VPN founded in 2018 and headquartered in the Netherlands, which merged into Lithuania's Nord Security in 2022 (the two brands still operate separately). Runs its own RAM-only servers, has passed Deloitte no-logs audits, and operates under Dutch/EU jurisdiction.
There's no limit on the number of devices you can connect on a single plan, which is unusual in the category, and RAM-only servers mean nothing persists after a reboot.
Worth knowing
It shares infrastructure and policies with sibling VPN brands after a 2022 merger, so it's less of a fully separate operation than the marketing suggests.
Incorporated in Amsterdam, Netherlands – a full EU member state.
30/30
Ownership & control
Acquired/corporate, EU/EFTA parent
Why this score?
Merged into Lithuania's Nord Security in 2022, keeping the parent inside the EU, though it now answers to a corporate group rather than standing fully independent.
10/25
Data sovereignty
Own infrastructure
Why this score?
Surfshark runs its own RAM-only server fleet across multiple European countries rather than renting from a third party.
30/30
Accountability & trust
Partially open source + GDPR + audited
Why this score?
Partially open source, GDPR-compliant, and its no-logs policy has been independently audited by Deloitte.
Swiss VPN by Proton AG with a strict no-logs policy independently audited annually. 11,496 servers across 117 countries, all owned and operated by Proton. Open-source apps on all platforms. Unique Secure Core architecture routes traffic through privacy-friendly countries first.
VPN from Nord Security, a Lithuanian-founded cybersecurity company. Runs its own RAM-only (diskless) server fleet and markets a no-logs policy that has been repeatedly audited by PwC and Deloitte. Caveat: the no-logs claim is framed around Panama's jurisdiction as a legal/marketing choice – the company itself is Lithuanian and EU-based.