SecuFocus
Under the hoodBrowsing & the web

Proton VPN vs ExpressVPN vs NordVPN vs IVPN: who protects what?

Retained data, audits, WireGuard and post-quantum encryption: a technical comparison of four VPNs, with privacy as the starting point.

Four smoked-glass tunnels carrying mint-coloured light trails, a visual metaphor for four VPN services.

Original AI-generated illustration · SecuFocus

At a glance

Key points

IVPN lets you create an account without an email address. Proton VPN combines open-source apps with a recent audit of its no-logs policy. ExpressVPN documents its server architecture and protocol while declaring more usage statistics. With NordVPN, retention periods and enabled options need particular attention. The table compares these privacy commitments; it does not measure app performance.

Sources and limits of this comparison

People rarely choose a VPN by reading its privacy policy. Yet that is where the differences start. “No logs” may describe traffic inside the tunnel while leaving out the customer account, application statistics and payments.

This comparison draws on policies, technical documentation, official repositories and accessible audits as of 1 October 2026. We read Proton’s 2026 Securitum report and ExpressVPN’s 2025 KPMG report. For NordVPN’s Deloitte assurance engagement, we consulted the provider’s announcement: the full report requires Nord Account access. The status of each piece of evidence is set out below.

SecuFocus did not measure throughput, latency, network leaks or resource consumption in these four applications for this article. The figures shown are documented parameters, stated retention periods and audit dates. They are not benchmark results. None of this article’s links are affiliate links.

Who are you trusting with your traffic?

Imagine checking your bank account on hotel Wi-Fi. HTTPS already protects the connection’s contents all the way to the bank. A VPN adds a tunnel between your device and its server: the local network sees a connection to the VPN instead of each destination carried inside that tunnel.

At the other end, the VPN operator occupies a sensitive position. It processes your network address and outbound traffic. Destination addresses, timing and volumes remain useful to an observer; domains may also be visible through DNS or other metadata. This does not mean the operator can read the contents of a correctly established HTTPS connection.

Now sign in to Google, Instagram or a shopping account: those services still recognise you. A different IP address removes neither cookies, accounts nor browser fingerprints. A targeted identification threat requires attention to those layers too. Adding Tor to a VPN without understanding the setup is no reliable shortcut; the Tor Project advises against combining them unless you understand the implications.

Your objectiveWhat to examine
Hide destinations from Wi-Fi or your ISPFull tunnelling, DNS, IPv6 and behaviour when the connection fails.
Reduce data held by the providerAccount, payment, telemetry, session state and persistent logs.
Limit the effects of a compromised serverArchitecture, isolation, access control and multi-hop.
Resist targeted identificationSigned-in accounts, browser, endpoint and correlation across both ends.
Under the hood

Two protections, two paths.

  1. Your deviceStarting point
  2. Internet providerVPN connection visible
  3. VPN serverTunnel exit
  4. WebsiteVPN exit IP

VPN from your device to the VPN server

HTTPS from your browser to the website, through the tunnel

Traffic routed through a VPN without leaks. HTTPS protects content in transit; the website still receives what you send it.

Source: EFF, encryption in transit

Data retained outside the tunnel

All four providers say they do not keep VPN browsing histories. Their policies differ on account data, diagnostics and payments. The table reflects their disclosures; SecuFocus has no access to their servers to confirm them.

Side by side4 tools · same criteria

Swipe to read the columns. Criteria and names stay visible. With a keyboard, use the arrow keys inside the table.

Data retained outside the tunnel
CriterionProton VPNExpressVPNNordVPNIVPN
VPN browsingNo retained history, according to the policy.No retained history, according to the policy.No retained history, according to the policy.No retained history, according to the policy.
Sessions and connectionsDeclares no VPN session logs.Connection day, without an exact time.Last-session information erased within 15 min of termination.Active session state erased on disconnection.
Other declared dataAccount IPs may be retained to combat abuse.VPN location, originating country/ISP, total MB transferred.Flag: VPN used within the previous 90 days.Payment references retained for accounting.
Point to examineAccount authentication logging is off by default.Optional diagnostics; advertising identifiers require consent.The 90-day flag is not a detailed history.No mandatory email; account purged after 90 days without an active subscription.

Your email address and invoice matter too

A well-designed tunnel does not make the subscription purchase anonymous. A bank card generally links payment to an identity at a processor. Cryptocurrency does not automatically remove that link: the funds’ origin and the exchange’s records may restore it.

Nord Account states that payment and billing information is retained for ten years after the last transaction. That is separate from VPN activity. Confusing the two would wrongly suggest that ten years of browsing history are retained.

Distinguish the payer’s identity, their link to the account and the link between that account and past network activity. Knowing who paid does not necessarily reveal their browsing. An account that requires little personal information still reduces what a breach could expose.

Another practical detail: a dedicated IP gives websites a stable reference point. NordVPN’s notice links that option to the account. Unless you have a specific need for it, it is a poor fit for the privacy benefit of sharing an address with many other users.

What the audits examined

“Audited” is not enough to compare services. Look for the period, the auditor’s access, the systems examined and the exclusions. An application audit may look for vulnerabilities without checking data retention on servers.

At Proton, Securitum examined samples of Free and Paid servers with assistance from the operator’s engineers. Its conclusion supports no-logs consistency within that scope. Accounts, billing, support, B2B servers and formal code review are excluded. That prevents the finding being extended to the whole ecosystem.

ExpressVPN’s KPMG report covers the description and design of controls at a particular date. Its assurance level should not be confused with continuous observation of their effectiveness. It provides useful evidence about TrustedServer, not a certification of every collection practice in every app.

Side by side4 tools · same criteria

Swipe to read the columns. Criteria and names stay visible. With a keyboard, use the arrow keys inside the table.

What the audits examined
CriterionProton VPNExpressVPNNordVPNIVPN
AuditorSecuritumKPMGDeloitteCure53 for the 2019 no-logs audit.
Period examined20–22 May 2026. Report: 27 May.As at 28 February 2025.10 November–12 December 2025, according to the announcement.Last stated no-logs audit: March 2019.
Document consultedFull report read.Full report read.Announcement consulted. Report requires Nord Account; not read.Position dated 19 June 2026 consulted; old report not examined here.
Type of evidenceTechnical sample review, Free and Paid; six person-days.ISAE (UK) 3000 Type I: reasonable assurance on controls at a particular date.ISAE 3000 revised; standard and specialised servers in the announced scope.The 2026 programme targets Unlinked Access for additional services.
Key limitationAccounts, payments, support, B2B and formal code review excluded.No verification of operating effectiveness over time.SecuFocus has not verified the report’s contents.No further no-logs audit planned; other audits do not replace it.

WireGuard: addresses, keys and connection records

WireGuard uses ChaCha20-Poly1305 for authenticated encryption and Curve25519 for key exchange. That is a well-known technical foundation. It does not, by itself, explain how a commercial service associates a subscription, public key, tunnel address and client network address.

The server needs a return endpoint to send packets back. That live state in memory is different from a file retaining yesterday’s connections. The relevant question is how it is created, renewed and deleted.

Proton documents a shared initial internal address, 10.2.0.2, followed by double NAT that assigns a session-specific internal address before traffic exits to the internet. NordLynx, based on WireGuard, also documents double NAT. These designs aim to avoid a stable internal address becoming a lasting identifier; they do not remove the operator’s intermediary role.

IVPN documents another concrete parameter: its manager resets a peer association when the last handshake is more than 180 seconds old. Default rotation of the key and internal address is 24 hours. Be careful about what that means: 180 seconds since a handshake is not exactly three minutes after your last click. The checking interval and protocol behaviour matter too.

Where does post-quantum encryption stand?

“256-bit” is not a sufficient answer. Encrypting data and establishing the secret are different problems. An adversary can record encrypted traffic today and hope to recover the keys later. Post-quantum protections address that scenario among others.

NIST standardised ML-KEM in FIPS 203 on 13 August 2024. Its inclusion in a protocol does not certify an entire application. A hybrid construction retains a classical mechanism while adding one designed to resist quantum attacks.

In IVPN’s documented design, the additional secret is renewed with the WireGuard keys. Simply seeing “WireGuard” in a router therefore does not establish that it receives the same protection as the official app. The manual configuration guide now explains how to prepare the required keys.

Side by side4 tools · same criteria

Swipe to read the columns. Criteria and names stay visible. With a keyboard, use the arrow keys inside the table.

Where does post-quantum encryption stand?
CriterionProton VPNExpressVPNNordVPNIVPN
Relevant protocolNew engine announced; general deployment not established here.LightwayNordLynxWireGuard
Documented mechanismDescribed as a planned feature.Hybrid ML-KEM exchange.Post-quantum option with NordLynx.KEM-derived PSK: Kyber-1024 and Classic-McEliece-348864.
Stated availability12 August 2026 announcement: still planned.Migration announced in January 2025.Check and enable the option on compatible devices.Enabled by default in the apps.
Check before useA roadmap does not establish an available feature.Do not extend this protection to OpenVPN.Restrictions, including dedicated IP and other protocols.Kyber does not mean ML-KEM. Manual setup needs specifically prepared keys.

RAM, encrypted disks and two hops protect different things

ExpressVPN’s KPMG report describes a writable filesystem in memory whose state disappears on reboot. NordVPN also presents a RAM-based infrastructure. Proton states that its servers use full-disk encryption. These are different designs; describing them all as “RAM-only” would be inaccurate.

RAM reduces what remains on disk after shutdown. Disk encryption protects data at rest. Neither, on its own, neutralises an attacker able to operate on a running machine or copy information elsewhere. Deployment controls, administrator access and monitoring configuration changes remain essential.

Proton’s Secure Core adds a first server controlled by Proton in Switzerland, Sweden or Iceland before the exit. It aims to limit what a compromised exit can directly link to the client’s address. Both hops nevertheless remain under the same provider’s responsibility. An observer watching both sides may also look for timing and volume correlations.

Choose two hops to address a specific risk. They add distance and network transitions; without measurements, we do not quantify the cost on your connection. They do not replace account separation or a system designed for anonymity.

The kill switch after a disconnection

A connection showing “protected” while idle tells only part of the story. Waking from sleep, switching Wi-Fi, losing a server and restarting the application are more revealing. Those are the moments to check whether traffic stays blocked or resumes outside the tunnel.

On Linux, IVPN documents a firewall that can operate on demand or remain always on. That distinction matters: persistent blocking can cover periods before an application establishes a tunnel. Features still differ across operating systems; a Linux property does not become an iOS guarantee.

Split tunnelling deserves the same care. Excluding an application authorises some traffic to take another route. Check that app’s packets, its DNS requests and IPv6 separately. A browser test showing the correct public IP cannot validate every path.

A browser’s encrypted DNS may also change which resolver receives your requests. That does not necessarily mean they leave the tunnel, but it changes the party you trust with them. A DNS result different from the VPN’s should be explained before being called a leak.

Which parts of the code are public?

Proton publishes its application code. IVPN publishes its desktop clients, among other components. NordVPN publishes its Linux client. ExpressVPN publishes Lightway, whose Rust implementation exposes client, server and TLS/DTLS layers. These are useful contributions, but their scopes are not interchangeable.

An open protocol implementation does not mean every screen and function in a commercial application is open. Nor does a public repository prove the installed binary was compiled from exactly that code. For deeper verification, look for matching versions, distribution signatures and documented build reproducibility.

Rust reduces certain classes of memory errors in code covered by its guarantees. It does not set logging policy, fix a wrong firewall rule or prevent a design mistake. The language is one security consideration, not a verdict.

Documented incidents

Three incidents described by the operators illustrate different types of failure. This selection is not exhaustive: a provider’s absence from the table does not mean it has never had an incident.

NordVPN acknowledged the compromise of a rented server in Finland in March 2018. Its account identifies the hosting provider’s remote access as the entry point. The practical lesson is that the data centre belongs to the trust chain, even when the VPN app uses sound encryption.

ExpressVPN fixed a DNS problem associated with split tunnelling in its Windows application in 2024. Its post, updated on 16 April, reports verification of the fix by Nettitude. Server-side no-logs commitments therefore cannot prevent a client-side regression.

On 11 August 2026, IVPN disclosed an incident involving its Bitcoin payment server: 0.6168 BTC of company funds were stolen. Its investigation states that VPN infrastructure and customer data were unaffected. We report that as the operator’s conclusion. Payment, account and tunnel security need separate assessment.

Jurisdiction and access requests

The consulted documents identify Proton AG in Switzerland, Express Technologies Ltd in the British Virgin Islands, nordvpn S.A. in Panama and IVPN Limited in Gibraltar. ExpressVPN also states that it belongs to Kape. These describe responsibilities, not an automatic privacy ranking.

The company’s registered location, the server country, the payment processor and the location of a possible seizure are different questions. A Swiss flag or an address outside an intelligence-sharing alliance does not establish that no data can be obtained.

The amount of retained data remains decisive: an operator that holds no link between a person and their browsing cannot hand over that history. This does not settle what obligations it might face in the future.

How to check behaviour on your device

A single speed result on an unknown connection mostly makes an attractive chart. A serious comparison must disclose the machine, operating system, client versions, protocol, servers and enabled options. Results need to be reproducible and their limitations understandable.

The protocol below suggests checks for your own setup. SecuFocus has not carried it out for this comparison.

  1. Establish a baseline without a VPN on the same Ethernet-connected device. Record line speed, latency and time; avoid competing downloads.
  2. Choose a nearby and a distant server for each VPN. Run at least ten alternating measurements per scenario. Keep the measurement endpoint constant and repeat at different times.
  3. Publish medians and variation in throughput, latency and packet loss alongside the exact settings. Separate single-hop, multi-hop and post-quantum scenarios.
  4. Check the exit IP, IPv4/IPv6 paths and DNS resolvers. Capture non-sensitive test traffic on the physical interface to distinguish the tunnel, DNS and direct traffic.
  5. Trigger sleep, network changes, process termination and loss of connectivity to the server. Observe whether unauthorised packets leave during the transition.
  6. Repeat with split tunnelling and browser DNS if you use them. Document intentional exclusions; do not describe deliberately excluded traffic as a leak.

Which VPN fits your priorities?

If privacy is your primary criterion, I would start by comparing Proton VPN and IVPN on your devices. That shortlist follows from their minimisation approaches and the documentation examined; it is not a speed-test result.

Proton VPN suits someone looking for a documented service and recent verification of its VPN environment, with Secure Core when two hops address a real risk. Keep the tunnel separate from the Proton account in your assessment, and do not rely today on a feature that has only been announced.

IVPN is particularly interesting if you want to limit the identity you provide at signup and understand what happens under the hood. Its WireGuard documentation is valuable. The age of its no-logs audit remains a reservation to accept consciously; other audits do not remove it.

ExpressVPN deserves attention for TrustedServer and Lightway. The decision is whether its declared collection around usage fits your expectations. NordVPN also offers a documented architecture and advanced options; take time to configure app privacy and read each option’s conditions.

For each provider, start with a short plan where possible so you can evaluate the service after reading the terms. Check stability, blocking after a disconnection and the features available on your system before committing for several years.

The questions that come up before choosing

“Which of these four VPNs is best?” No universal winner is demonstrated here. For privacy, our initial shortlist is Proton and IVPN, for different reasons. Actual behaviour on your device may then settle the choice.

“Is a free VPN necessarily less private?” No. Examine its funding model, terms and available evidence. Price alone describes neither the data collected nor the quality of the software.

“Is the fastest also the safest?” These are different properties. This article establishes no speed ranking. Your connection and selected settings require separate measurements.

“Can you trust a no-logs service?” Check how it defines the term, which data falls outside that promise and what the available audits covered. An audit provides evidence about a system at a particular time; it cannot guarantee all of the service’s future behaviour.

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.