Questions
The ranking here disagrees with most others, and it disagrees in a specific direction: almost nothing scores well. These are the questions that follow from that, answered against the model rather than around it.
Because a single number would have to trade privacy against reach, and that trade is not ours to make. A censorship tool with weak privacy and a privacy-first VPN with a small network are both correct answers — to different questions.
So a provider carries a security score and a usability score, out of 100 each, and they are never averaged. The ranking follows security alone. Usability is printed beside it and sorts the table if you ask it to, but it never moves a provider past a better security score — the only order it decides is between records with identical security scores, and 56 of the 77 are in that position.
The distribution is what it is: 0 strong, 2 acceptable, 2 weak, 11 insufficient and 53 not recommended. The other 0 carry a no_data verdict: too little is published to place them, so no list ranks them, and each keeps its page.
But read what that measures. The model scores the state of the evidence, not a hunch about the company. A provider lands low either because something documented is against it, or because almost nothing has been established either way — and those two are very different situations that a star rating would blur into one.
The honest summary is not “the market is bad”. It is that most of this market has never been checked by anyone but itself.
Not on the strength of a rank, no. Find its record in the ranking and read the breakdown: the score is a product of eight channels, and which one dragged it down changes what the number means for you.
A provider marked down because a court record shows it produced data is telling you something different from one marked down because nobody has ever audited it. The first is a finding. The second is a gap.
No. It means that what has been published about this provider, weighed by who published it and how old it is, leaves fewer routes by which the provider itself could identify you.
It says nothing about your device, your browser, what you log into through the tunnel, or an adversary who does not need the provider's cooperation. And it cannot see a lie nobody has caught yet — the model was tested against four providers later caught lying and separated only one of them clearly in advance.
There are none, and that is deliberate. We do not run the software; we read what has been published about it, with a source and a date against every value. A speed number measured once from one place is not a fact about a provider, and it would sit in the same table as facts that are.
What we do carry on the usability axis is what can be sourced: server countries, network size, price, free tier, protocol, kill switch, simultaneous connections, and whether streaming and P2P are permitted.
unknown. Is the research unfinished?42% of security fields across the register are unknown — 2,143 of 5,159 — and that number is a finding rather than an apology. unknown means nobody has published an answer — not that we did not look, and not that the answer is bad.
It also costs the provider points. A field left open feeds the ignorance channel, on the reasoning that a claim nobody can check is worth less than one that has been. The alternative — inferring a value from the marketing page — would produce a fuller table and a worse one.
Ten of the 77 carry usability.state: no_data. Too little was published to place them, so the figure you see is a lower bound rather than a measurement — it is what the record supports, and the real answer can only be higher.
It is a statement about the research and not about the provider. Such a provider has not failed an examination; it has not been examined. The same holds on the security axis, where no of the 77 carry a no_data verdict and no list ranks them.
Because the record does not ask what a provider claims. It asks what record exists that could link traffic to a person, and it answers with a field that carries a source and a date.
Of the values on file, 3,285 rest on a document somebody else published and 2,875 are the provider's own assertion. Both are stored, and they are not treated alike: an unexamined favourable claim regresses towards the market prior, while an admission against interest keeps its full weight. And most of those assertions settle nothing — 2,415 of the 2,875 sit on a field the record still counts as unknown. A no-logs sentence in a privacy policy is a claim about the future written by the party it constrains.
Different questions, and they live at different URLs on purpose so they cannot compete for the same search.
Jurisdiction is where the operating company is registered — it decides who can compel the company, and whether the company gets a say. Server countries is where traffic exits, which decides which local regimes touch the hardware. A company registered somewhere permissive can still run its fleet through countries that mandate logging, and several do.
An audit is evidence, and evidence has properties. The model reads five of them: who the auditor was, what standard they worked to, whether the report is published in full or as a press line, whether the whole fleet or a sample was in scope, and whether it is a one-off or a series.
And it ages. An audit holds its weight for 12 months, then halves every 18; an observed practice holds for 12 and halves every 60, because a habit decays more slowly than a snapshot. Neither falls to zero — a floor remains, since a passed audit is never worth nothing.
Sources are graded the same way: A counts fully, B at 0.85, C at 0.7, D at 0.35. Across the register there are 580 A-grade sources against 3,200 B, 289 C and 26 D.
There is no lever to reach for. The score is computed from published fields and carries no editorial adjustment — the hand-tuning that once existed was removed precisely because every provider page prints the arithmetic, and a moved number would make that printout a lie.
What a provider can do is change the evidence: publish the audit in full, put the retention answer somewhere checkable, maintain the transparency report. That moves the number, and it is meant to.
Because a rating assembled from other people's commercial rankings says more about those rankings than about the provider. It cannot sit in the same table as an assessment built from sources and dates without one quietly borrowing authority from the other.
Ranking here is built from the security assessment and nothing else.
Per field, by how fast the answer moves. Prices and platform facts carry a 30-day life; server counts and enforcement history 90; architecture and retention 180; audits and company facts 365. A value past its life is re-checked before it is trusted again.
Every value also carries the date it was last confirmed, printed next to it on the record. The current pass was read on 26 September 2026 against methodology 3.7.0.
Tell us, with a source. The correction form carries the field identifier, the value you saw and the version of the model that produced it, so nobody has to ask what you were looking at.
Corrections to factual data are made the same day. If a correction moves a score it moves the rank with it, and the change appears in the public log — field, old value, new value, date. The log records what moved, never who asked.
There is a form for exactly that, and it asks for a work email on the domain we already hold for the service — the only identity check made anywhere on this site.
One thing it will not do is negotiate the number. Point at the field and at what is published about it, and the field moves; the score follows from the field, not from the conversation.
That is what the glossary is for — the field states, the eight channels, where a value came from, and the ordinary VPN vocabulary a record is written in.