Skip to main content

Home Guides Security checklist

Checklist

VPN security checklist

The 12 points to check before choosing a VPN. Each one is an objective criterion you can verify independently of the provider's marketing claims.

    1. Jurisdiction

    Which country's laws is the VPN provider subject to?

    Review the home country's data-retention, legal-request and corporate-transparency rules. Intelligence alliances add context; they do not by themselves prove better privacy or no-logs implementation.

    2. Proof of independent audits

    Has the no-logs claim been verified by a third party?

    Look for a report from a recognized third party, including its date and scope. A one-off review covers only that period and scope; regular repeated audits provide a stronger signal about current implementation.

    3. No-logs policy

    What kind of logs does the provider keep?

    Check how the policy treats source IPs, destinations, connection timestamps, bandwidth and account data separately. Read retention periods, purposes and third-party sharing terms instead of relying on the marketing headline.

    4. Encryption standard

    Which encryption algorithm and key length?

    Verify the current app's cipher suite and protocol configuration in provider documentation and audit reports. Avoid services that default to obsolete, weak options such as PPTP.

    5. Protocol options

    Which VPN protocols does it support?

    WireGuard or a current WireGuard derivative plus a mature alternative such as OpenVPN can provide flexibility. Check the implementation's update and security-audit history as well as the protocol name.

    6. DNS leak protection

    Where do DNS queries go while the VPN is active?

    Confirm that DNS queries use the expected encrypted tunnel and resolver. Queries leaving the tunnel can expose domain activity; test for leaks across the networks and applications you use.

    7. Kill switch

    What happens if the VPN connection drops?

    A kill switch is designed to stop traffic when the tunnel drops, reducing IP-exposure risk. Verify system-wide versus per-app coverage, reconnect behavior and split-tunneling exceptions on your platform.

    8. RAM-only server infrastructure

    How do the servers run?

    A RAM-only design can reduce local-disk persistence and clears memory on reboot. It does not by itself prevent centralized logging or misconfiguration, so assess the architecture claim alongside independent audits.

    9. Open-source clients

    Is the VPN app's code public?

    Open source makes code review and vulnerability reporting easier. It does not by itself guarantee the absence of backdoors or that the distributed binary matches the source; look for reproducible builds and audit history too.

    10. Device limit

    How many devices can you use on one subscription?

    Estimate your simultaneous-device needs, then verify the provider's current connection cap, router rules and fair-use terms on the official plan page. These limits can change.

    11. Public legal record (if any)

    Has the no-logs claim been tested in a legal case?

    Past cases or server-seizure reports can show how a provider responded to a request at a specific time. They are not standalone proof of the current policy or a future guarantee; verify the underlying decisions and reports directly.

    12. Pricing transparency

    Is the renewal price clear?

    Before paying, check the introductory total, automatic-renewal price, tax, currency, app-store exceptions and refund terms. A promotional headline does not show the full cost.

How to use this list

When picking a VPN, verify these 12 points on the provider's own site, in audit reports and in independent reviews. Our source-based comparison framework evaluates these criteria alongside provider documentation and current terms — to compare profiles, visit the VPN comparisons page.

Related pages