Most VPN comparison pages rank providers by how much commission they pay. You can do better than that in about twenty minutes, using only the provider’s own published material and two free tools.
Start with the question almost nobody asks first.
Step 0: what are you actually trying to stop?
A VPN solves a narrow problem: it stops your internet provider, your employer’s network or the café wifi from seeing which sites you visit, and it changes the IP address websites see. That is genuinely useful.
- Hiding browsing from your ISP or a shared network — a VPN is the right tool.
- Using a service from another country — a VPN is the right tool, subject to that service’s terms.
- Avoiding advertising profiles — partly. Fingerprinting and your logged-in accounts identify you regardless.
- Being anonymous to a determined state adversary — no consumer VPN provides this. That is a Tor and operational-security problem, and buying a subscription will not solve it.
A VPN does not remove trust from the equation. It moves it from your internet provider to a company you have never met. The whole exercise is deciding which company deserves it.
Step 1: who owns the company? (5 minutes)
Search the provider’s name plus “owned by” and check the corporate registry of the country it claims to be in. You are looking for three things: who ultimately owns it, whether it belongs to a group that also owns “independent” review sites, and whether the ownership has changed recently without an announcement.
Consolidation in this industry is heavy, and a provider you chose for its independence may now share a parent with three competitors and a comparison site that ranks them.
Step 2: read the audit, not the badge (5 minutes)
“Independently audited” is not a fact until you know what was audited. Open the actual report and check:
- Scope. Was it the no-logs configuration of production servers, or a marketing review of a privacy policy?
- Date. An audit from four years and two ownership changes ago describes a company that no longer exists.
- Access. Did the auditor get server access and configuration, or were they shown documents?
- Findings. A report with zero findings is usually a narrow scope, not a perfect company. Real audits list issues and remediations.
- Publication. Full report available, or a summary blog post? A summary is marketing.
Step 3: check the logging policy against the account system (3 minutes)
Read the privacy policy, not the landing page. Many “no-logs” providers still record connection timestamps, bandwidth per account and the source IP at connection — which, combined with an email address and a card payment, is plenty to link a session to a person.
Ask what identifies you at signup. An email address you have used elsewhere and a card payment tie your identity to the account permanently, whatever the traffic-logging policy says.
Step 4: jurisdiction, honestly (2 minutes)
The “Fourteen Eyes” framing is repeated everywhere and explains less than it appears to. What matters is whether the jurisdiction can compel a provider to start logging a specific user and forbid it from saying so. Several countries widely marketed as privacy havens have exactly such powers.
A provider that operates diskless servers and holds nothing to hand over is a stronger position than a favourable-sounding country.
Step 5: verify the technical claims yourself (5 minutes)
Sign up for the shortest plan available and test before committing to a year.
- Protocol support. WireGuard should be available and default. If the only option is a proprietary protocol with no public specification, that is a downgrade.
- Leak testing. Run a DNS and WebRTC leak test on every device you will use. A single leaking platform makes the subscription pointless there.
- Kill switch under failure. Disconnect your network deliberately mid-transfer and see whether traffic escapes. Test it; do not trust the checkbox.
- Speed against your own baseline. Measure without the VPN first, then with it, on the nearest server and a distant one.
The red flags that end it early
- Lifetime subscriptions. The business model does not support them; either the price is subsidised by your data or the service will be sold.
- “Military-grade encryption” as a headline feature. It means AES-256, which everyone uses. It is filler.
- Claims of complete anonymity.
- No named legal entity, no address, no way to identify who runs it.
- A free unlimited tier with no clear funding. Running bandwidth costs money; if you are not paying, the traffic is the product.
What a reasonable outcome looks like
You should end up with a provider that has recent audits with real findings, a legal entity you can name, WireGuard by default, no leaks on your devices, and a price you pay monthly until you are confident. That is achievable in an evening, and it beats any ranking table.
If you get through this and conclude you would rather trust yourself than any company, that is also a valid answer — see our WireGuard self-hosting guide.
