NordVPN

145 of 158 criteria sourced · 8 % unsourcedProvider websiteView in the matrixJSON export

vpn-matrix.com earns nothing from this entry. The link to the provider website is a source, not a recommendation.

Who owns this

Parent company

Nord Security

Brands in the same group

Further brands according to the source: NordLayer (Geschäftskunden-VPN von Nord Security), Surfshark (seit dem Zusammenschluss vom 01.02.2022 in derselben Unternehmensgruppe)

This group also owns review and comparison sites

none disclosed on about page

If the same group tests its own service, that review is not independent. That is noted here as ownership only.

Audits and incidents

Sourced facts with dates only, no judgements. Ongoing proceedings are marked as such.

Security incidents and data leaks

trust.breach_history

Im März 2018 wurde ein von NordVPN in einem finnischen Rechenzentrum gemieteter Server über ein unsicheres Fernwartungssystem des Rechenzentrumsbetreibers kompromittiert. Offengelegt wurde ein abgelaufener interner privater Schlüssel. NordVPN erklärte, der Server habe keine Aktivitätsprotokolle enthalten und Zugangsdaten seien nicht abgreifbar gewesen. Der Vorfall wurde am 21.10.2019 öffentlich bestätigt.confirmed

No-logs audit details

trust.nolog_audit_details

Fünfte Prüfung durch Deloitte Audit Lithuania nach ISAE 3000 (Revised), durchgeführt vom 18.11. bis 20.12.2024, Bericht vom 18.02.2025. Geprüft wurden nach Anbieterangabe IT-Systeme, unterstützende Infrastruktur und die No-Logs-Politik, darunter Standard-, Double-VPN-, Onion-over-VPN-, verschleierte und P2P-Server.provider claim

App and client audits

trust.app_audits

Cure53 prüfte 2024 mit elf Testern über 55 Tage die Mobil-, Desktop- und Browser-Anwendungen sowie Threat Protection und Meshnet. Berichtet wurden 31 Feststellungen, davon vier mit hoher Schwere; die Behebung wurde nach diesem Bericht von Cure53 nachgeprüft.confirmed

Infrastructure and server audits

trust.infra_audit

Cure53 prüfte laut Mitteilung vom 02.03.2023 im September und Oktober 2022 Infrastruktur und Server, im Juli und August 2022 Apps und Erweiterungen. Der Prüfumfang umfasste nach dieser Mitteilung auch Websites, mehrere APIs, Nord Account, Nord Checkout, Nord UCP, VPN-Server und den serverseitigen NordLynx-Code.provider claim

Transparency report

trust.transparency_report

noneprovider claim

Warrant canary

trust.warrant_canary

noneprovider claim

Acquisition history / former name

company.acquisition_history

Am 01.02.2022 gaben Surfshark und Nord Security ihren Zusammenschluss bekannt; beide Unternehmen erklärten, weiterhin als eigenständige Firmen mit getrennter Infrastruktur zu arbeiten. Im April 2022 nahm Nord Security erstmals externes Kapital auf.confirmed

Marketing claims contradicting the provider's own terms

site.claims_vs_reality

Home/features market Dedicated IP and 224+ locations; privacy acknowledges personal data processing with third partiesprovider claim

All criteria

Empty cells mean we lack the source.

Company and ownership

17/21 sourced

Legal company name

company.legal_name

nordvpn S.A.confirmed

Trademark holder, if different

company.brand_owner

Nord Security (Cyberspace B.V. / Nordsec); service incorporated in Panamaconfirmed

Year founded

company.founded

2012provider claim

Headquarters (country)

company.hq_country

LTconfirmed

Other relevant jurisdictions

company.jurisdictions

Panama (nordvpn S.A.); parent Nord Security headquartered in Lithuania; offices also UK, Netherlands, Poland, Germany, Switzerlandconfirmed

Intelligence alliance of the home country

company.eyes_alliance

noneconfirmed

Parent group / holding

company.parent

Nord Securityconfirmed

Beneficial owners publicly known

company.ubo_public

partly knownprovider claim

Ownership structure

company.ownership_type

private equityconfirmed

Leadership team publicly named

company.team_public

yesprovider claim

Verifiable postal address for legal service

company.address_verifiable

yesconfirmed

Sister VPN brands in the group

company.sister_vpn_brands

NordLayer (Geschäftskunden-VPN von Nord Security), Surfshark (seit dem Zusammenschluss vom 01.02.2022 in derselben Unternehmensgruppe)provider claim

Group owns VPN review and comparison sites

company.owns_review_sites

none disclosed on about pageprovider claim

Runs an affiliate programme

company.affiliate_program

yesprovider claim

Typical commission rate

company.affiliate_commission

We have no source for this criterion.

YouTube and influencer sponsoring

company.influencer_sponsoring

occasionalprovider claim

Documented misleading advertising claims

company.misleading_claims

We have no source for this criterion.

Acquisition history / former name

company.acquisition_history

Am 01.02.2022 gaben Surfshark und Nord Security ihren Zusammenschluss bekannt; beide Unternehmen erklärten, weiterhin als eigenständige Firmen mit getrennter Infrastruktur zu arbeiten. Im April 2022 nahm Nord Security erstmals externes Kapital auf.confirmed

Operating status

company.status

activeconfirmed

Discontinuation date

company.discontinued_date

We have no source for this criterion.

User base migrated to

company.user_base_migrated_to

We have no source for this criterion.

Logging and data collection

16/16 sourced

Core statement of the logging policy

logging.policy_summary

Der Anbieter erklärt eine No-Logs-Politik: Es würden keine Aufzeichnungen darüber geführt, was Nutzende aufrufen, wann sie sich verbinden oder welche personenbezogenen Daten während der Nutzung anfallen. Als gespeicherte Daten nennt der Support verschlüsselte Zugangsdaten, die E-Mail-Adresse, einen Benutzernamen für den VPN-Aufbau sowie Zahlungs- und Abrechnungsdaten für Erstattungen.provider claim

Activity and traffic logs

logging.activity_logs

noneprovider claim

Connection logs

logging.connection_logs

noneprovider claim

Storage of the real IP address

logging.source_ip_stored

not storedprovider claim

Storage of the assigned VPN IP

logging.assigned_ip_stored

not storedprovider claim

Precision of stored timestamps

logging.timestamps_stored

noneprovider claim

Recording of transferred data volume

logging.bandwidth_logged

not recordedprovider claim

Enforcement of the device limit

logging.concurrent_conn_enforcement

Plan-dependent device limits on pricing table; Dedicated IP add-on at checkoutprovider claim

Minimum account data required

logging.account_data_minimum

Nach Support-Angabe verschlüsselte Zugangsdaten, die E-Mail-Adresse, ein Benutzername für den VPN-Aufbau sowie Zahlungsdaten; von den Zahlungsdaten wird die Transaktions- oder Bestellnummer für Erstattungen gespeichert. Für das Nord Account sind E-Mail-Adresse und Passwort nötig.provider claim

Telemetry in the apps

logging.app_telemetry

cannot be disabledprovider claim

Trackers and SDKs in the Android app

logging.thirdparty_sdks_android

Third-party processors named in privacy policy include analytics/marketing vendors (e.g. Google Analytics ecosystem and others listed under recipients)provider claim

Trackers in the iOS app

logging.thirdparty_sdks_ios

Third-party processors named in privacy policy include analytics/marketing vendors listed under recipientsprovider claim

Trackers and cookies on the website

logging.website_trackers

Website cookies for advertising/analytics; Cookie Policy linkedprovider claim

Data shared with third parties

logging.data_shared_with

Service providers (support, payments e.g. Stripe/Adyen/PayPal/Coingate); law enforcement only with valid Panama process; no VPN activity logs to shareprovider claim

Retention periods stated in the policy

logging.retention_period

Account/billing data retained as needed for service; VPN activity not logged per no-logs articleprovider claim

EU representative named under GDPR

logging.gdpr_representative

yesprovider claim

Evidence, audits and track record

16/17 sourced

Independent no-logs audit

trust.nolog_audit

yesprovider claim

No-logs audit details

trust.nolog_audit_details

Fünfte Prüfung durch Deloitte Audit Lithuania nach ISAE 3000 (Revised), durchgeführt vom 18.11. bis 20.12.2024, Bericht vom 18.02.2025. Geprüft wurden nach Anbieterangabe IT-Systeme, unterstützende Infrastruktur und die No-Logs-Politik, darunter Standard-, Double-VPN-, Onion-over-VPN-, verschleierte und P2P-Server.provider claim

Audit report published

trust.audit_report_public

not publishedprovider claim

App and client audits

trust.app_audits

Cure53 prüfte 2024 mit elf Testern über 55 Tage die Mobil-, Desktop- und Browser-Anwendungen sowie Threat Protection und Meshnet. Berichtet wurden 31 Feststellungen, davon vier mit hoher Schwere; die Behebung wurde nach diesem Bericht von Cure53 nachgeprüft.confirmed

Infrastructure and server audits

trust.infra_audit

Cure53 prüfte laut Mitteilung vom 02.03.2023 im September und Oktober 2022 Infrastruktur und Server, im Juli und August 2022 Apps und Erweiterungen. Der Prüfumfang umfasste nach dieser Mitteilung auch Websites, mehrere APIs, Nord Account, Nord Checkout, Nord UCP, VPN-Server und den serverseitigen NordLynx-Code.provider claim

Audit frequency

trust.audit_cadence

irregularprovider claim

Tested in court or by authorities

trust.court_tested

We have no source for this criterion.

Transparency report

trust.transparency_report

noneprovider claim

Warrant canary

trust.warrant_canary

noneprovider claim

Security incidents and data leaks

trust.breach_history

Im März 2018 wurde ein von NordVPN in einem finnischen Rechenzentrum gemieteter Server über ein unsicheres Fernwartungssystem des Rechenzentrumsbetreibers kompromittiert. Offengelegt wurde ein abgelaufener interner privater Schlüssel. NordVPN erklärte, der Server habe keine Aktivitätsprotokolle enthalten und Zugangsdaten seien nicht abgreifbar gewesen. Der Vorfall wurde am 21.10.2019 öffentlich bestätigt.confirmed

Bug bounty programme

trust.bug_bounty

HackerOne bug bounty via Nord Security (https://hackerone.com/nordsecurity)confirmed

Handling of reported vulnerabilities

trust.cve_handling

Bug bounty on HackerOne for Nord Security; vulnerability reporting encouragedprovider claim

Open source clients

trust.opensource_clients

someconfirmed

Open source server side

trust.opensource_server

noprovider claim

Reproducible builds

trust.reproducible_builds

noprovider claim

Available on F-Droid

trust.fdroid_available

noprovider claim

Listings by independent bodies

trust.independent_recommendations

Customer/press quotes on about page; widely reviewed commerciallyprovider claim

Protocols and cryptography

16/17 sourced

WireGuard

crypto.wireguard

yesprovider claim

OpenVPN over UDP

crypto.openvpn_udp

yesprovider claim

OpenVPN over TCP

crypto.openvpn_tcp

yesprovider claim

IKEv2/IPsec

crypto.ikev2

yesprovider claim

Proprietary protocol

crypto.proprietary_protocol

NordLynx (nach Anbieterangabe auf WireGuard aufbauend) und NordWhisper (Eigenentwicklung). Quellcode und externe Prüfberichte zu beiden Protokollen sind nicht öffentlich dokumentiert.provider claim

Legacy protocols still offered

crypto.legacy_protocols

IKEv2/IPsec still supported alongside OpenVPN/NordLynx/NordWhisperprovider claim

Default data cipher

crypto.data_cipher_default

ChaCha20/Poly1305 via NordLynx/WireGuard; AES for OpenVPN stackprovider claim

Weakest accepted cipher

crypto.data_cipher_weakest

AES-256provider claim

Key exchange and authentication

crypto.handshake

WireGuard/NordLynx handshake; post-quantum option documentedprovider claim

Perfect forward secrecy

crypto.pfs

yesprovider claim

Post-quantum key exchange

crypto.post_quantum

opt-inprovider claim

Own DNS resolvers

crypto.own_dns

yesprovider claim

DNS leak protection

crypto.dns_leak_protection

yesprovider claim

IPv6 handling

crypto.ipv6_handling

We have no source for this criterion.

WebRTC protection or guidance

crypto.webrtc_guidance

yesprovider claim

Obfuscation methods

crypto.obfuscation

Eigene Kategorie verschleierter Server unter den Specialty Servers. Die konkrete Technik wird nicht offengelegt, der Anbieter beschreibt sie allgemein als Stealth-Server, die den VPN-Verkehr wie gewöhnlichen Internetverkehr aussehen lassen. Unter Linux funktionieren die verschleierten Server nach Anbieterangabe nur mit OpenVPN über TCP oder UDP.provider claim

Usability behind the Great Firewall

crypto.works_in_china

per user reportsprovider claim

Features

19/20 sourced

Kill switch

features.killswitch

bothprovider claim

Permanent lockdown

features.killswitch_permanent

yesprovider claim

Split tunneling

features.split_tunneling

Nach Anbieterangabe lassen sich in der App einzelne Anwendungen von der VPN-Verbindung ausnehmen; in den Browser-Erweiterungen lassen sich einzelne Websites ausschließen.provider claim

Multihop

features.multihop

fixed routesprovider claim

Tor integration (Onion over VPN)

features.tor_integration

yesprovider claim

Port forwarding

features.port_forwarding

not availableprovider claim

Surcharge for a dedicated IP

features.dedicated_ip

We have no source for this criterion.

SOCKS5 proxy

features.socks5

yesprovider claim

HTTP proxy

features.http_proxy

yesprovider claim

Smart DNS

features.smart_dns

yesprovider claim

Ad and tracker filtering in DNS

features.adblock_dns

fixed listprovider claim

Malware and phishing filter

features.malware_filter

yesprovider claim

Custom DNS servers allowed

features.custom_dns_allowed

yesprovider claim

Local network access toggle

features.lan_access_toggle

yesprovider claim

Auto connect rules

features.autoconnect_rules

yesprovider claim

Private device network (mesh)

features.mesh_private_net

yesprovider claim

GPS location override (Android)

features.gps_spoofing

noprovider claim

Traffic analysis defence

features.traffic_analysis_defense

Obfuscated servers hide VPN traffic as normal activityprovider claim

IPv6 inside the tunnel

features.ipv6_tunnel

noprovider claim

Obfuscation without configuration

features.stealth_default

noprovider claim

Servers and network

10/12 sourced

Number of servers

network.server_count

8,719 Serverprovider claim

Number of countries

network.country_count

149 Laenderprovider claim

Number of cities

network.city_count

224 Staedteprovider claim

Virtual locations

network.virtual_locations

labelledprovider claim

RAM-only servers (diskless)

network.ram_only

entire networkprovider claim

Hardware ownership

network.ownership

mixedprovider claim

Own AS (autonomous system)

network.own_asn

noprovider claim

10 Gbps ports

network.10g_servers

We have no source for this criterion.

P2P and file sharing

network.p2p_servers

entire networkprovider claim

Public server list

network.server_list_public

yesconfirmed

Public status page

network.status_page

noprovider claim

Known upstream hosting providers

network.hosting_providers

We have no source for this criterion.

Apps and platforms

16/16 sourced

Windows app

apps.windows

native appprovider claim

macOS app

apps.macos

native appprovider claim

Linux app with GUI

apps.linux_gui

native appconfirmed

Linux command line

apps.linux_cli

native appconfirmed

Android app

apps.android

native appprovider claim

iOS app

apps.ios

native appprovider claim

Android TV app

apps.androidtv

native appprovider claim

Apple TV app

apps.appletv

native appprovider claim

Fire TV app

apps.firetv

native appprovider claim

Browser extension

apps.browser_ext

own extensionprovider claim

Type of browser extension

apps.browser_ext_type

standalone browser proxyprovider claim

Router support

apps.router_support

Der Anbieter dokumentiert die Einrichtung auf einem Router und weist auf eine Liste nicht unterstützter Router hin. Eine Routerverbindung belegt nach Anbieterangabe nur einen der zehn Geräteplätze und schützt alle dahinter liegenden Geräte.provider claim

Native build for Apple Silicon

apps.macos_arm_native

yesprovider claim

Command line documented

apps.cli_documented

yesprovider claim

Simultaneous devices

apps.simultaneous_devices

10provider claim

Usable without an account

apps.no_account_needed

noprovider claim

Account, pricing and payment

17/17 sourced

Data required at signup

pricing.signup_email_required

verified emailprovider claim

Account model

pricing.account_model

email as loginprovider claim

Cash by mail

pricing.cash_by_mail

noprovider claim

Monero

pricing.monero

noprovider claim

Bitcoin

pricing.bitcoin

yesprovider claim

Lightning

pricing.lightning

noprovider claim

Retail gift cards

pricing.retail_giftcards

noprovider claim

PayPal

pricing.paypal

yesprovider claim

Credit and debit card

pricing.credit_card

yesprovider claim

SEPA payment

pricing.sepa

noprovider claim

Monthly price

pricing.monthly_price

€14.99provider claim

Effective price on the longest term

pricing.effective_price_longest

€3.49provider claim

Price change at renewal

pricing.renewal_price_hike

very large increaseprovider claim

Flat pricing without permanent discounts

pricing.flat_pricing

noprovider claim

Free tier and its limits

pricing.free_tier

Kein dauerhaft kostenloses Angebot. Der Anbieter schreibt, über die eigene Website gebe es keine kostenlose Testphase, sondern nur die Geld-zurück-Frist von 30 Tagen. Eine kostenlose Testphase besteht nach derselben Quelle allein für Android-Nutzende, die die App über Google Play beziehen; sie wird von Google Play abgewickelt.provider claim

Money-back window

pricing.moneyback_days

30 Tageprovider claim

Cancellation path

pricing.cancellation_ease

cancel in accountprovider claim

Usage and performance

7/10 sourced

P2P policy in the terms of service

usage.p2p_policy

entire networkprovider claim

Streaming unblocking officially advertised

usage.streaming_officially

yesprovider claim

Netflix regions reported

usage.netflix_regions_reported

We have no source for this criterion.

Other streaming services

usage.other_streaming_services

SmartPlay streaming support claimedprovider claim

Bandwidth cap

usage.bandwidth_cap

no limitprovider claim

Data cap

usage.data_cap

noneprovider claim

Speed measurement references

usage.speed_references

We have no source for this criterion.

Latency and gaming suitability

usage.latency_gaming

We have no source for this criterion.

SMTP and port 25 handling

usage.smtp_policy

Nach Support-Angabe sind alle Ports für ausgehende Verbindungen offen mit Ausnahme von SMTP und NetBIOS; als Alternative für den Mailversand werden die Ports 465 und 587 genannt.provider claim

Official support in restrictive countries

usage.restrictive_countries_support

Obfuscated servers for VPN-blocking networksprovider claim

Support and documentation

6/7 sourced

24/7 live chat

support.livechat_247

yesprovider claim

Email or ticket support

support.email

yesprovider claim

Telephone support

support.phone

noprovider claim

German-language support

support.german_language

We have no source for this criterion.

Documentation assessment

support.docs_quality

thorough and currentprovider claim

Self-hosted chat widget

support.selfhosted_chat

noprovider claim

Self-service account deletion

support.account_deletion_easy

yesprovider claim

Provider website hygiene

5/5 sourced

SSL Labs grade of the website

site.ssl_grade

A+confirmed

Tracker load of the website

site.cookie_privacy_impact

Cookies for personalization/advertising; Privacy Controls / Cookie Policy linkedprovider claim

URL of the warrant canary

site.canary_page

none foundprovider claim

Length and readability of the legal documents

site.tos_readability

Standard Nord Account legal termsprovider claim

Marketing claims contradicting the provider's own terms

site.claims_vs_reality

Home/features market Dedicated IP and 224+ locations; privacy acknowledges personal data processing with third partiesprovider claim

Something wrong here?

If a value is wrong or outdated, report it with evidence. Every change is reviewed and then appears publicly in the changelog.