VPNs with open source clients

Providers whose applications are published as source code, fully or in part.

21 of 85 providers in the dataset

What this filter checks

A single catalogue criterion is checked. Providers whose clients are fully open source are included, as are those where part is open, for instance the desktop client but not the phone app. Providers without published source code drop out.

Open source first of all only means the source code can be read. It does not mean the file shipped through the app store was built from exactly that source. A different criterion answers that question, namely reproducible builds. Anyone looking for both combines the two rows in the matrix.

The levels confirmed and provider claim count for inclusion. A provider claim suffices here because in the case of open source it is easy to check: a repository is either public or it is not. Where we have looked at the repository ourselves, the level is confirmed.

The rule lives in the source code and is only read out here. It is a condition on catalogue criteria, nothing more.

All of the following conditions must hold.

  • Open source clients has the value all or some

    trust.opensource_clients

    Whether the source code of the apps can be inspected. Open code makes independent review possible, but it does not prove that the binary in the app store was built from exactly that code; only reproducible builds show this. Some means, for instance, that the desktop client is open while the mobile app is not.

Which level of evidence counts

For this filter the levels confirmed and provider claim count. Disputed and unsourced cells drop out. Confidence levels in detail

Not a ranking. The page lists providers for whom a statement is sourced. If someone is missing, it may be missing evidence, not the property.

Providers with evidence for this

Sorted alphabetically, as everywhere on this site. There is no order by quality.