Owner
Many VPN brands belong to the same few companies. See which brands share an owner and which are independent: a finding against one brand can count against its siblings.
Who the operating company answers to, from M15_owner_group. The corporate groups are the ones named in methodology.groups; independent is a value of the field rather than one of them, and it means the provider answers to nobody on this list.
This is the one taxonomy where a sibling can move a score. R02_cluster_contagion carries a finding against one brand into the integrity channel of another in the same group — scaled by whether they share infrastructure, and never applied to a finding that predates the acquisition. R11_evidence_voiding works the other way: an audit dated before control changed hands does not count for the company that holds the brand now. Both need M16_control_since, which is why the date matters more here than the ownership does.
What a page here does not show is how much risk was carried: the magnitude lives in security.breakdown.cluster and is not published on a record. Group membership, brand role and the date are.
Where M15 is unknown the record appears under no owner at all (five on file). That is the honest state rather than a gap: such a provider is often reported to sit inside a larger group, and publishes it nowhere anyone can cite. Independence is a fact about ownership and says nothing about quality on its own — the term holds records at both ends of the register.
Browse
Each one opens a list of providers ranked by security. The number shows how many providers it holds today.