establishedno source published |
| Transparency report |
| ExpressVPN | Opera VPN | |
|---|---|---|
| Documented gap between claim and behaviour | — not establishedno source published | No documented lie noneBopera.com · 3 sources · |
| Marketing against audit findings | No gap on record noneBexpressvpn.com · | Marketing claims more than the audit found marketing_overstatesAblogs.opera.com · 2 sources · |
| Ownership structure transparency | Ownership is stated and checkable clear | Ownership is stated and checkable clear |
| Adverse events on the owner group record | A history of adware or malware adware_malware_history |
| ExpressVPN | Opera VPN | |
|---|---|---|
| Legal entity | Express Technologies Ltd.Bexpressvpn.com · 2 sources · | Opera Norway AS, Vitaminveien 4, 0485 Oslo, Norway - data controller for the Opera browsers and the party named in the transparency report; holding company Opera Limited, an exempted company incorporated in the Cayman Islands in March 2018, listed on Nasdaq as OPRAAopera.com · 2 sources · |
| Where the company sits | Virgin Islands (UK) VGBexpressvpn.com · 2 sources · | Norway NOAopera.com · 2 sources · |
| Year the service launched | 2009Bexpressvpn.com · |
| ExpressVPN | Opera VPN | |
|---|---|---|
| Platforms with a client | 10 Windows, Android, iOS, macOS, Linux, Routers, Android TV, Browser extension, Apple TV, Fire TVBexpressvpn.com · | 5 Android, iOS, Linux, macOS, WindowsBblogs.opera.com · 2 sources · |
| Countries with an exit | 106 countriesBexpressvpn.com · | — not establishedno source published |
| Paying monthly | $14.99 per monthBexpressvpn.com · | — the question does not ariseno source published |
| Paying yearly | $59.85 a year at renewal, billed once |
| ChannelPressure taken from what was left | ExpressVPNDominant channel: Integrity0 to 0.9, longer is worse | Opera VPNDominant channel: Retention0 to 0.9, longer is worse |
|---|---|---|
| RetentionDoes a record exist that links traffic to a person, and who checked? | 0.455 | 0.750 |
| IntegrityHas it been caught saying one thing and doing another? | 0.633 | 0.516 |
| JurisdictionCan someone compel what exists, without the provider getting a say? | 0.000 | 0.478 |
| IgnoranceHow much of this did nobody establish? | 0.127 | 0.149 |
| HygieneWhat identifying material is collected in passing, and can the client be checked at all? | 0.134 | 0.148 |
| ArchitectureWho operates the exit, and what does it do to the traffic? | 0.050 | 0.050 |
| DisclosureHas it already handed something over? | 0.000 | 0.000 |
| SilenceTen years, millions of users and nothing on record? | 0.000 | 0.000 |
| What is left of 100The channels multiply: each one takes a share of what the one before it left standing | 14 | 4 |
By circumstance
| ExpressVPN | Opera VPN | |
|---|---|---|
| Torrenting | — not established | Blocked blocked |
| Streaming | Reachable yes | — not established |
| Devices at once | 10 | unlimited |
| Under censorship | Claimed to work claimed | — not established |
| Exits in mandate countries | 7 United Arab Emirates, Belarus, China, India, Kazakhstan, Turkey, Vietnam | — not established |
| Hosting in those countries | Virtual locations only, hardware elsewhere virtual_only | — not established |
| Company under a mandate | No such mandate no | No such mandate no |
| Secret orders | No secret-order regime on record none_known | Orders go through a judge judicial_only |
| Deloitte (no-log audit, opinion as of 10 August 2024, announced 25 September 2024); Cure53, Berlin (white-box security assessment of the VPN clients, servers and periphery, summary report 23 March 2022)Ablogs.opera.com · 2 sources · |
| Auditor category | One of the Big Four big4 | One of the Big Four big4 |
|---|
| Assurance standard | ISAE 3000 isae3000Aexpressvpn.com · | — not establishedno source published |
|---|
| Date of latest report | 2025-02-28Aexpressvpn.com · | 2024-08-10Bblogs.opera.com · |
|---|
| Audit cadence | An annual series annual_seriesBexpressvpn.com · 3 sources · | Repeated, at no fixed interval repeated_irregularAblogs.opera.com · 2 sources · |
|---|
| Total published audits | 5Bexpressvpn.com · 4 sources · | 2Ablogs.opera.com · 2 sources · |
|---|
| Retention as the report states it | Session metadata session_metadataAexpressvpn.com · | — not establishedno source published |
|---|
| Client source code published | Some clients partialBexpressvpn.com · | None noneAsec.gov · |
|---|
| Reproducible builds | Yes, and a build was reproduced yes_verifiedAexpressvpn.com · | — not establishedno source published |
|---|
| Separate pentest | Yes, and the report was read yes_verified | Yes, and the report was read yes_verified |
|---|
| Strength of the assurance opinion | A reasonable-assurance opinion reasonableAexpressvpn.com · | — not establishedno source published |
|---|
Current, with request numbers fresh_with_numbers |
Current, with request numbers fresh_with_numbers |
| Reported numbers plausible for this scale | The numbers are plausible at this scale plausible | The numbers are plausible at this scale plausible |
|---|
| Warrant canary discipline | — not establishedno source published | Never had one noneBsecurity.opera.com · |
|---|
| Requests received | 155Bexpressvpn.com · | 20Asecurity.opera.com · |
|---|
| Requests that produced data | 0 | 0 |
|---|
| Secret-order regime | No secret-order regime on record none_knownBexpressvpn.com · | Orders go through a judge judicial_onlyBsecurity.opera.com · |
|---|
| Chronology of documented enforcement events | 1 documented demandCtorrentfreak.com · | 0 No demand on the public recordBsecurity.opera.com · 2 sources · |
|---|
| — not establishedno source published |
| How the service is paid for | Paid subscriptions only paid_onlyBexpressvpn.com · | Paid for by advertising ads_supportedAblogs.opera.com · 2 sources · |
|---|
| Claims of 100% anonymity or military-grade crypto | Makes no such claim noBexpressvpn.com · | Claims total anonymity or military-grade encryption yesAblogs.opera.com · |
|---|
| Aggressive lifetime subscriptions | Does not no | Does not no |
|---|
| Coverage exists only on affiliate sites | — not establishedno source published | Covered outside affiliate sites too noBsec.gov · 2 sources · |
|---|
| Security incident and how it was disclosed | Disclosed by someone else third_party_disclosedBjustice.gov · 2 sources · | Disclosed by the provider, promptly self_disclosed_promptAblogs.opera.com · 2 sources · |
|---|
| Affiliate programme and payout tier | — not established | — not established |
|---|
| Owner-run review media discloses the tie | — not establishedno source published | — the question does not ariseBblogs.opera.com · |
|---|
| App store declaration | The store form matches the published policy matches_policyBapps.apple.com · 3 sources · | Behaviour is declared to the store, not in the policy undisclosed_behaviourAplay.google.com · 2 sources · |
|---|
| User base scale (mass >=10M, mid >=1M, niche <1M) | — not establishedno source published | Mass: 10 million users or more massAsec.gov · |
|---|
| Ultimate beneficial owner as written | Teddy Sagi, via Unikmind Holdings Limited (Isle of Man), sole shareholder of Kape Technologies plc since the May 2023 delisting; Kape owns ExpressVPN through Express Technologies Ltd.Cen.wikipedia.org · 2 sources · | Kunlun Tech Co., Ltd., incorporated in the PRC, ultimate parent, holding 68.0% through its Hong Kong subsidiary Hong Kong Kunlun Tech Holding Limited; Kunlun is controlled by Opera's executive chairman James Yahui Zhou, who holds 11.6% of Kunlun directly and 15.1% through Beijing Yingrui Century Software R&D Center L.P.Asec.gov · |
|---|
| Other businesses of the owner group | Antivirus · A review directory · Adtech or adwareCen.wikipedia.org · | Adtech or adware · A portfolio of other appsAsec.gov · 2 sources · |
|---|
| Country of the ultimate beneficial owner | IMBperivan.com · | CNAsec.gov · |
|---|
| Owner group | kapeBexpressvpn.com · | kunlunAsec.gov · |
|---|
| Date the current owner took control | 2021-09Cexpressvpn.com · 2 sources · | 2016-11Asec.gov · |
|---|
| Role of this brand inside the group | A brand the group acquired acquired_brandCexpressvpn.com · | The group's principal brand principalBsec.gov · |
|---|
| Infrastructure shared with cluster siblings | — not establishedno source published | Separate infrastructure separateAblogs.opera.com · |
|---|
| — the question does not ariseno source published |
| Usable free tier | No free tier noneBexpressvpn.com · | A free tier with no data cap unlimited_freeAopera.com · 2 sources · |
|---|
| Works under active censorship | Claimed to work claimedDexpressvpn.com · | — not establishedno source published |
|---|
| Protocols offered | 4 A vendor protocol with published source, WireGuard, OpenVPN, IKEv2Bexpressvpn.com · 3 sources · | — not establishedno source published |
|---|
| Kill switch coverage | On every platform all_platformsCexpressvpn.com · | — not establishedno source published |
|---|
| Split tunneling available | Available yesBexpressvpn.com · | — not establishedno source published |
|---|
| Simultaneous connections | 10Bexpressvpn.com · | unlimitedBopera.com · 2 sources · |
|---|
| Friction to start using it | An email address only email_onlyBexpressvpn.com · | No account needed no_accountAblogs.opera.com · 2 sources · |
|---|
| P2P allowed | — not establishedno source published | Blocked blockedAblogs.opera.com · 2 sources · |
|---|
| Major streaming services reachable | Reachable yesBexpressvpn.com · | — not establishedno source published |
|---|