Affiliate links present. Disclosure
Proton VPN
Verification over convenience — every privacy claim backed by open-source code, annual audits, and Swiss law
Choose Proton VPN if you need privacy you can verify, not just trust. Skip it if streaming reliability or ease of use are your primary criteria.
Some VPN services are built around convenience. Others are built around trust. Proton VPN belongs firmly to the second category — here, design decisions are shaped less by ease of use and more by the requirement that the system can be externally verified.
At a glance
Right fit if
- Users who want open-source clients, annual third-party audits, and Swiss jurisdiction — all three together
- Users who find comfort in understanding systems rather than delegating to them
- High-risk users: journalists, activists, users in surveillance-heavy environments who need Secure Core multi-hop
Not the right fit if
- Users whose primary use case is streaming — manual server selection often required, no one-tap platform access
- Users who want a VPN that runs invisibly — Proton's interface is legible by design, not invisible
- Users comparing on price alone — Proton sits at the premium end, especially for the Unlimited bundle
Score breakdown
Scale reflects category fit and operational confidence — not absolute product quality.
Tap WHY to see the verdict · HOW to see the evidence
ProtonVPN is built around the idea that trust should be verifiable at every layer — not claimed through policy statements, but confirmed through open-source code, consecutive public audits, and a real-world legal test that produced nothing. That commitment to verifiability runs through the product's architecture at a pace more cautious than most commercial competitors.
All client apps are open-source on GitHub — iOS, Android, Windows, macOS, Linux. Five consecutive Securitum annual no-logs audits (2022–2026) are scoped to server infrastructure and configuration, not app source code — the 2026 review ran May 20–22 on-site at Proton AG's Zurich offices, with complete reports publicly accessible without account login. Securitum separately conducts a distinct app-code security audit of Proton's client applications — a different engagement with a different scope. No-logs policy has been tested in 458 legal requests as of July 2026 — Proton stated no logs were available to produce in any. A separate SOC 2 Type II attestation, completed July 2025 and audited by Schellman, covers Proton's operational security controls rather than the no-logs claim specifically. Proton does not run a traditional warrant canary; it argues Swiss law's mandatory eventual notification of surveillance subjects makes one redundant, and points to the transparency report instead. Swiss constitutional privacy protections currently apply to legal processes routed through Switzerland — but a proposed revision to the Swiss VÜPF surveillance ordinance, unresolved as of mid-2026, could require VPN providers above roughly 5,000 users to log IP addresses, verify identity with official ID, and hand over data in plaintext; Proton has said it would rather relocate than comply, and some reports say infrastructure relocation has already begun. The 2021 ProtonMail incident involved a different product under a different legal mechanism — an emergency preservation order on a specific email account's future IP logging, not an existing VPN record.
What exists
- Five consecutive Securitum annual no-logs audits (2022–2026), scoped to server infrastructure — full reports publicly accessible without login
- A separate, distinct Securitum app-code security audit of client applications; code also published on GitHub for public review
- 458 legal requests as of July 2026: Proton stated no VPN logs were available to provide in any
- Separate SOC 2 Type II operational-security attestation completed July 2025, audited by Schellman
- Transparency report updated as legal requests arrive; cash and crypto (Bitcoin only) payments accepted; free plan requires no payment
What's missing
- No traditional warrant canary — Proton states one is unnecessary under Swiss law, since surveillance subjects are eventually notified anyway; relies on the transparency report instead
- No-logs audits are point-in-time, sampled, and operator-assisted — Proton staff demonstrate systems live while Securitum directs the review; explicitly excludes source code per Securitum's own scope note
- 2021 Swiss court order compelled ProtonMail IP disclosure (separate product, same legal framework)
- Pending Swiss VÜPF surveillance-law revision (unresolved as of mid-2026) could require mandatory IP logging and ID verification — a live risk to Proton's jurisdictional advantage, not a settled fact
Secure Core builds jurisdiction stacking into the routing architecture — traffic passes through servers in Iceland, Switzerland, or Sweden before reaching the exit, meaning a compromised exit node doesn't expose the origin. That design introduces deliberate latency. ProtonVPN treats the latency as the cost of the privacy guarantee, not a problem to be optimized away.
WireGuard UDP is available on Windows, macOS, Android, iOS/iPadOS, Android TV, and Linux — effectively all platforms. Stealth (obfuscated, WireGuard-based) covers the same list except Linux is beta-only. IKEv2 is available on macOS only, but in an active phaseout — Proton began removing server-side IKEv2 support in April 2026, with connections increasingly likely to fail from that point on, and final support scheduled to end February 2027; treat it as a legacy option, not a stable feature. OpenVPN is available on the Linux GUI app only — neither is a cross-platform option the way WireGuard is. Kill switch is available system-wide on all plans including free, but is not enabled by default — official setup guides for every platform describe manually turning it on. The stricter Advanced/Permanent kill switch mode — which persists across restarts — is Windows- and Linux-only. Secure Core routes through two servers in privacy-favorable jurisdictions before the exit — if the exit is compromised, the entry-point encryption holds. NetShield provides DNS-level ad and malware blocking. Port forwarding is supported on Windows and Linux paid plans, a differentiator versus providers like NordVPN that removed it entirely. Per-app kill switch doesn't exist — system-wide only. Secure Core latency is real and deliberate: two-server routing adds latency proportional to jurisdictional-hop distance. Users who enable Secure Core for everyday browsing are accepting that trade.
What exists
- Smart Protocol automatically selects the best available protocol and is enabled by default; WireGuard UDP is available across the major supported platforms; Stealth (obfuscated, WireGuard-based, available on free tier too) for censored networks
- System-level kill switch available on all platforms including free tier — requires manual activation, not on by default
- Secure Core multi-hop routing on paid plans
- NetShield DNS-level ad and malware blocking; full IPv6 leak protection; port forwarding on Windows/Linux paid plans
What's missing
- OpenVPN available on Linux GUI app only — not Windows/macOS/mobile
- Kill switch is NOT enabled by default on any platform — requires manual activation per official setup guides
- Advanced/Permanent kill switch limited to Windows and Linux — not macOS, iOS, Android
- No per-app kill switch — system-wide blocking only
- Secure Core not available on free tier
- Obfuscation available only via Stealth protocol — OpenVPN and WireGuard not separately obfuscated
Streaming servers are labeled and navigable on paid plans — per Proton's own instructions, you connect to a Plus server in the relevant country rather than selecting a labeled streaming category. That transparency is consistent with how ProtonVPN surfaces other technical decisions. The free plan doesn't reach streaming servers at all.
Proton publishes an official streaming guide (protonvpn.com/support/streaming-guide) covering 100+ named services with per-country breakdowns — Disney+, Amazon Prime Video, and Max/HBO Max each list the countries where Proton's Plus servers work. Per the guide's own FAQ, to access a specific catalog you connect to a Plus server in the relevant country — there's no separate 'streaming category' selector. Note: the guide's main service list and its own FAQ disagree on how many countries carry local Netflix libraries (25 in the main list, 10 in the FAQ) — this is an inconsistency on Proton's own page, so no single Netflix-country count is used here. This is a descriptive current-status list, not a contractual guarantee — Proton doesn't promise ongoing compatibility against any service's anti-VPN detection. Free plan users connect through the standard pool — streaming access is inconsistent and not a product commitment at the free tier. When a streaming server is blocked, Proton's standard response is IP rotation on that server; there can be a gap between the blocking event and the fix.
What exists
- Labeled streaming servers available on paid plans
- Disney+, Amazon Prime Video, Max/HBO Max, BBC iPlayer, Hulu, and 100+ other named services in Proton's official streaming guide
What's missing
- No streaming server access on free plan
- Official list is descriptive, not a contractual guarantee — no ongoing-compatibility promise against any specific service
Bare-metal hardware with no major cloud providers in the core VPN fleet means ProtonVPN's exit IPs don't share reputation with commercial cloud traffic. The fleet has roughly doubled since the prior review pass. Secure Core's two-server routing introduces latency that's architectural rather than avoidable — the speed story depends entirely on whether Secure Core is engaged.
The server fleet runs on bare-metal hardware with no virtual machine usage. Proton's official server page (protonvpn.com/vpn-servers) states 20,000+ servers in 140+ countries in its static, indexable text — up from about 10,000 servers in 100+ countries at the prior check; counts change frequently and should be treated as approximate. Core VPN servers avoid major cloud providers — a ProtonVPN exit IP isn't competing for reputation with other tenants on a shared cloud block. WireGuard UDP is available on nearly every platform, and Smart Protocol (auto-select) is the actual default. VPN Accelerator — Proton's proprietary packet-processing optimization, enabled by default — can increase speeds by up to 400% on long-distance connections, applied across protocols rather than being WireGuard-specific. Secure Core adds latency proportional to the geographic distance between the jurisdictional intermediary and the exit server. The 2026 Securitum audit reconfirmed full-disk encryption on servers rather than RAM-only architecture — different technique, same protection goal: hardware seizure produces encrypted volumes, not readable data.
What exists
- WireGuard UDP available on Windows, macOS, Android, iOS/iPadOS, Android TV, Linux; Smart Protocol (auto-select) is the actual default; VPN Accelerator (proprietary optimization, up to 400% on long-distance links) enabled by default across protocols
- 20,000+ servers in 140+ countries per official static page text (protonvpn.com/vpn-servers) — up from ~10,000 servers / 100+ countries at prior check — bare-metal hardware, no virtual machines
- No major public cloud providers in core VPN fleet
What's missing
- Secure Core multi-hop adds latency — two-server routing by design
- Hardware in colocated facilities — not Proton-owned data center buildings
The interface exposes its own logic — you can see which protocol is active, whether Secure Core or NetShield is engaged, what split tunneling rules are set. That transparency is deliberate design. The product doesn't hide decisions from you, which means it asks more of you than providers built around invisibility.
Platform coverage: Windows, macOS, Linux, iOS, Android, Android TV, Apple TV, and Chromebook. Split tunneling covers Windows (exclude and include modes, app and IP-based), macOS (experimental, exclude-mode only, incompatible with WebKit-based apps like Safari, requires WireGuard or Stealth), the Linux GUI app, Android and Android TV (both exclude and include modes), and the browser extension (domain-based). It's absent specifically on iOS/iPadOS and Apple TV — not a blanket Apple-platform gap, since macOS does have it. Chrome and Firefox extensions are both available but restricted to paid plans — free-tier users don't get the extension. The interface surfaces meaningful controls in context: Secure Core toggle, NetShield level, protocol selector, and split tunneling app list are accessible without digging through advanced settings.
What exists
- Native apps for Windows, macOS, Linux, iOS, Android, Android TV, Apple TV, Chromebook
- Split tunneling on Windows (full), macOS (experimental, exclude-only), Linux GUI, Android and Android TV (both modes), and the browser extension
- Chrome and Firefox extensions available (Premium plans only)
What's missing
- Split tunneling not available on iOS/iPadOS or Apple TV specifically — macOS is not excluded, it has a working experimental implementation
- Browser extension gated to paid plans — not available on free tier
- Interface includes multiple configuration layers — not a single-button design
Paid plans allow ten simultaneous connections. The free plan connects one device from a smaller regional selection. Browser extensions for Chrome and Firefox exist but require a paid plan.
Paid plans support ten simultaneous connections. Free plan is single-device with a narrower set of available server locations. Chrome and Firefox extensions are both available but Premium-only — free-tier users don't get them. Router setup guides cover a wide range of firmware: AsusWRT (stock and Merlin), DD-WRT, FreshTomato, GL.iNet Flint, MikroTik (WireGuard), OpenWRT, OPNsense, pfSense, and Vilfo — no dedicated Proton-branded router product. The Proton ecosystem offers Mail, Drive, Calendar, and Pass on the same account; the connection limit applies to the VPN product within that suite.
What exists
- 10 simultaneous connections on paid plans
- Chrome and Firefox extensions available (Premium plans)
- Router setup guides for AsusWRT, DD-WRT, FreshTomato, GL.iNet, MikroTik, OpenWRT, OPNsense, pfSense, Vilfo
What's missing
- Not unlimited — below the unlimited tiers in the category
- Browser extension gated to paid plans — not available free
- No dedicated router firmware or product
The free plan is the entry point worth examining first — unlimited bandwidth, no data cap, no ads, same infrastructure as paid plans. The limitation is server selection and potential congestion, not degraded hardware. Paid Proton sits at the premium end; the Unlimited bundle changes the per-service math if you use the full ecosystem, and the discounted intro rate on long-term plans is not guaranteed to carry through to renewal.
The free plan provides unlimited bandwidth, no data cap, no advertising, and no server tiering that puts free users on separate hardware, with servers available in 10 countries. Free users may encounter more congestion at peak times and don't get streaming-optimized servers. Paid plans are offered as monthly, 1-year, and 2-year terms, with the lowest per-month rate on the 2-year term. The Unlimited bundle includes Proton Mail, Drive, Calendar, and Pass — if you use the ecosystem, the per-service cost drops below standalone VPN pricing at most competitors. Per Proton's official Terms of Service, the discounted rate shown at signup applies to the initial term, and renewal is billed at "the then-current price valid at the time of the renewal" — this doesn't guarantee the promotional rate carries over.
What exists
- Free plan available with unlimited bandwidth, servers in 10 countries
- Pricing publicly listed across monthly, 1-year, and 2-year terms
- Monthly billing option available
What's missing
- Free plan limited to one connection and no streaming-optimized servers
- Discounted intro pricing applies to the first term only — per official ToS, renewal is charged at "the then-current price valid at the time of the renewal," which is not guaranteed to match the initial discounted rate
- Refund requires support contact — not self-service
Full-disk encryption on servers rather than RAM-only architecture — a different mechanism achieving the same protection against physical hardware seizure. The VPN product has a clean operational record. The 2021 ProtonMail incident raised legitimate questions about Swiss law's limits that are worth understanding clearly, and separately from the VPN product's own record.
Servers use full-disk encryption confirmed in the 2025 Securitum audit — hardware seizure produces encrypted volumes rather than readable data. No VPN-specific infrastructure incidents publicly documented. Proton communicates incidents through blog posts and transparency reports. The 2021 ProtonMail event demonstrated that Swiss law includes a compelled-prospective-logging mechanism under Europol pressure — it involved a specific email account's future activity, not an existing VPN record, and the VPN product operates under different legal obligations. Understanding the distinction matters for accurately evaluating what Swiss jurisdiction does and doesn't protect.
What exists
- Full-disk encryption on servers — confirmed in Securitum 2025 audit
- Proactive incident communication via blog and transparency reports
What's missing
- Encrypted disk model rather than RAM-only architecture
- No public uptime SLA
- No VPN-specific infrastructure incidents publicly documented
Trade-offs
- Not primarily focused on streaming or aggressive geo-unblocking
- Secure Core improves privacy at the cost of speed
- Pricing emphasizes trust and transparency over budget positioning
- Pending Swiss VÜPF surveillance-law revision (unresolved as of mid-2026) is a live risk to the jurisdictional advantage this provider is chosen for
When it breaks
- Secure Core adds 20–50ms latency on top of standard geographic delay. For everyday browsing with it enabled, the overhead becomes noticeable — it's a deliberate trade-off.
- Streaming may require manual server selection. Users who expect one-tap platform access will encounter more friction than with CyberGhost or Nord.
- The free tier doesn't include streaming-optimized servers — it's functional for basic privacy use, not for streaming or performance-sensitive tasks.
Hidden trade-offs
- Open-source status means anyone can inspect the code — but also means any vulnerability is publicly visible. The security community considers this a net positive; some users find it unsettling.
- The Unlimited bundle pricing assumes you'll use Proton Mail, Drive, Calendar, and Pass. If you only need the VPN, the per-product cost calculation is less favorable.
Sources
Building a complete privacy stack?
A VPN handles network-level encryption. Password managers and antivirus cover the gaps it can't.
Quick comparisons
© 2026 Softplorer