The checklist
How to judge a VPN, including this one
Much of the comparison material for VPNs carries an affiliate link. Its criteria tend to get picked because they produce a ranking, not because they tell you anything.
Server totals, country totals, cipher names and award badges are all easy to put in a table. None of them describes what you're about to depend on.
So here's a checklist. You can score a provider against it in a few minutes of reading their own pages.
We wrote it to be useful even if you finish it and buy a competitor, because a checklist only one product can pass is an advertisement. Where we do badly on a line, the line says so.
Ask which protocol, then stop asking about encryption
The protocol is the one technical answer worth insisting on. The rest of the product sits on top of it.
A current answer is WireGuard. It fixes its cryptographic choices in advance, so there's nothing to negotiate. Its handshake is a single round trip. And it's deliberately small, which is what makes it feasible at all to read the implementation, not the marketing.
What about a provider that leads with an in-house protocol nobody outside the company has examined? That's a larger claim with less to check it against.
Once the protocol is named, questions about encryption strength have almost no information left in them. 'Military-grade encryption' has no technical content.
The primitives involved are the ordinary ones already carrying banking, messaging and everyday web traffic. You have no way to turn the phrase into a difference between two products. A provider that spends its most prominent space on something that distinguishes nothing has told you where its attention goes.
We use WireGuard. So does anyone else who answers this question with a current protocol. Say you're comparing us with one of them. Read honestly, this line is a tie, and we don't get to count it as a win.
Note
Most of what follows can't be verified from outside. What you're really judging is whether a provider's account of itself is specific enough to be proved wrong.
Separate what a provider can see from what it promises
A VPN moves the point where your traffic enters the public internet. That point is a machine the provider operates. So by construction, the provider is positioned to observe which addresses it forwards to on your behalf.
No policy changes that. A policy only governs what's done with the position.
This split is what most comparison tables miss. A claim about visibility is a claim about architecture, and you can reason about it from first principles. A claim about retention is a claim about behaviour. You can't check it from outside at all.
The same goes for name resolution. Clean Web, a switch in the app, sends your lookups to our own resolver, which refuses known ad and tracker hosts, so no socket is opened. It starts on in the Android app and off on iPhone, iPad, Mac and Windows. With it off, your lookups go through the tunnel to a public resolver instead.
For example, say an app on your phone asks for a known tracker's hostname. The resolver refuses, and no connection is made. That's a real benefit at the network level. It also means the resolver is a component with a view.
Both things are true at once. A provider that tells you only the first half is selling.
Ask for the column list, not the adjective
'No logs' is an adjective. The useful question is which fields exist in the database.
A provider that answers specifically has described something that could be contradicted. A provider that answers with reassurance hasn't. A good answer names what's stored, what's kept for billing, and how long the rest survives.
Here's ours. We write one row per connect and one per disconnect. Each holds an account identifier, a timestamp, the event type and status, which exit was used, the session duration, the platform and the client version. A row can also carry an error message, a session ID that pairs the connect with its disconnect, and a disconnect reason.
Suppose you connect to Frankfurt at 9:00 and disconnect at 9:40. That's two rows. Between them they record your account identifier, both times, each event's type and status, the Frankfurt exit, a 40-minute duration, your platform and your client version.
Those rows don't hold a destination, a visited site or a DNS query. They aren't the whole ledger, though. Our nodes run a permanent packet capture to build usage figures. Once an hour it becomes an aggregate that includes the outside addresses reached and the domains resolved.
That aggregate is keyed to the 10.x address we assign your device inside the tunnel, and each node names those addresses by account and device, so treat it as linked to your account. We keep it for 90 days. Your originating public address is stored too. It sits with the session token that keeps your app signed in, in a record we write each time you sign in, and in our API's request log. Your account holds your email, the name and photo your Apple or Google sign-in shares, and your plan. We keep a record of each device too: its name, platform, last exit and when it was last seen. And our apps send usage events and crash reports to Google's Firebase under your account ID. On Android and Windows, each session's summary includes the exit, duration, data used and tunnel address.
Part of what that specificity exposes is unflattering. There's no automatic purge on that table, so those rows sit on no retention clock. If your bar is 'nothing is kept', mark this against us.
So why publish the shape anyway? Because a vague claim can't be held to anything. A list of fields can.
Find out who owns it and how the money arrives
Ownership is the cheapest thing to check and the most often skipped. Who is the operating company, and who owns it? The answer is usually several clicks away from the pricing page.
Shared ownership between brands isn't disqualifying in itself. Neither is a review site having a commercial relationship with what it ranks. Both are worth establishing before you treat two entries in a comparison as independent opinions.
Revenue matters more. Relaying traffic costs money continuously. Volume is billed at the exit, and each exit carries a monthly bill whether anyone routes through it or not.
A subscription bought inside an iPhone or Android app is processed by Apple or Google. They take a commission before the provider sees anything. So the headline price isn't the figure the provider works with.
Say you buy our monthly plan inside the iPhone app. Apple processes the payment and takes its commission first. What reaches us is less than the 3.99 US dollars you paid.
Where a service is free and unmetered, the arithmetic has to close some other way. The options are few: a bounded free tier whose cost is absorbed, a loss-leader funded by subscribers, or an arrangement in which the traffic itself has value to someone.
That's a constraint on every provider. It isn't an accusation about any of them.
Can the provider name the exits, or only count them?
A count is the easiest number to inflate and the hardest to use. Nobody connects to a fleet. Your session runs through one machine. So the question that bears on your experience is whether a well-provisioned exit sits near you or near the service you're reaching.
A total in the thousands, spread across dozens of countries, describes a cost structure. It leaves you no way to work out whether any of it helps.
So ask for the list. A provider willing to publish which cities it terminates traffic in has made a statement you can check against a traceroute. That statement becomes embarrassing if a location turns out to be an address block announced from somewhere else. A provider publishing only a total has kept the claim safely unfalsifiable.
Our list is short, and it changes as we add and retire servers, so the region list in the app is the one to trust. Naming exits is the easy part. The next section is where a short list stops looking good.
Where this checklist goes against us
A short list is fine, and the shape of the gaps matters more than the total. Whole regions of the world have no exit of ours, so check the region list for the places you need before you pay.
Say you're in Dubai, Lagos, Mumbai or Toronto. Your nearest option is thousands of kilometres away, and a round trip pays that distance twice. No protocol removes the floor that distance sets.
On this line, a provider with a genuine nearby exit is the better purchase. If you're in one of those places, you should buy it.
We don't have a kill switch. If the tunnel drops, your traffic can continue over the ordinary network. Nothing holds it until the tunnel returns.
If you're browsing on a hotel network, that's an inconvenience. If you require that packets either go through the tunnel or go nowhere, it's a reason to choose something else.
Our server issues the configuration, and it includes the tunnel's private key. In a stronger design, the device generates its own key pair and sends only the public half. That design is stronger on exactly this axis, because the key material need not exist anywhere but the device.
We don't work that way. If you're ranking providers on key custody, rank us below those that do.
- A short exit list, with whole regions left with no exit at all.
- No kill switch, so a dropped tunnel doesn't hold your traffic.
- Server-issued configuration, private key included. Your device doesn't generate its own key pair.
- We write connection metadata, and there's no purge schedule on the table holding it.
- No split tunnelling and no multi-hop, if either is on your list.
Does the pricing page show the renewal price?
The surprise worth looking for isn't a hidden fee. It's a hidden second year: a headline monthly figure that turns out to be a long prepayment divided up. The rate it renews at is set out somewhere less prominent than the rate it starts at.
The test is simple. Find the renewal price before you pay, and treat its absence as the answer.
Read trials the same way, because copy tends to float a trial free of the plan it belongs to. Our seven-day trial attaches to the monthly plan and to that plan alone. The weekly plan and the day pass carry none.
Our prices are flat and don't step up: 1.99 US dollars a week and 3.99 a month, plus a 0.99 day pass on Android. Every plan reaches the whole region list with no device limit, and paid plans add unlimited session length.
Short plans are a worse business to run than annual ones. With a weekly plan, one acquisition cost is spread over a week. With an annual plan, it's spread over a year. That's part of why the annual plan is the one most pricing pages are built around.
Is the free tier bounded in a way that explains how it's paid for?
A free tier is a good place to read a company's economics, because the limits are where the cost control lives. Hours cost money. Accounts don't.
A free tier capped in hours is being paid for by the cap. An unmetered one is being paid for by something the page hasn't mentioned.
So ask whether the published limits are the kind that would contain a bill. A speed cap degrades the experience without necessarily reducing total bytes. A device cap limits convenience, not volume. An hours cap maps directly onto the dominant variable cost.
We allow three free sessions a week, shared across all your devices. Each is a one-hour window that starts when you connect and keeps running if you disconnect, so three hours is the most you'll get. Every location is on the list, the same as on a paid plan.
Those limits are restrictive. The point is that they're legible. You can see what's given away and work out that it's affordable to give.
Lines to cross off the comparison entirely
Several of the criteria that comparison tables lean on hardest carry no information at all. Cross them off. Your reading gets considerably shorter, and that makes room for the questions above. Those are fewer, and harder to answer with a logo.
- Server and country totals. One machine serves your session, so the total describes the provider's costs. It doesn't describe anyone's experience.
- Cipher names and 'military-grade' phrasing. The primitives are shared across the industry and across the rest of the web.
- Speed claims. You can't reproduce a throughput figure measured on an unnamed route with unnamed hardware. And distance sets a floor marketing can't move.
- Award badges and press logos. These record a relationship with a publication. They aren't a property of the software.
- Feature lists with no page behind each item. If you can't find a named feature documented, it's a word in a table.
What you're actually judging
You can't verify most of this checklist from a browser. Nobody outside a provider can inspect its database, watch its exit machines, or confirm a deletion happened.
Independent audits narrow the gap, and they're worth more than a self-description. But an audit is a point-in-time report on a scope the company chose and paid for. That isn't continuous proof.
That leaves a less satisfying but more usable criterion. Is a provider's account of itself specific enough to be wrong?
'We keep no logs' can't be contradicted by anything. A list of stored fields can. A country total can't be tested. Ten named cities can.
Specificity doesn't demonstrate honesty. It does create a way for dishonesty to be caught, and vagueness removes it.
Apply this consistently and it reorders the market. Some well-marketed providers become hard to evaluate at all, and some small ones become easy. It applies to this page too, including the lines above where our specific answer is the unfavourable one.
What it costs
Short plans, priced so a week costs what a week is worth. Cancel any time in your store settings.
$1.99per week
$3.99per month
No annual subscription. No long-term commitment.
7-day free trial
See all plansCommon questions
What's the single most useful question to ask a VPN provider?
Ask which fields their connection database actually contains. It's specific, and you can compare a straight answer against their own privacy page. An evasive answer is informative in itself. A provider comfortable listing fields is describing something that could be contradicted.
Does a bigger server count mean a better VPN?
It mostly describes the provider's cost structure. Your session runs through one exit, so what matters is whether a well-provisioned exit sits near you or near the service you're reaching. Capacity spread thinly across many locations can serve people worse than a shorter, properly resourced list.
Is a no-logs claim worth anything if you can't verify it?
A little, and more when it's specific. An unfalsifiable claim gives you nothing to hold a provider to. A named list of stored fields can be compared against the privacy policy, the app and whatever an audit examined. Specificity doesn't prove honesty. It makes dishonesty catchable.
Where does WrapVPN do badly on this checklist?
Five places. Our exit list is short, and whole regions of the world have no exit of ours. We don't have a kill switch. Our server issues the tunnel configuration, private key included, so the key isn't generated on your device, and that's weaker on key custody. We write connection metadata, with no purge schedule on that table. And our nodes capture traffic to build hourly usage figures that include the addresses and domains reached.
Should you buy WrapVPN after reading this page?
Not if a nearby exit matters to you and our nearest one is thousands of kilometres away. And not if a kill switch or device-held keys are requirements for you. Our plans suit you if you want a VPN for days or weeks, not for a year, on a list covering Europe, Asia-Pacific, North America and South America.
Do independent audits settle the question?
They help more than a self-description, and less than they're presented as doing. An audit is a report at one moment, on a scope the company selected and funded, by a firm it hired. Read which scope was examined and what was left out. That's usually more informative than the headline that an audit happened.
Get WrapVPN
One account covers your phone, tablet and computer. Connect in a tap, from any of our regions.
Keep reading
Closely related pages, chosen because they answer the question this one raises next.
Guide
What you are actually paying for with a VPN
Where the money goes in a consumer VPN, and what that explains about free tiers, annual discounts and the server counts in the advertising.
Guide
What WireGuard is, and why it connects instantly
WireGuard fixes its cipher suite instead of negotiating one and shakes hands in a single round trip. What that buys you, what it costs, and where the promise ends.
Plans
A VPN without an annual commitment
Why VPN prices are quoted as if you will prepay for years, what that costs you at renewal, and how a daily, weekly or monthly cycle works instead.
Guide
Why almost every VPN is sold by the year
Why VPN pricing converged on discounted annual terms, how to read a per-month figure, what changes at renewal, and when a short plan is the wrong purchase.