How We Test

Our Testing Methodology

Every number on this site comes from a repeatable process, not a press kit. Here’s exactly what that process is, and why each step exists.

01

Self-funded subscriptions, no exceptions

Every subscription we test is bought with real money, at the listed price, through the same checkout flow any customer uses. No press accounts, no reviewer credentials, no early-access builds supplied by the provider. Reviewer accounts routinely get preferential treatment: dedicated support, different server pools, app builds that haven’t shipped publicly yet. A review built on a reviewer account measures a product nobody else gets. We only measure what a subscriber actually receives.

02

Six nodes, hourly, for a minimum of two weeks

A single speed test from one location on one day tells you almost nothing. Server load shifts by time of day, routing paths change, and a provider can swap a congested server between your first test and your second. So every provider is measured from six geographically distributed nodes, running automated speed and leak checks hourly, for a minimum of two weeks: 212 hours of logging and leak audits per review cycle. That volume catches what a single snapshot can’t: a DNS leak that only appears on reconnect, a handshake that behaves differently under load, a server that’s fast at 3 a.m. and mediocre at peak traffic. Whatever protocol a provider defaults to, WireGuard on most modern services, OpenVPN or IKEv2 as fallbacks, or a proprietary tunnel like ExpressVPN’s Lightway, we’re testing the connection as it actually ships, not as it’s documented.

03

The full leak panel: DNS, WebRTC, IPv6

Three leak types explain most of the gap between a VPN’s marketing page and its runtime behavior. A DNS leak sends a device’s DNS queries to an ISP resolver instead of through the encrypted tunnel, quietly exposing browsing activity to the original network. A WebRTC leak exposes a device’s real IP address through a browser’s WebRTC API and a STUN request, bypassing the tunnel even while it’s active. An IPv6 leak occurs when a dual-stack device’s IPv6 traffic travels unprotected because the VPN only tunnels IPv4. We test for all three across major operating systems, because leak behavior isn’t uniform. A leak visible on Windows may not reproduce on macOS or mobile; each OS handles its network stack differently.

04

Quarterly re-testing

A verdict published a year ago describes infrastructure that may no longer exist. Providers migrate servers, patch protocols, and change ownership: Kape Technologies acquiring Private Internet Access in 2019, or Surfshark and Nord Security landing under the same parent holding company, Cyberspace, after a 2022 merger, are the kind of structural shifts that change what’s actually running behind a provider’s marketing page. Every verdict on this site is re-tested quarterly against the same six-node, full leak panel process used for the original review. A verdict here doesn’t expire quietly. It gets checked again, on a schedule, whether or not anything’s changed.

Where our testing ends and independent audits begin

It’s worth being precise about what kind of testing this is. What we run is runtime, black-box testing: observing what a paying subscriber’s traffic actually does on the open internet, from outside the provider’s infrastructure, over hundreds of hours. We don’t have code access, and we’re not a security auditing firm.

That’s a different discipline from a code audit. Firms like Securitum (Proton VPN’s auditor since 2022, five consecutive annual audits as of May 2026), Cure53 (which has audited Mullvad’s infrastructure and ExpressVPN’s Lightway protocol), and PwC and Deloitte (which have handled no-logs audits for NordVPN and Surfshark, and the build process behind ExpressVPN’s RAM-only TrustedServer network) work inside a provider’s servers and source code, under NDA, to check whether the software matches the stated policy. A third layer sits above both: legal exposure. Private Internet Access’s no-logs claim has been tested in actual subpoenas and a federal court case, a different kind of proof than either an audit or a runtime test. Legal record, code audit, and runtime testing answer different questions. We only answer one of them: what does this provider’s traffic do, right now, when we test it ourselves.

See every verdict this process has produced →