ExpressVPN / Perfect Privacy compared

Same criteria, same rules. You see where they diverge.
No winner on this page. vpn-matrix.com assigns no points and makes no recommendations.

Differences (97)

Criteria where the values diverge.

 ExpressVPNPerfect Privacy
Legal company name
Express Technologies Ltd.provider claim
CyberDock IT Solutions GmbHconfirmed
Trademark holder, if different
Kape Technologies family (joined Kape)provider claim
CyberDock IT Solutions GmbH / Perfect Privacy brandprovider claim
Year founded
2009provider claim
2008provider claim
Headquarters (country)
VGprovider claim
DEconfirmed
Other relevant jurisdictions
Britische Jungferninseln (Vertragspartner und Gerichtsstand laut Nutzungsbedingungen), Vereinigtes Königreich (Mutterkonzern Kape Technologies mit Sitz in London)provider claim
DE (Hamburg HRB 152750)confirmed
Intelligence alliance of the home country
noneconfirmed
14 Eyesconfirmed
Parent group / holding
Kape Technologiesconfirmed
CyberDock IT Solutions GmbH (Hamburg)provider claim
Beneficial owners publicly known
fully knownconfirmed
partly knownprovider claim
Ownership structure
private equityconfirmed
owners undisclosedprovider claim
Leadership team publicly named
noprovider claim
yesprovider claim
Verifiable postal address for legal service
noprovider claim
yesprovider claim
Sister VPN brands in the group
Private Internet Access, CyberGhost VPNconfirmed
none documentedprovider claim
Group owns VPN review and comparison sites
Der Konzern übernahm im März 2021 Webselenese, den Betreiber der VPN-Vergleichsseiten vpnMentor und Wizcase, Kaufpreis 149,1 Millionen US-Dollar. Webselenese wird auf der Konzernseite als Marke geführt.confirmed
none documentedprovider claim
YouTube and influencer sponsoring
occasionalprovider claim
unknownprovider claim
Acquisition history / former name
2018 Umbenennung des Adware-Entwicklers Crossrider in Kape Technologies. 13.09.2021 Übernahme von ExpressVPN durch Kape für 936 Millionen US-Dollar. 26.04.2023 Übernahmeangebot von Unikmind Holdings für unbedingt erklärt, Streichung von der Londoner AIM zum 31.05.2023 angekündigt.confirmed
Originally Switzerland-based (from 2008); later operated by CyberDock IT Solutions GmbH in Hamburg, Germany; technical entity claimed as Webinvest International SA (Panama)provider claim
Operating status
activeconfirmed
discontinuedconfirmed
Discontinuation date?
01/30/2026provider claim
Core statement of the logging policy
Laut Datenschutzerklärung werden keine Aktivitätslogs (Browserverlauf, Zielserver, Inhalte, DNS-Anfragen) und keine Verbindungslogs (IP-Adresse, ausgehende VPN-IP, Verbindungszeitpunkt, Sitzungsdauer) gespeichert. Erhoben werden der Tag eines erfolgreichen Verbindungsaufbaus ohne Uhrzeit, der gewählte Standort und die Summe des je Konto übertragenen Datenvolumens.provider claim
No user traffic logs; no IP addresses, access times/duration, or per-user bandwidth stored; account holds login, expiry, emailconfirmed
Precision of stored timestamps
coarse (date only)provider claim
noneconfirmed
Recording of transferred data volume
per accountprovider claim
aggregate onlyconfirmed
Enforcement of the device limit
10–14 simultaneous connections depending on plan tierprovider claim
Unlimited simultaneous connections (vendor claim; mirrored in reviews)provider claim
Minimum account data required
Name, E-Mail-Adresse und Zahlungsdaten bei Anlage eines Kontos laut Datenschutzerklärung.provider claim
username/password, account expiry, emailconfirmed
Telemetry in the apps
opt inprovider claim
noneprovider claim
Trackers and SDKs in the Android app
AppsFlyer (attribution; advertising IDs with consent); additional analytics platforms referenced for marketingconfirmed
None — vendor claimed in-house development without third parties (Wayback home)provider claim
Trackers in the iOS app
AppsFlyer (attribution; IDFA with consent); Sentry and platform crash reporters discussed for appsconfirmed
No iOS app (CyberInsider con); N/A for first-party iOS SDKsprovider claim
Trackers and cookies on the website
Privacy policy discloses marketing/analytics cookies on websiteprovider claim
Google Analytics with anonymizeIp; advertising cookies disclosedprovider claim
Data shared with third parties
Die Richtlinie nennt Dienstleister für Zahlungsabwicklung und Betrieb der Dienste sowie Marketingpartner für die Zuordnung von Werbekontakten. Die Empfänger werden nicht einzeln aufgezählt.provider claim
Payment processors (Paymentwall, PayPal, Stripe, Bitcoin processors); Google Analytics on website with anonymized IPprovider claim
Retention periods stated in the policy
Keine allgemeine Frist genannt, die Richtlinie spricht von einem begrenzten Zeitraum nach geltendem Datenschutzrecht. Für transaktionsbezogene Kommunikation nennt sie zehn Jahre.provider claim
VPN: no connection data retained; account credentials/email/expiry retained for billing/supportprovider claim
Independent no-logs audit
yesconfirmed
noprovider claim
No-logs audit details
KPMG LLP, Prüfung nach ISAE (UK) 3000 Type 1 zum Stichtag 28.02.2025. Geprüft wurden die TrustedServer-Architektur und die Logging-Aussagen der Datenschutzerklärung anhand von Dokumentenprüfung, Systembeobachtung und Interviews. Type 1 bewertet die Ausgestaltung der Kontrollen zu einem Stichtag, nicht ihre Wirksamkeit über einen Zeitraum, und umfasste keine vollständige Sicherheitsanalyse.confirmed
No-logs policy described as involuntarily tested via police server seizures (notably 2016 Golem/heise reporting); vendor claimed regular internal/external audits on Wayback homepageprovider claim
Audit report published
full reportconfirmed
not publishedprovider claim
App and client audits
Cure53 veröffentlichte Berichte zur Browser-Erweiterung (10.-11.2018 und 09.-10.2022), zu ExpressVPN Keys (09.-10.2022), zum iOS-Client (08.-09.2022), zum Android-Client (08.2022), zum macOS-Client (06.-07.2022) und zu den Linux-Clients (07.-08.2022).confirmed
Vendor claimed regular internal/external audits on Wayback homepage; no named app-audit firm/report URL foundprovider claim
Infrastructure and server audits
Cure53 prüfte TrustedServer im Zeitraum 04.-05.2022 sowie die Router-Firmware Aircove 06.-07.2022 und 11.2024. Der Anbieter nennt zusätzlich eine Prüfung von TrustedServer durch PwC.confirmed
No public infra audit report found; involuntary 2016 seizure treated as practical no-logs test in secondary sourcesprovider claim
Audit frequency
annualconfirmed
irregularprovider claim
Tested in court or by authorities
Im Januar 2017 beschlagnahmten türkische Behörden im Ermittlungsverfahren zur Ermordung des russischen Botschafters Andrej Karlow einen von ExpressVPN genutzten Server. Nach dem Bericht konnten die Ermittler daraus keine Nutzerdaten gewinnen, der Anbieter erklärte, keine Verbindungs- oder Aktivitätslogs zu besitzen. ExpressVPN stellte danach den Betrieb physischer Server in der Türkei ein und liefert türkische IP-Adressen über Server in den Niederlanden.confirmed
2016 Netherlands server seizure reported; no customer data recovered (vendor/community narrative on archived pages and reviews)provider claim
Transparency report
regularprovider claim
noneprovider claim
Warrant canary
noneprovider claim
staleprovider claim
Security incidents and data leaks?
Police seizures of VPN hardware/servers reported (heise 2010; Golem 2016); operator framed seizures as validating no-logs (no user data found)confirmed
Bug bounty programme
Öffentliches Programm über die Plattform YesWeHack, alternativ Meldung per E-Mail. Geltungsbereich sind Desktop- und Mobil-Apps, Router und Router-Firmware (Aircove), Browser-Erweiterungen, Backend-Systeme und die VPN-Server mit TrustedServer-Technik. Für den ersten Nachweis eines unberechtigten Serverzugriffs, einer Codeausführung, eines IP-Lecks oder einer Einsicht in unverschlüsselten Verkehr auf TrustedServer ist ein einmaliger Bonus von 100.000 US-Dollar ausgelobt.provider claim
?
Handling of reported vulnerabilities
Eigenes Vulnerability Disclosure Program mit zugesagtem Safe Harbor für Sicherheitsforschung im Rahmen der Richtlinie. Meldungen können anonym und ohne Prämie eingereicht werden.provider claim
?
Listings by independent bodies
Public audits by PwC, Cure53, KPMG linked from features/trust messagingprovider claim
Historically recommended in privacy community reviews; CyberInsider and SafetyDetectives reviewed it; recommendations withdrawn after Jan 2026 shutdownprovider claim
WireGuard
yesprovider claim
noprovider claim
Proprietary protocol
Lightway. Der Quellcode ist veröffentlicht (Lightway Core in C unter GPL-2.0, laut Repository nicht mehr aktiv entwickelt, sowie die aktive Neuimplementierung Lightway in Rust unter AGPL-3.0). Cure53 prüfte die Rust-Implementierung und die WolfSSL-RS-Anbindung im Oktober und November 2024 und meldete fünf Feststellungen, davon eine als Sicherheitslücke eingestufte Denial-of-Service-Schwachstelle der Stufe High.confirmed
Stealth VPN (DPI obfuscation wrapping VPN to look like HTTPS)provider claim
Legacy protocols still offered
PPTP und SSTP werden laut Anbieter in den ExpressVPN-Apps nicht mehr unterstützt.provider claim
SSH2 tunnelprovider claim
Default data cipher
AES-256 nach Anbieterangabe, der Betriebsmodus wird nicht dokumentiert.provider claim
AES-256 (OpenVPN)provider claim
Weakest accepted cipher
AES-256 (no weaker cipher advertised)provider claim
AES-256provider claim
Key exchange and authentication
Lightway protocol handshake (plus OpenVPN/IKEv2 options historically)provider claim
OpenVPN / IPsec industry standards (details not fully specified on feature pages)provider claim
Post-quantum key exchange
on by defaultprovider claim
not availableprovider claim
IPv6 handling
unclearprovider claim
routed through tunnelprovider claim
Obfuscation methods
Laut Anbieter automatische Verschleierung auf jedem Server, die ohne Zutun greift, wenn ein Netz VPN-Verkehr blockiert. Das Verfahren wird nicht dokumentiert.provider claim
Stealth VPN (HTTPS-like masking against DPI)provider claim
Usability behind the Great Firewall
per user reportsprovider claim
unclearprovider claim
Permanent lockdown
yesprovider claim
noprovider claim
Split tunneling
Windows und macOS nach Anwendung und nach Website, Linux nach Anwendung, IP-Adresse oder Subnetz, Android ab 7.0 nach Anwendung. Unter iOS nur Ausschluss einzelner IPv4-Adressen, keine Auswahl nach Anwendung.provider claim
yes (app split-tunneling per SafetyDetectives review of the service)provider claim
Multihop
not availableprovider claim
freely combinableprovider claim
Port forwarding
not availableprovider claim
availableprovider claim
SOCKS5 proxy
noprovider claim
yesprovider claim
HTTP proxy
noprovider claim
yesprovider claim
Smart DNS
yesprovider claim
noprovider claim
Custom DNS servers allowed
noprovider claim
yesprovider claim
Traffic analysis defence
Automatic obfuscation on every server; Lightway protocolprovider claim
Stealth VPN Technology / NeuroRouting historically offeredprovider claim
IPv6 inside the tunnel
noprovider claim
yesprovider claim
Number of servers?
55 Serverprovider claim
Number of countries
113 Laenderprovider claim
23 Laenderprovider claim
Number of cities
214 Staedteprovider claim
35 Staedteprovider claim
Virtual locations
labelledprovider claim
no virtual locationsprovider claim
Hardware ownership
mixedprovider claim
colocationprovider claim
Own AS (autonomous system)?
noprovider claim
Public status page
noprovider claim
yesprovider claim
Known upstream hosting providers
Not individually listed on server-locations page; markets servers in 113 countriesprovider claim
100% dedicated bare-metal / root servers (no cloud VPS); operators not individually named on fetched pagesprovider claim
Linux command line
native appprovider claim
manual config onlyprovider claim
Android TV app
native appprovider claim
not availableprovider claim
Apple TV app
native appprovider claim
not availableprovider claim
Fire TV app
native appprovider claim
not availableprovider claim
Browser extension
own extensionprovider claim
not availableprovider claim
Type of browser extension
standalone browser proxyprovider claim
no extensionprovider claim
Router support
Kein eigenes Router-Programm und keine eigene Router-Firmware mehr, der Anbieter nennt einen app-first-Ansatz und verweist auf routereigene VPN-Funktionen sowie auf DD-WRT oder OpenWrt. Der eigene Router Aircove wird weiterhin geführt.provider claim
VPN Routers documentation linked in footerprovider claim
Simultaneous devices
Bis zu 14 Geräte gleichzeitig, abhängig vom gebuchten Tarif.provider claim
unlimited / personal multi-device use allowed; no sharing credentialsprovider claim
Cash by mail
noprovider claim
yesprovider claim
Retail gift cards
noprovider claim
yesprovider claim
SEPA payment
noprovider claim
yesprovider claim
Monthly price?
€12.99provider claim
Effective price on the longest term
€2.99provider claim
€8.95provider claim
Price change at renewal
very large increaseprovider claim
same priceprovider claim
Money-back window
30 Tageprovider claim
7 Tageprovider claim
Streaming unblocking officially advertised
yesprovider claim
noprovider claim
Netflix regions reported?
Poor / largely incompatible with Netflix and Disney+ per CyberInsider testing notesprovider claim
Other streaming services
Markets HD/4K streaming on 10G/40G servers; Netflix not region-audited on fetched pagesprovider claim
CyberInsider: does not work well with streaming sites such as Netflix and Disney Plusprovider claim
Data cap
Kein monatliches Datenlimit und keine eigene Bandbreitenbegrenzung nach Anbieterangabe.provider claim
noneprovider claim
SMTP and port 25 handling?
Not documented on fetched Wayback/review pagesprovider claim
Official support in restrictive countries
Automatic obfuscation marketed for restrictive networksprovider claim
?
24/7 live chat
yesprovider claim
noprovider claim
Documentation assessment
thorough and currentprovider claim
workableprovider claim
SSL Labs grade of the website
A+confirmed
?
Tracker load of the website
Privacy policy covers website cookies/trackersprovider claim
Privacy policy covered website cookies historicallyprovider claim
URL of the warrant canary
none foundprovider claim
Historical warrant canary page (service discontinued)provider claim
Length and readability of the legal documents
Standard corporate legal pagesprovider claim
Technical privacy-focused documentation historicallyprovider claim
Marketing claims contradicting the provider's own terms
Markets as World's #1 VPN with intro $2.99/mo on multi-year Basic; servers in 113 countries on server-locations pageprovider claim
Discontinued service — historical claims onlyprovider claim

All sourced criteria (152)

 ExpressVPNPerfect Privacy
Legal company name
Express Technologies Ltd.provider claim
CyberDock IT Solutions GmbHconfirmed
Trademark holder, if different
Kape Technologies family (joined Kape)provider claim
CyberDock IT Solutions GmbH / Perfect Privacy brandprovider claim
Year founded
2009provider claim
2008provider claim
Headquarters (country)
VGprovider claim
DEconfirmed
Other relevant jurisdictions
Britische Jungferninseln (Vertragspartner und Gerichtsstand laut Nutzungsbedingungen), Vereinigtes Königreich (Mutterkonzern Kape Technologies mit Sitz in London)provider claim
DE (Hamburg HRB 152750)confirmed
Intelligence alliance of the home country
noneconfirmed
14 Eyesconfirmed
Parent group / holding
Kape Technologiesconfirmed
CyberDock IT Solutions GmbH (Hamburg)provider claim
Beneficial owners publicly known
fully knownconfirmed
partly knownprovider claim
Ownership structure
private equityconfirmed
owners undisclosedprovider claim
Leadership team publicly named
noprovider claim
yesprovider claim
Verifiable postal address for legal service
noprovider claim
yesprovider claim
Sister VPN brands in the group
Private Internet Access, CyberGhost VPNconfirmed
none documentedprovider claim
Group owns VPN review and comparison sites
Der Konzern übernahm im März 2021 Webselenese, den Betreiber der VPN-Vergleichsseiten vpnMentor und Wizcase, Kaufpreis 149,1 Millionen US-Dollar. Webselenese wird auf der Konzernseite als Marke geführt.confirmed
none documentedprovider claim
Runs an affiliate programme
yesprovider claim
yesprovider claim
YouTube and influencer sponsoring
occasionalprovider claim
unknownprovider claim
Acquisition history / former name
2018 Umbenennung des Adware-Entwicklers Crossrider in Kape Technologies. 13.09.2021 Übernahme von ExpressVPN durch Kape für 936 Millionen US-Dollar. 26.04.2023 Übernahmeangebot von Unikmind Holdings für unbedingt erklärt, Streichung von der Londoner AIM zum 31.05.2023 angekündigt.confirmed
Originally Switzerland-based (from 2008); later operated by CyberDock IT Solutions GmbH in Hamburg, Germany; technical entity claimed as Webinvest International SA (Panama)provider claim
Operating status
activeconfirmed
discontinuedconfirmed
Discontinuation date?
01/30/2026provider claim
Core statement of the logging policy
Laut Datenschutzerklärung werden keine Aktivitätslogs (Browserverlauf, Zielserver, Inhalte, DNS-Anfragen) und keine Verbindungslogs (IP-Adresse, ausgehende VPN-IP, Verbindungszeitpunkt, Sitzungsdauer) gespeichert. Erhoben werden der Tag eines erfolgreichen Verbindungsaufbaus ohne Uhrzeit, der gewählte Standort und die Summe des je Konto übertragenen Datenvolumens.provider claim
No user traffic logs; no IP addresses, access times/duration, or per-user bandwidth stored; account holds login, expiry, emailconfirmed
Activity and traffic logs
noneprovider claim
noneconfirmed
Connection logs
noneprovider claim
noneconfirmed
Storage of the real IP address
not storedprovider claim
not storedconfirmed
Storage of the assigned VPN IP
not storedprovider claim
not storedprovider claim
Precision of stored timestamps
coarse (date only)provider claim
noneconfirmed
Recording of transferred data volume
per accountprovider claim
aggregate onlyconfirmed
Enforcement of the device limit
10–14 simultaneous connections depending on plan tierprovider claim
Unlimited simultaneous connections (vendor claim; mirrored in reviews)provider claim
Minimum account data required
Name, E-Mail-Adresse und Zahlungsdaten bei Anlage eines Kontos laut Datenschutzerklärung.provider claim
username/password, account expiry, emailconfirmed
Telemetry in the apps
opt inprovider claim
noneprovider claim
Trackers and SDKs in the Android app
AppsFlyer (attribution; advertising IDs with consent); additional analytics platforms referenced for marketingconfirmed
None — vendor claimed in-house development without third parties (Wayback home)provider claim
Trackers in the iOS app
AppsFlyer (attribution; IDFA with consent); Sentry and platform crash reporters discussed for appsconfirmed
No iOS app (CyberInsider con); N/A for first-party iOS SDKsprovider claim
Trackers and cookies on the website
Privacy policy discloses marketing/analytics cookies on websiteprovider claim
Google Analytics with anonymizeIp; advertising cookies disclosedprovider claim
Data shared with third parties
Die Richtlinie nennt Dienstleister für Zahlungsabwicklung und Betrieb der Dienste sowie Marketingpartner für die Zuordnung von Werbekontakten. Die Empfänger werden nicht einzeln aufgezählt.provider claim
Payment processors (Paymentwall, PayPal, Stripe, Bitcoin processors); Google Analytics on website with anonymized IPprovider claim
Retention periods stated in the policy
Keine allgemeine Frist genannt, die Richtlinie spricht von einem begrenzten Zeitraum nach geltendem Datenschutzrecht. Für transaktionsbezogene Kommunikation nennt sie zehn Jahre.provider claim
VPN: no connection data retained; account credentials/email/expiry retained for billing/supportprovider claim
EU representative named under GDPR
yesprovider claim
yesprovider claim
Independent no-logs audit
yesconfirmed
noprovider claim
No-logs audit details
KPMG LLP, Prüfung nach ISAE (UK) 3000 Type 1 zum Stichtag 28.02.2025. Geprüft wurden die TrustedServer-Architektur und die Logging-Aussagen der Datenschutzerklärung anhand von Dokumentenprüfung, Systembeobachtung und Interviews. Type 1 bewertet die Ausgestaltung der Kontrollen zu einem Stichtag, nicht ihre Wirksamkeit über einen Zeitraum, und umfasste keine vollständige Sicherheitsanalyse.confirmed
No-logs policy described as involuntarily tested via police server seizures (notably 2016 Golem/heise reporting); vendor claimed regular internal/external audits on Wayback homepageprovider claim
Audit report published
full reportconfirmed
not publishedprovider claim
App and client audits
Cure53 veröffentlichte Berichte zur Browser-Erweiterung (10.-11.2018 und 09.-10.2022), zu ExpressVPN Keys (09.-10.2022), zum iOS-Client (08.-09.2022), zum Android-Client (08.2022), zum macOS-Client (06.-07.2022) und zu den Linux-Clients (07.-08.2022).confirmed
Vendor claimed regular internal/external audits on Wayback homepage; no named app-audit firm/report URL foundprovider claim
Infrastructure and server audits
Cure53 prüfte TrustedServer im Zeitraum 04.-05.2022 sowie die Router-Firmware Aircove 06.-07.2022 und 11.2024. Der Anbieter nennt zusätzlich eine Prüfung von TrustedServer durch PwC.confirmed
No public infra audit report found; involuntary 2016 seizure treated as practical no-logs test in secondary sourcesprovider claim
Audit frequency
annualconfirmed
irregularprovider claim
Tested in court or by authorities
Im Januar 2017 beschlagnahmten türkische Behörden im Ermittlungsverfahren zur Ermordung des russischen Botschafters Andrej Karlow einen von ExpressVPN genutzten Server. Nach dem Bericht konnten die Ermittler daraus keine Nutzerdaten gewinnen, der Anbieter erklärte, keine Verbindungs- oder Aktivitätslogs zu besitzen. ExpressVPN stellte danach den Betrieb physischer Server in der Türkei ein und liefert türkische IP-Adressen über Server in den Niederlanden.confirmed
2016 Netherlands server seizure reported; no customer data recovered (vendor/community narrative on archived pages and reviews)provider claim
Transparency report
regularprovider claim
noneprovider claim
Warrant canary
noneprovider claim
staleprovider claim
Security incidents and data leaks?
Police seizures of VPN hardware/servers reported (heise 2010; Golem 2016); operator framed seizures as validating no-logs (no user data found)confirmed
Bug bounty programme
Öffentliches Programm über die Plattform YesWeHack, alternativ Meldung per E-Mail. Geltungsbereich sind Desktop- und Mobil-Apps, Router und Router-Firmware (Aircove), Browser-Erweiterungen, Backend-Systeme und die VPN-Server mit TrustedServer-Technik. Für den ersten Nachweis eines unberechtigten Serverzugriffs, einer Codeausführung, eines IP-Lecks oder einer Einsicht in unverschlüsselten Verkehr auf TrustedServer ist ein einmaliger Bonus von 100.000 US-Dollar ausgelobt.provider claim
?
Handling of reported vulnerabilities
Eigenes Vulnerability Disclosure Program mit zugesagtem Safe Harbor für Sicherheitsforschung im Rahmen der Richtlinie. Meldungen können anonym und ohne Prämie eingereicht werden.provider claim
?
Open source clients
someconfirmed
someprovider claim
Open source server side
noprovider claim
noprovider claim
Reproducible builds
noprovider claim
noprovider claim
Available on F-Droid
noprovider claim
noprovider claim
Listings by independent bodies
Public audits by PwC, Cure53, KPMG linked from features/trust messagingprovider claim
Historically recommended in privacy community reviews; CyberInsider and SafetyDetectives reviewed it; recommendations withdrawn after Jan 2026 shutdownprovider claim
WireGuard
yesprovider claim
noprovider claim
OpenVPN over UDP
yesprovider claim
yesprovider claim
OpenVPN over TCP
yesprovider claim
yesprovider claim
IKEv2/IPsec
yesprovider claim
yesprovider claim
Proprietary protocol
Lightway. Der Quellcode ist veröffentlicht (Lightway Core in C unter GPL-2.0, laut Repository nicht mehr aktiv entwickelt, sowie die aktive Neuimplementierung Lightway in Rust unter AGPL-3.0). Cure53 prüfte die Rust-Implementierung und die WolfSSL-RS-Anbindung im Oktober und November 2024 und meldete fünf Feststellungen, davon eine als Sicherheitslücke eingestufte Denial-of-Service-Schwachstelle der Stufe High.confirmed
Stealth VPN (DPI obfuscation wrapping VPN to look like HTTPS)provider claim
Legacy protocols still offered
PPTP und SSTP werden laut Anbieter in den ExpressVPN-Apps nicht mehr unterstützt.provider claim
SSH2 tunnelprovider claim
Default data cipher
AES-256 nach Anbieterangabe, der Betriebsmodus wird nicht dokumentiert.provider claim
AES-256 (OpenVPN)provider claim
Weakest accepted cipher
AES-256 (no weaker cipher advertised)provider claim
AES-256provider claim
Key exchange and authentication
Lightway protocol handshake (plus OpenVPN/IKEv2 options historically)provider claim
OpenVPN / IPsec industry standards (details not fully specified on feature pages)provider claim
Perfect forward secrecy
yesprovider claim
yesprovider claim
Post-quantum key exchange
on by defaultprovider claim
not availableprovider claim
Own DNS resolvers
yesprovider claim
yesprovider claim
DNS leak protection
yesprovider claim
yesprovider claim
IPv6 handling
unclearprovider claim
routed through tunnelprovider claim
WebRTC protection or guidance
yesprovider claim
yesprovider claim
Obfuscation methods
Laut Anbieter automatische Verschleierung auf jedem Server, die ohne Zutun greift, wenn ein Netz VPN-Verkehr blockiert. Das Verfahren wird nicht dokumentiert.provider claim
Stealth VPN (HTTPS-like masking against DPI)provider claim
Usability behind the Great Firewall
per user reportsprovider claim
unclearprovider claim
Kill switch
system-wideprovider claim
system-wideprovider claim
Permanent lockdown
yesprovider claim
noprovider claim
Split tunneling
Windows und macOS nach Anwendung und nach Website, Linux nach Anwendung, IP-Adresse oder Subnetz, Android ab 7.0 nach Anwendung. Unter iOS nur Ausschluss einzelner IPv4-Adressen, keine Auswahl nach Anwendung.provider claim
yes (app split-tunneling per SafetyDetectives review of the service)provider claim
Multihop
not availableprovider claim
freely combinableprovider claim
Tor integration (Onion over VPN)
noprovider claim
noprovider claim
Port forwarding
not availableprovider claim
availableprovider claim
SOCKS5 proxy
noprovider claim
yesprovider claim
HTTP proxy
noprovider claim
yesprovider claim
Smart DNS
yesprovider claim
noprovider claim
Ad and tracker filtering in DNS
configurableprovider claim
configurableprovider claim
Malware and phishing filter
yesprovider claim
yesprovider claim
Custom DNS servers allowed
noprovider claim
yesprovider claim
Local network access toggle
yesprovider claim
yesprovider claim
Auto connect rules
yesprovider claim
yesprovider claim
Private device network (mesh)
noprovider claim
noprovider claim
GPS location override (Android)
noprovider claim
noprovider claim
Traffic analysis defence
Automatic obfuscation on every server; Lightway protocolprovider claim
Stealth VPN Technology / NeuroRouting historically offeredprovider claim
IPv6 inside the tunnel
noprovider claim
yesprovider claim
Obfuscation without configuration
noprovider claim
noprovider claim
Number of servers?
55 Serverprovider claim
Number of countries
113 Laenderprovider claim
23 Laenderprovider claim
Number of cities
214 Staedteprovider claim
35 Staedteprovider claim
Virtual locations
labelledprovider claim
no virtual locationsprovider claim
RAM-only servers (diskless)
entire networkprovider claim
entire networkprovider claim
Hardware ownership
mixedprovider claim
colocationprovider claim
Own AS (autonomous system)?
noprovider claim
10 Gbps ports
some serversprovider claim
some serversprovider claim
P2P and file sharing
entire networkprovider claim
entire networkprovider claim
Public server list
yesprovider claim
yesprovider claim
Public status page
noprovider claim
yesprovider claim
Known upstream hosting providers
Not individually listed on server-locations page; markets servers in 113 countriesprovider claim
100% dedicated bare-metal / root servers (no cloud VPS); operators not individually named on fetched pagesprovider claim
Windows app
native appprovider claim
native appprovider claim
macOS app
native appprovider claim
native appprovider claim
Linux app with GUI
native appprovider claim
native appprovider claim
Linux command line
native appprovider claim
manual config onlyprovider claim
Android app
native appprovider claim
native appprovider claim
iOS app
native appprovider claim
native appprovider claim
Android TV app
native appprovider claim
not availableprovider claim
Apple TV app
native appprovider claim
not availableprovider claim
Fire TV app
native appprovider claim
not availableprovider claim
Browser extension
own extensionprovider claim
not availableprovider claim
Type of browser extension
standalone browser proxyprovider claim
no extensionprovider claim
Router support
Kein eigenes Router-Programm und keine eigene Router-Firmware mehr, der Anbieter nennt einen app-first-Ansatz und verweist auf routereigene VPN-Funktionen sowie auf DD-WRT oder OpenWrt. Der eigene Router Aircove wird weiterhin geführt.provider claim
VPN Routers documentation linked in footerprovider claim
Native build for Apple Silicon
yesprovider claim
yesprovider claim
Command line documented
yesprovider claim
yesprovider claim
Simultaneous devices
Bis zu 14 Geräte gleichzeitig, abhängig vom gebuchten Tarif.provider claim
unlimited / personal multi-device use allowed; no sharing credentialsprovider claim
Usable without an account
noprovider claim
noprovider claim
Data required at signup
any email addressprovider claim
any email addressprovider claim
Account model
email as loginprovider claim
email as loginprovider claim
Cash by mail
noprovider claim
yesprovider claim
Monero
noprovider claim
noprovider claim
Bitcoin
yesprovider claim
yesprovider claim
Lightning
noprovider claim
noprovider claim
Retail gift cards
noprovider claim
yesprovider claim
PayPal
yesprovider claim
yesprovider claim
Credit and debit card
yesprovider claim
yesprovider claim
SEPA payment
noprovider claim
yesprovider claim
Monthly price?
€12.99provider claim
Effective price on the longest term
€2.99provider claim
€8.95provider claim
Price change at renewal
very large increaseprovider claim
same priceprovider claim
Flat pricing without permanent discounts
noprovider claim
noprovider claim
Free tier and its limits
noneprovider claim
noneprovider claim
Money-back window
30 Tageprovider claim
7 Tageprovider claim
Cancellation path
cancel in accountprovider claim
cancel in accountprovider claim
P2P policy in the terms of service
entire networkprovider claim
entire networkprovider claim
Streaming unblocking officially advertised
yesprovider claim
noprovider claim
Netflix regions reported?
Poor / largely incompatible with Netflix and Disney+ per CyberInsider testing notesprovider claim
Other streaming services
Markets HD/4K streaming on 10G/40G servers; Netflix not region-audited on fetched pagesprovider claim
CyberInsider: does not work well with streaming sites such as Netflix and Disney Plusprovider claim
Bandwidth cap
no limitprovider claim
no limitprovider claim
Data cap
Kein monatliches Datenlimit und keine eigene Bandbreitenbegrenzung nach Anbieterangabe.provider claim
noneprovider claim
SMTP and port 25 handling?
Not documented on fetched Wayback/review pagesprovider claim
Official support in restrictive countries
Automatic obfuscation marketed for restrictive networksprovider claim
?
24/7 live chat
yesprovider claim
noprovider claim
Email or ticket support
yesprovider claim
yesconfirmed
Telephone support
noprovider claim
noprovider claim
German-language support
yesprovider claim
yesprovider claim
Documentation assessment
thorough and currentprovider claim
workableprovider claim
Self-hosted chat widget
noprovider claim
noprovider claim
Self-service account deletion
yesprovider claim
yesprovider claim
SSL Labs grade of the website
A+confirmed
?
Tracker load of the website
Privacy policy covers website cookies/trackersprovider claim
Privacy policy covered website cookies historicallyprovider claim
URL of the warrant canary
none foundprovider claim
Historical warrant canary page (service discontinued)provider claim
Length and readability of the legal documents
Standard corporate legal pagesprovider claim
Technical privacy-focused documentation historicallyprovider claim
Marketing claims contradicting the provider's own terms
Markets as World's #1 VPN with intro $2.99/mo on multi-year Basic; servers in 113 countries on server-locations pageprovider claim
Discontinued service — historical claims onlyprovider claim