Explainer
One encrypted hop between your device and the internet. This page is the starting point for the section: what the hop does, who it hides you from, who it hands the view to instead, and which of the promises made for it survive contact with the mechanism.
A VPN is one encrypted hop. Instead of your device reaching a website straight across the network you are sitting on, it opens an encrypted tunnel to a server the VPN provider runs, and that server makes the request on your behalf. Everything between you and that server is unreadable to whoever carries it. Everything after it looks like it came from the server rather than from you.
That is the entire mechanism, and two consequences fall out of it. The network you are on — the cafe Wi-Fi, the office router, your internet provider — stops being able to read what you are doing. And the provider running the server starts being able to.
A VPN moves the question of who can watch you. It does not remove it. Almost every honest claim made for a VPN is a version of the first consequence, and almost every dishonest one is a version of the second gone unmentioned.
The client on your device and the provider's server agree on keys, then wrap every packet you send in that encryption before it leaves the machine. The wrapper carries only what a router needs to move it: the address of the server and the size of the packet. What is inside — the site, the page, the request — is sealed until it reaches the far end.
At the far end the server unwraps it and makes the request over the ordinary internet, from its own address, in whichever country it stands in. The reply comes back the same way in reverse. From the website's side, the visitor is the server.
Three details in that description do most of the work, and all three are things a record on this site records:
The vocabulary for all of this — tunnel, exit, kill switch, DNS leak — is defined in the glossary, each entry pointing at whichever page on this site owns the concept.
This is the table the rest of the page argues with. It is the honest version of the diagram every VPN sells itself with.
| Who | Without a VPN | With one |
|---|---|---|
| The network you are on | Which sites you reach, and when | That you are connected to a VPN, and how much traffic you send |
| Your internet provider | The same, and it is generally required to keep some of it | The same as above — one encrypted destination, nothing about what is inside |
| The VPN provider | Nothing. It is not in the path | Everything the network used to see, plus who is paying for the account |
| The site you visit | Your address, and whatever your browser and your login tell it | The server's address, and whatever your browser and your login tell it |
| Anyone who can compel the provider | Goes to your internet provider instead | Gets what the VPN provider holds, or an order to start holding it |
Read the last two rows together. A VPN is effective against the party that carries your traffic and ineffective against the party you are talking to — and the party in the middle changes rather than disappears.
Because the mechanism moves visibility rather than deleting it, choosing a VPN is choosing who holds it. That is a question about a company, not about software, and it is why this site scores what it scores.
Three things decide how much that transfer costs you:
That is the whole reason the ranking exists in the shape it does. Of the 77 records on file, read on 26 September 2026 under methodology 3.7.0, 0 score strong on security and 53 are not recommended, which is a statement about how little of this market has ever been examined by anyone but itself. The methodology sets out how the number is built; the register is the number applied to every record.
The whole distribution: Strong 0 · Acceptable 2 · Weak 2 · Insufficient 11 · Not recommended 53. The register opens on Proton VPN, at 70/100.
A record's security score is read into a band by the stored methodology: Strong from 75, Acceptable from 55, Weak from 35, Insufficient from 15, and Not recommended below that. Eight channels make the score, each taking at most 0.9 of what the one before it left standing — the question each channel asks is set out on the methodology, and is not repeated here.
The register sorts its 77 records into nine service classes, and a class with a record on file has a page of its own. An alternative in the sense this site uses is another record of the same class; a record of another class does a different job.
| Class | Records |
|---|---|
| Commercial VPN | 59 |
| Bundled suite | 0 |
| Browser proxy | 1 |
| Censorship tool | 4 |
| Decentralized | 2 |
| P2P exit | 2 |
| Proxy network | 0 |
| Self-hosted | 0 |
| Unknown | 0 |
It does nothing about the two largest ways you are identified online: your browser, which is distinctive enough to recognise on its own, and your accounts, which you sign into by name. A site you log into knows precisely who you are regardless of which country its visitor appears to come from.
It does not remove malware, it does not make a bad password good, and it does not make an insecure site secure — the encryption ends at the exit server, and the rest of the journey is whatever it would have been.
If your risk is political persecution, this is the wrong tool. The threat model a VPN answers is a network operator with commercial curiosity, not a state adversary, and we would rather write that down than sell a subscription that does not fit.
No. It hides your traffic from the network carrying it and replaces your address with the exit server's; your browser, your logins and anything you type identify you exactly as before.
Anonymity is a different tool with a different cost, and Tor is the one that provides it — slower by design, and without a company to trust.
Only if you have a reason your own internet provider should not see which sites you reach. A VPN at home moves that visibility to the VPN provider, and whether that is an improvement depends entirely on which of the two you would rather trust.
On a network you do not control — a hotel, an airport, an office — the calculation is different, because you know nothing about who runs it.
Somebody pays for the bandwidth. A free tier is either a sample of a paid product or a business model of its own, and the second kind — advertising, resale of idle bandwidth, data brokerage — is what the register scores worst.
The register carries a free-tier filter for exactly this reason, and it is a filter rather than a recommendation: a free tier and a security score are separate facts, and the second is the one to read.
In most of the world, yes, and it is a separate question from whether what you do through it is legal. A short list of countries restricts, licenses or blocks VPNs outright.
Next
Every explainer ends by naming the pages that own what it only touched.
Not an explainer but the model itself, for a reader who got to the end of this page and wants to know how the judgement is made.
What the register knows about this market as a whole, and what it does not — every figure from the index, none from a survey.
The restriction belongs to a country rather than to a provider, and where the register holds that law it is stated and cited on the country's own page. This site does not publish instructions for getting around a national block.