Transparency
State of our own data
85
providers
158
criteria
6,153
sourced cells
of 13,430 possible
54.2%
unsourced cells
Read from the database when this page is requested. The share of unsourced cells is included because a comparison table should show its gaps.
Who we are
- Operator
- Kolja Sagorski
- Legal form
- Einzelunternehmen
- Trading as
- sagorski.it
- Location
- Germany
One person, not a media company. No investors, no parent company.
The operator holds no shares in a VPN provider, in a provider's parent company, or in any business that resells VPN services. Conversely, no provider holds shares in this project. If that changes, it will be stated here first.
There are no affiliate links. No outbound link to a provider carries a partner identifier, and there is no commission agreement.
Income, live from the database
This table is not maintained, it is read. It shows every entry in the payments table that is marked public, and public is the default for every payment made by a provider. What is not listed here did not arrive.
No income so far
No provider has paid for the Verified badge yet, so this table is empty. The operator currently carries the cost. As soon as the first invoice is paid and booked, it appears here with provider, service, amount and date.
All amounts are net of VAT. Payment is by invoice and SEPA bank transfer, no payment processor is involved.
What money buys and what it does not
The rulebook holds in these six points and is written into the contract with every verified provider in exactly this form.
Identity is proven, not claimed
A company account is only unlocked once the provider demonstrates control of its domain: either through a DNS TXT record carrying a token we issue, or through a confirmation sent from an address on the official provider domain. No proof, no account.
The service is exhaustively listed
What is paid for: the Verified badge on your own entry, display of your own logo on the basis of the trademark clearance granted with it, a direct line to the editorial team, and the right to edit your own entry. Nothing else is included, and nothing else can be added for a fee.
On verified entries only the company edits
Once an entry is verified, other users no longer suggest values on it. The suggestion is replaced by the sourced objection: anyone who believes a value is wrong reports it with a source, and the editorial team reviews it. No source, no objection.
The editorial veto always applies
Provider edits go live immediately, but appear in the changelog marked as changed by provider and are automatically queued for editorial review. If a value set by the provider contradicts an independent source, the editorial team marks the value as disputed and shows both sources side by side. The editorial veto always applies and is written into the contract in exactly those terms.
Verified does not change the view
Verified has no effect on sorting, filtering or the default selection, and that is enforced technically. The type used to describe filter conditions in the code does not even know the field, so no filter can read it. Providers appear alphabetically, criteria in catalogue order, badge or no badge.
When it lapses, it is gone
If Verified is not renewed, the badge and the editing right end on the due date and the entry becomes an ordinary community entry again. The data stays, because it was sourced and not bought.
Rulebook in full, proof procedure and price: To the Verified programme
Infrastructure
Who operates this site
The entire application runs on Cloudflare, Inc., a company based in San Francisco, California, in the United States. There is no second operator and no server of our own any more: delivery, compute, database, file storage, mail sending and the name resolution of the domain all sit with this one provider.
Which services are in use
In detail, each with the purpose it is used for:
- Cloudflare Workers executes the application and renders the pages. Every request to this domain ends up there.
- Cloudflare D1 is the database. It holds providers, criteria, data points, sources, accounts, suggestions and payments.
- Cloudflare R2 is the file storage for the logos of providers who granted clearance and for the data packages of the open data export.
- Cloudflare KV holds the cache of the pre-rendered pages.
- Cloudflare Email Sending delivers the transactional mail: confirmation links, account notifications, the moderation digest.
- Cloudflare Cron Triggers starts the maintenance runs, that is the review queue, the link check, the data export and the expiry of the Verified badge.
- Cloudflare DNS answers the name queries for vpn-matrix.com and holds the zone.
What this means
Every request for this page passes through Cloudflare servers. In doing so, a company in the United States processes connection data and the full IP address of your line before the application sees anything at all. That cannot be switched off or configured away, it is how this infrastructure works.
This constitutes a transfer of personal data to a third country. Which data is affected, on what legal basis it is processed, and what is still outstanding on the data processing agreement is set out in the privacy policy. To the privacy policy
This commitment was revised
We decided against that commitment deliberately and disclose it here. The pledge remains in the source code, now set to false and with the name of the actual operator beside it. It is not deleted, because a removed pledge would look in the history like one that never existed.
A project that accuses providers of hiding their entanglements has to name its own, above all the uncomfortable one. Anyone reading this page should find the contradiction here rather than having to uncover it.
Software in use
The application code itself is open source and tied to no provider:
- Next.js for the application and page rendering
- the OpenNext adapter, which translates the Next.js build for Cloudflare Workers
- SQLite as the database, operated as Cloudflare D1
- Drizzle for database access and migrations
- better-auth for sign in and sessions, with no third party sign in services
No foreign hosts in the browser
Nothing is loaded from a foreign host in the browser. No Google fonts, no external scripts, no embedded videos, no payment processor. The Content Security Policy of this site permits resources from this domain only: a third party added by accident would be blocked rather than loaded quietly. That does not mean no third party is involved. The domain itself is delivered by Cloudflare, which is the point made above.
What is unchanged
There are no cookies for visitors, no tracking, no analytics tool in the page source and no ad network. No counting script is shipped and no identifier is set that would allow a device or a person to be recognised again.
One qualification belongs here: Cloudflare keeps request statistics for the zone by itself. They arise at the server and not in the browser, they cannot be opted out of while running on this infrastructure, and they are a different thing from a counting service we would install ourselves. They are stated here because a pledge that hides its exception is not a pledge.
No cookies for visitors
Reading this page sets no cookie. The only cookie in the entire project is the session after signing in, and that exists solely for the editorial team, community accounts and providers. The light or dark display setting lives in the browser's local storage, not in a cookie. There is no tracking and no profiling, which is why there is no consent banner: there would be nothing to consent to.
Editorial independence
Moderation log
Every change to a data point is public in the changelog, with the old value, the new value, the author role and the timestamp. Rejected suggestions appear there with the reason. There is no silent correction. To the changelog
Methodology
How a value comes about, when it counts as sourced, when it is marked disputed and when it has to be checked again is set out in the methodology. It is the yardstick this project has to be measured against. To the methodology
Conflicts of interest
The operator works professionally as an IT security consultant. Should a client relationship ever arise with a provider listed here or with its parent company, it would be disclosed at this point with the name, the nature of the work and the period, and the affected entries would be flagged.
Open data and API
The full data set is downloadable and available through an open JSON interface, including sources and retrieval dates. Anyone who wants to recheck, audit or reuse the figures needs neither an account nor permission.
Licence
The data set is published under CC-BY-SA-4.0, that is Creative Commons Attribution-ShareAlike 4.0 International. Credit the source and share alike. https://creativecommons.org/licenses/by-sa/4.0/