Not recommended
Opera VPN
Paying monthly
— no monthly plan
Paying yearly
— no yearly plan
Coverage
Not published no country list published
Free tier
Yes free, no data cap
Security
Usability
Opera VPN was assessed by the HushFleet team and placed in the Not recommended band, with a security score of 4/100; too little is published to place its usability score. In the overall security ranking of VPN providers it ranks 43 of 68. Browser proxy, company jurisdiction Norway. It has an independent security audit: it is known only from press coverage, evidence level A.
7 fields sit on this record without entering the score, and the contract says so in the field itself: scored: false. They are here because a reader asking who owns this company, or who signed the audit, is asking something the record answers — and because a value that never touches the arithmetic should be visibly outside it rather than quietly mixed in.
Alternatives
Not recommended
Paying monthly
— no monthly plan
Paying yearly
— no yearly plan
Coverage
Not published no country list published
Free tier
Yes free, no data cap
Security
Usability
| Offered countries that sit under a logging mandateC09_mandate_countries | unknown |
|---|---|
| Country of the ultimate beneficial ownerM11_owner_jurisdiction | CN |
| Owner group cluster keyM15_owner_group | kunlun |
| Date the current owner took controlM16_control_since | 2016-11 |
| Role of this brand inside the groupM17_brand_role | principal |
| Infrastructure shared with cluster siblingsM18_shared_infrastructure | separate |
| Total published auditsV10_audit_count | 2 |
| Service class | Browser proxy — security leads |
|---|---|
| Security score | 4 of 100 · Not recommended |
| Usability score | 75 of 100 · state no_data · 45% established · 41.9% of the weight read |
| Legal entity | Opera Norway AS, Vitaminveien 4, 0485 Oslo, Norway - data controller for the Opera browsers and the party named in the transparency report; holding company Opera Limited, an exempted company incorporated in the Cayman Islands in March 2018, listed on Nasdaq as OPRA |
| Jurisdiction | Norway |
| Ultimate owner | Kunlun Tech Co., Ltd., incorporated in the PRC, ultimate parent, holding 68.0% through its Hong Kong subsidiary Hong Kong Kunlun Tech Holding Limited; Kunlun is controlled by Opera's executive chairman James Yahui Zhou, who holds 11.6% of Kunlun directly and 15.1% through Beijing Yingrui Century Software R&D Center L.P. |
| Exposure | High · dominant channel: retention |
| Retention | Nothing that links traffic to a person |
| Latest audit | Deloitte (no-log audit, opinion as of 10 August 2024, announced 25 September 2024); Cure53, Berlin (white-box security assessment of the VPN clients, servers and periphery, summary report 23 March 2022) · 10 Aug 2024 · Repeated, at no fixed interval · Yes, and the report was read |
| Countries with exits | not published |
| Protocols | unknown |
| Works under active censorship | unknown |
| Weakest protocol still offered | unknown |
| Own DNS inside the tunnel | unknown |
| Platforms | AndroidiOSLinuxmacOSWindows |
| Simultaneous devices | unlimited |
| Kill switch | unknown |
| Split tunnelling | unknown |
| Signing up | No account needed |
| Free tier | A free tier with no data cap |
| P2P allowed | Blocked |
| Major streaming services reachable | unknown |
| Price, monthly | not published |
| Price, yearly | not published |
13 Sep 20261 changes
Why this provider is in the catalogueM14_inclusion_basis
hand_picked changed to adverse_record
12 Sep 20261 changes
Security scoresecurity.score
5 changed to 4
30 Aug 20261 changes
Anonymous payment optionsC05_payment_anonymous
empty changed to not_sold
Coverage147countries
Paying monthly$9.99monthly
Paying yearly$53.88yearly total
Free tierYeslimited free plan
Devices10at once
Security
Usability
Coverage50countries
Paying monthly$5.69monthly
Paying yearly$69.60yearly total
Free tierNopaid plans only
Devices5at once
Security
Usability
Coverage41countries
Paying monthly$6.00monthly
Paying yearly$60.00yearly total
Free tierNopaid plans only
Devices5at once
Security
Usability
Eight channels, each asking one question of the published record and reading a named set of fields to answer it. They multiply rather than add — the factor beside a channel is what is left after the pressure it found, and open a channel to see every field it read, as it is stored. How the model works
Security fields
67 55 of them feed a channel
Established
51 15 left unknown, 1 not applicable
Completeness
77% the share the model could weigh
Citations
86 across 14 documents
Every value carries what it rests on, and the model weighs the four levels differently. Weight, then how many citations on this record sit at that level:
A weighs 1.00 · 62 hereB weighs 0.85 · 24 here
The weights are methodology.json’s own; a claim seen in the artefact itself counts for more than the same claim reported second-hand. The date at the end of a row is the day that value was last read.
A channel does not price every field it reads. The ones it did are marked along their edge and carry what they added; everything else was read and cost nothing. Only a channel that composes field by field can mark a field at all — the rest price themselves by the parameters printed above their rows.
Still open on this record.
The owner group's record. X04 is the deliberate hole. The Form 20-F establishes that Opera itself is not party to any material proceeding, but the field asks about the owner group, and Kunlun's own record was not chased to a primary document this run.
The two proceedings nobody opened. The reported CFIUS-mandated divestiture of Grindr and the 2020 securities class action that followed a short-seller report are both widely described and neither was opened here. Grindr's first post-listing Form 10-K does not recount it.
Why the score does not turn on it. Both clean and unknown price at 0.000, so nothing in the score turns on this; what is missing is the record, not the number, and the next run should start at the Kunlun filings and the federal docket rather than at a summary of them.
The report that would move four fields. The Deloitte report is the other document that would move several fields at once: V04, V07, V11 and V15 are all unknown only because it is not published, and V11 in particular is the field the whole no-log claim rests on.
What has no document. U07 has no document and neither does C13 behind it: Opera names AES-256 and a "secure tunnel" and never a protocol, so the weakest transport on offer is unestablished. U08, U09 and U12b are unfilled for the same reason - the feature comparison table on the product page marks rows with ticks that the fetched markup does not carry, and reading ticks off a rendered image is not a source.
Servers described, not evidenced. C02, C06 and C08 have nothing behind them: Opera says the servers are physical and its own, which settles neither disk nor DNS nor who owns the hardware. C09b cannot be answered while U02 is unknown.
One store, not two. Only the Google Play data-safety form was read; the App Store privacy labels for the iOS browser were not, so X12 rests on one store rather than the worse of two.
Two readings rather than statements. Linux in U01 is inferred from the desktop help manual, which documents the VPN and covers Windows, macOS and Linux together without splitting by platform; Android and iOS are named explicitly in the audit announcement. U10 is unlimited because there is no account and no device cap to enforce one, which is a reading of the product rather than a stated figure.
On the record as a whole.
Scope. This record is Opera's free VPN built into the browser, which is what makes it a browser_proxy: Opera states plainly that it "only protects your browsing within the Opera browser, and not your entire device".
The paid sibling VPN Pro is a different product and is not scored here - the privacy statement says VPN Pro "is provided by a third-party service provider which owns, operates, and maintains the infrastructure", it costs from $4 a month, covers up to six devices and 48 countries, and the free VPN by contrast runs on Opera's own infrastructure.
Who that third party is has moved: the 2024 audit announcement says VPN Pro servers are "provided in collaboration with Nord", and the 2026 explainer says VPN Pro is "equipped with the next-gen Lightway protocol", which is ExpressVPN's. Neither document says the arrangement changed.
X02 is the load-bearing finding, and both documents behind it are Opera's own. The 2024 announcement quotes Deloitte's opinion as "the configuration of IT systems and management of the supporting IT operations was suitably designed and implemented, in all material respects, based on the criteria described in Opera's Management Assertion, as of 10th August 2024", and separately attributes the sentence "There is no data logging functionality built into the VPN service, and no data whatsoever is collected" to Opera's own Management Assertion.
The 2026 post re-tells the same engagement as Deloitte having done the finding: "we gave Deloitte's team complete access to our VPN and server infrastructure, and they were able to verify our claim ... In fact, a data logging function is not even built into the VPN in the first place." The same post upgrades a window the 2024 post dates as 18 June to 10 August 2024 into "complete access".
Opera is describing its own assertion as its auditor's conclusion. That is why the VERIFY block splits the way it does. V01 is yes_verified on the strength of a report actually opened - Cure53's own published management summary of its March 2022 assessment - not on the strength of the Deloitte announcement.
The Deloitte report itself is not published anywhere, so V02 is press_only, and every field that is a finding of that report rather than a fact about the engagement stays unknown: fleet coverage (V04), assurance standard (V07), what the report states is retained (V11) and the strength of the opinion (V15).
Engagement facts - the firm, its category, the date, what was listed as tested - are taken from the announcement. A vendor that has demonstrably re-characterised this audit once is not a source for what the audit concluded. C01 is none_linkable because that is the declaration in the privacy statement; V11 is the finding, and there is no finding to read.
Cure53's report is real and is the reason V14 is yes_verified: seven testers, twenty-four person-days, white-box across four work packages covering the VPN clients, the server configuration and infrastructure, and the Opera Mini protocol used to deliver VPN config. Fourteen security-relevant issues, eight of them actual vulnerabilities, five rated high severity and none critical.
Composed rather than added: a prior of 0.55 on the silent branch, moved by what the paper says (0.0118) and by what the practice shows (0.0), at credence 0.0118 from the audit and 0.595 from how the provider engaged, against a severity of 0.03 for what is actually retained.
Retention linkable to a person as declaredmaterialC01_linkable_retention
none_linkable
Aopera.comAopera.com30 Aug 2026
Report a problem with C01_linkable_retentionPersistent device identifier the provider holdsC12_device_identifier
persistent_hardware_id
Aopera.com30 Aug 2026
Report a problem with C12_device_identifierComputed
×0.044 of a clean record completeness 77%
Where the drop comes from: Retention. It is the channel this record's risk is concentrated in — on its own it takes a clean record to ×0.250, and its bar above is filled to that.
Exposure is recorded as high and the integrity status as caught_lying.
Against the rest of the register, this record sits furthest above on Ignorance — ×0.851 where the register averages ×0.662 — and furthest below on Retention, ×0.250 against ×0.432.
Published score
4Every row above is one field of the published record, and every one of them can be challenged: every row carries Report, or raise something about the record as a whole. A correction with a source behind it is made the same day, and if it moves the score it moves the rank.
As of March 2022 nine were fixed with the fixes verified, one partly fixed, three risk accepted, one a false alert and one still in progress. Opera's blog says the seven items relating directly to the browser VPN were "all subsequently resolved", and the table bears that out - the residue sits in the Opera Mini work package, not in the VPN itself.
Ownership is fully disclosed and ends in a mandate country, which is why X03 and C11 point in opposite directions without contradicting each other.
The data controller named in Opera's own privacy statement is Opera Norway AS, a Norwegian company, and the transparency report is filed in that name.
The holding company is Opera Limited, an exempted company incorporated in the Cayman Islands in March 2018 with no substantive operations of its own. The Form 20-F for 2025 names Hong Kong Kunlun Tech Holding Limited as principal shareholder at 68.0%, a subsidiary of Kunlun Tech Co., Ltd. incorporated in the PRC, and states that Kunlun "is the ultimate parent of Opera and is controlled by Opera's executive chairman".
So M06 is NO and C10 is no, while M11 is CN and C11 is yes.
C12 is the sharpest gap between the VPN's declaration and the application it lives inside. The VPN section of the privacy statement declares no logging; a different section of the same document says that when an Opera application is installed "a random installation ID is generated. We collect this identifier, as well as Machine ID, hardware specifications (model, release date, etc.), operating system, environment configuration, and feature usage data", retained for up to three years.
A Machine ID is hardware-derived, so the identifier the provider holds is persistent_hardware_id and not an app-scoped random one, whatever the tunnel does or does not log.
X12 compares two documents Opera filed itself. The Play data-safety form for com.opera.browser declares Installed apps collected for Analytics, and the privacy statement never mentions collecting the applications installed on the device at all. Installed apps is behaviour, not an identifier, hence undisclosed_behaviour.
The same form declares Device or other IDs shared with other companies for advertising, which is what puts C07a at ads. C07b rests on something narrower and is marked B for it: the only third-party host in the markup served for the product page is Google Tag Manager, and what that container loads at run time was not enumerated.
U02 is unknown by design of the product, not by failure of the search: the free VPN offers three regions - Opera names them America, Asia and Europe - and never a country. C09 and C09b follow from that and cannot be settled while it holds.
X05 is ads_supported on Opera's own explainer, which lists advertising first among three revenue lines and describes Opera Ads collecting a randomly-generated user ID, city or country and broad categories of sites browsed, retained for up to a year; together with U05 = unlimited_free this is exactly the case R15 exists to flag.
X06 is the 2026 post's claim that AES-256 "would take a hacker with even the fastest computer more than a billion years to break". X09 is self_disclosed_prompt on two 2026 posts in which Opera published vulnerabilities that outside researchers had reported to it, along with the analysis and the fixed version - these are browser vulnerabilities rather than VPN incidents, and no VPN incident is known.
C05 is not_sold. The free VPN has no payment step at all - no subscription, no account - so there is nothing to pay anonymously or otherwise.
This record was first written as none, which reads as "only identified payment methods are offered" and is false here, because the vocabulary had no token for a service that takes no money; unknown would have claimed the search failed, which was also false, and between two wrong readings the one that errs against the provider was recorded. The token exists now and prices at nothing, which is the honest answer: where there is no payment there is no payment identity to leak.
How the report is publishedV02_report_publication
press_only
Ablogs.opera.com30 Aug 2026
Report a problem with V02_report_publicationSubject of the latest auditV03_audit_subject
no_logsinfrastructure
Bblogs.opera.com30 Aug 2026
Report a problem with V03_audit_subjectServer fleet coverageV04_scope_servers
unknown
nothing published · recorded as asserted
Auditor categoryV06_firm_category
big4
Ablogs.opera.com30 Aug 2026
Report a problem with V06_firm_categoryAssurance standardV07_audit_standard
unknown
nothing published · recorded as asserted
Date of latest reportmaterialV08_audit_date_latest
2024-08-10
Bblogs.opera.com30 Aug 2026
Report a problem with V08_audit_date_latestAudit cadenceV09_audit_regularity
repeated_irregular
Ablogs.opera.comAblogs.opera.com30 Aug 2026
Report a problem with V09_audit_regularityWhat the report states is retainedV11_audit_findings
unknown
nothing published · recorded as asserted
Strength of the assurance opinionV15_assurance_strength
unknown
nothing published · recorded as asserted
Chronology of documented enforcement eventsP12_case_history
Bsecurity.opera.comBsec.gov30 Aug 2026
Report a problem with P12_case_historyWhat this channel priced on this record:Lie 0.1Monetisation 0.2Absolute claims 0.04Store declaration 0.3
User base scale (mass >=10M, mid >=1M, niche <1M)also read by silenceM08_user_scale
mass
Asec.gov30 Aug 2026
Report a problem with M08_user_scaleOther businesses of the owner groupM10_owner_other_business
adtech_adwareapp_portfolio
Asec.govAblogs.opera.com30 Aug 2026
Report a problem with M10_owner_other_businessTransparency reportalso read by ignorance, silenceP05_transparency_report
fresh_with_numbers
Asecurity.opera.com30 Aug 2026
Report a problem with P05_transparency_reportReported numbers plausible for this scalealso read by ignoranceP06_report_plausibility
plausible
Bsecurity.opera.comBsec.gov30 Aug 2026
Report a problem with P06_report_plausibilityDocumented gap between claim and behaviourX01_documented_lie
none
Bopera.comBblogs.opera.comBsec.gov30 Aug 2026
Report a problem with X01_documented_lieMarketing versus audit findingsX02_claim_gap
marketing_overstates
Ablogs.opera.comAblogs.opera.com30 Aug 2026
Report a problem with X02_claim_gapOwnership structure transparencyX03_owner_transparency
clear
Asec.gov30 Aug 2026
Report a problem with X03_owner_transparencyAdverse events on the owner group recordX04_owner_group_history
unknown
nothing published · recorded as asserted
How the service is paid forX05_monetisation_model
ads_supported
Ablogs.opera.comAblogs.opera.com30 Aug 2026
Report a problem with X05_monetisation_modelClaims of 100% anonymity or military-grade cryptoX06_absolute_claims
yes
Ablogs.opera.com30 Aug 2026
Report a problem with X06_absolute_claimsAggressive lifetime subscriptionsX07_lifetime_push
no
Ablogs.opera.comAopera.com30 Aug 2026
Report a problem with X07_lifetime_pushCoverage exists only on affiliate sitesX08_affiliate_only_reviews
no
Bsec.govBcure53.de30 Aug 2026
Report a problem with X08_affiliate_only_reviewsSecurity incident and how it was disclosedalso read by ignoranceX09_incident_handling
self_disclosed_prompt
Ablogs.opera.comAblogs.opera.com30 Aug 2026
Report a problem with X09_incident_handlingAffiliate programme and payout tierX10_affiliate_program
unknown
nothing published · recorded as asserted
Owner-run review media discloses the tieX11_review_media_disclosure
not applicable
Bblogs.opera.com30 Aug 2026
Report a problem with X11_review_media_disclosureApp store data declaration against the provider's own policyX12_store_data_declaration
undisclosed_behaviour
Aplay.google.comAopera.com30 Aug 2026
Report a problem with X12_store_data_declarationContagion from the owner groupS18_cluster_contagion
0.0
no owner group on this record, so nothing to carry
Where the company sits 0.0, where its owner sits 0.45, the exits it offers 0.05, the gag-order regime 0.0.
Hosting in the mandate countries it offersC09b_mandate_hosting
unknown
nothing published · recorded as asserted
Incorporation country mandates retentionC10_company_under_mandate
no
Aopera.comAsec.gov30 Aug 2026
Report a problem with C10_company_under_mandateBeneficial owner sits under a retention regimeC11_owner_under_mandate
yes
Asec.gov30 Aug 2026
Report a problem with C11_owner_under_mandateResponse to a national logging mandatealso read by ignoranceP04_mandate_response
unknown
nothing published · recorded as asserted
Secret-order regime in the incorporation countryP11_gag_order_regime
judicial_only
Bsecurity.opera.com30 Aug 2026
Report a problem with P11_gag_order_regimePriced from what is missing: 0.77 of the weighted record is established, on a slope of 0.9 under a cap of 0.6, with a posture of 0.7 relieved by 0.4.
Record completenessS08_completeness
77%
derived from the record itself
Response to a national logging mandatealso read by jurisdictionP04_mandate_response
unknown
nothing published · recorded as asserted
Transparency reportalso read by integrity, silenceP05_transparency_report
fresh_with_numbers
Asecurity.opera.com30 Aug 2026
Report a problem with P05_transparency_reportReported numbers plausible for this scalealso read by integrityP06_report_plausibility
plausible
Bsecurity.opera.comBsec.gov30 Aug 2026
Report a problem with P06_report_plausibilityWarrant canary disciplinealso read by disclosureP07_warrant_canary
none
Bsecurity.opera.com30 Aug 2026
Report a problem with P07_warrant_canarySecurity incident and how it was disclosedalso read by integrityX09_incident_handling
self_disclosed_prompt
Ablogs.opera.comAblogs.opera.com30 Aug 2026
Report a problem with X09_incident_handlingA capped sum — the one channel that adds: 0.148 of a possible 0.28, from the fields marked below.
RAM-only diskless serversC02_ram_only
unknown+0.018
nothing published · recorded as asserted
IP allocation modelC03_ip_sharing
shared
Bopera.comBhelp.opera.com30 Aug 2026
Report a problem with C03_ip_sharingSignup without emailC04_signup_no_email
yes_declared+0.005
Ablogs.opera.comAblogs.opera.com30 Aug 2026
Report a problem with C04_signup_no_emailAnonymous payment optionsC05_payment_anonymous
not_sold
Bopera.comBblogs.opera.com30 Aug 2026
Report a problem with C05_payment_anonymousOwn DNS inside the tunnelC06_own_dns_in_tunnel
unknown+0.012
nothing published · recorded as asserted
Worst third-party SDK category in the appC07a_app_sdk
ads+0.040
Aplay.google.com30 Aug 2026
Report a problem with C07a_app_sdkWorst third-party tracker category on the siteC07b_site_trackers
analytics+0.010
Bopera.com30 Aug 2026
Report a problem with C07b_site_trackersWho owns the hardwareC08_servers_ownership
unknown+0.009
nothing published · recorded as asserted
Weakest protocol still offeredC13_weakest_protocol
unknown
nothing published · recorded as asserted
Client source code publishedV12_client_open_source
none+0.040
Asec.gov30 Aug 2026
Report a problem with V12_client_open_sourceReproducible buildsV13_reproducible_builds
unknown+0.014
nothing published · recorded as asserted
Separate client or infrastructure pentestV14_pentest_exists
yes_verified
Acure53.de30 Aug 2026
Report a problem with V14_pentest_existsWhat this channel priced on this record:Price 0.05
Who operates the exitC00_architecture
provider_operated+0.000
Ablogs.opera.comAblogs.opera.com30 Aug 2026
Report a problem with C00_architectureWhat the exit does to passing trafficC14_traffic_modification
unknown+0.050
nothing published · recorded as asserted
Server seizure by law enforcementalso read by silenceP01_seizure_event
none_known
Asecurity.opera.comAsec.gov30 Aug 2026
Report a problem with P01_seizure_eventActual disclosure historyP02_disclosure_history
none_known
Asecurity.opera.com30 Aug 2026
Report a problem with P02_disclosure_historyCourt record of compelled productionalso read by silenceP03_court_record
none_known
Asecurity.opera.comAsec.gov30 Aug 2026
Report a problem with P03_court_recordWarrant canary disciplinealso read by ignoranceP07_warrant_canary
none
Bsecurity.opera.com30 Aug 2026
Report a problem with P07_warrant_canaryRequests received in periodP08_requests_received
20
Asecurity.opera.com30 Aug 2026
Report a problem with P08_requests_receivedRequests where data was providedP09_data_provided
0
Asecurity.opera.com30 Aug 2026
Report a problem with P09_data_provided10 years in operation at 0.015 a year under a cap of 0.3, weighted 1.2: the rule did not fire.
Year the service launchedM07_launch_year
2016
Ablogs.opera.com30 Aug 2026
Report a problem with M07_launch_yearUser base scale (mass >=10M, mid >=1M, niche <1M)also read by integrityM08_user_scale
mass
Asec.gov30 Aug 2026
Report a problem with M08_user_scaleServer seizure by law enforcementalso read by disclosureP01_seizure_event
none_known
Asecurity.opera.comAsec.gov30 Aug 2026
Report a problem with P01_seizure_eventCourt record of compelled productionalso read by disclosureP03_court_record
none_known
Asecurity.opera.comAsec.gov30 Aug 2026
Report a problem with P03_court_recordTransparency reportalso read by integrity, ignoranceP05_transparency_report
fresh_with_numbers
Asecurity.opera.com30 Aug 2026
Report a problem with P05_transparency_report