Trusted or Tracked? The Hidden Truth About the VPN Industry
Photo: VPN padlock digital privacy network security abstract, via www.sunsetresortrentals.com
Every day, millions of Americans open a VPN app and assume they have vanished from the internet. The padlock icon appears, the server location flips to Amsterdam or Singapore, and a quiet confidence sets in. That confidence, however, may be largely unearned. The virtual private network industry — worth an estimated $45 billion globally — is built on a foundation of marketing language that frequently outpaces the technical and legal reality it describes.
This is not an argument against VPNs categorically. When implemented honestly and chosen carefully, they serve a legitimate purpose. The problem is that the marketplace is saturated with products whose privacy guarantees dissolve the moment they are scrutinized.
The 'No-Log' Promise and Why It Often Falls Short
The phrase "strict no-log policy" appears on nearly every VPN vendor's homepage. It implies that the provider retains zero records of your browsing activity — that even if compelled by a government subpoena, the company would have nothing to hand over. In practice, this claim exists on a spectrum ranging from technically accurate to demonstrably false.
In 2023, a well-known VPN provider that had prominently advertised a no-log policy was revealed to have cooperated with law enforcement by supplying connection timestamps and originating IP addresses. The company's defense was that it logged "connection metadata" rather than "browsing content" — a distinction its marketing material had never made clear to consumers.
This is not an isolated incident. Researchers at the Top10VPN organization and independent security journalists have repeatedly identified providers whose privacy policies, when read carefully, permit logging of connection times, bandwidth consumed, and even DNS queries. Each of those data points, assembled together, can reconstruct a meaningful portrait of a user's online behavior.
The lesson is straightforward: a privacy policy is a legal document, not a marketing brochure. Reading it — particularly the sections governing data retention, third-party sharing, and law enforcement cooperation — is non-negotiable before committing to any provider.
Follow the Ownership Trail
Perhaps the most underreported dimension of the VPN industry is its ownership landscape. Over the past decade, a small number of holding companies have quietly acquired dozens of consumer VPN brands, creating the illusion of competitive choice in a market that is, in fact, heavily consolidated.
Kape Technologies, formerly known as Crossrider — a company that itself had a documented history of distributing adware — now owns CyberGhost, ExpressVPN, Private Internet Access, and ZenMate, among others. Aura, a US-based consumer safety conglomerate, controls Hotspot Shield and several related products. J2 Global, now known as Ziff Davis, owns IPVanish and StrongVPN.
Consolidation is not inherently sinister. But it raises legitimate questions. When a single corporate parent controls multiple VPN brands that compete for the same privacy-conscious customers, are those customers genuinely receiving independent products built on distinct philosophies — or are they choosing between labels on the same bottle?
More critically, corporate ownership determines legal jurisdiction. A VPN headquartered in a country that is a member of the Five Eyes, Nine Eyes, or Fourteen Eyes intelligence-sharing alliances — the United States, United Kingdom, Australia, Canada, New Zealand, and their partners — is subject to national security demands that may never become public. A provider may be entirely truthful when it says it has never voluntarily shared data with authorities while remaining silent about data it was legally compelled to produce under a gag order.
The Free VPN Trap
Free VPN services deserve particular scrutiny. Operating a reliable VPN infrastructure is expensive. Servers cost money. Bandwidth costs money. Engineers cost money. When a product is offered at no charge, the business model almost always involves monetizing the user in some form.
A 2019 study published by the Commonwealth Scientific and Industrial Research Organisation analyzed 283 free Android VPN apps and found that 38 percent contained malware or malware-adjacent code, 84 percent leaked user traffic in detectable ways, and 18 percent did not encrypt user data at all — despite claiming to do so. Several of those apps had been downloaded millions of times from the Google Play Store.
Some free VPN providers have been documented selling anonymized — though frequently re-identifiable — browsing data to advertising data brokers. Others have been caught injecting tracking cookies into user sessions. The very infrastructure that users trusted to protect their privacy was being used to surveil them commercially.
A Framework for Evaluating Providers
Given this landscape, how should a privacy-conscious American consumer approach VPN selection? The following framework is a useful starting point.
Jurisdiction matters. Providers incorporated in Panama, the British Virgin Islands, or Switzerland operate under legal frameworks that are generally more resistant to foreign intelligence requests than US or UK-based entities. This does not make them immune, but it raises the evidentiary bar meaningfully.
Audits must be independent and recent. Several reputable providers — Mullvad, ProtonVPN, and IVPN among them — have commissioned third-party security audits from firms such as Cure53 or SEC Consult and published the results publicly. An audit conducted three years ago by a firm the company hired and paid for is considerably less reassuring than a recent, independent review with a published methodology.
Open-source clients enable scrutiny. When a VPN's client application is open source, independent researchers can verify that the code does what the company claims. Mullvad and ProtonVPN both publish open-source clients. Closed-source applications require users to accept the company's word entirely.
Business model transparency is a signal. Providers that generate revenue exclusively through paid subscriptions have less incentive to monetize user data than those with advertising partnerships or unclear funding sources.
Warrant canaries have limits. Some providers maintain "warrant canary" statements — periodic attestations that they have not received government demands. These are better than nothing, but they are not a comprehensive privacy guarantee.
What a VPN Actually Protects — and What It Does Not
Even the most reputable VPN has significant limitations that users must understand. A VPN masks your IP address from the websites you visit and encrypts the connection between your device and the VPN server. It does not make you anonymous. It does not prevent browser fingerprinting, tracking cookies, or account-based surveillance. If you are logged into Google while using a VPN, Google still knows exactly who you are.
For genuinely high-stakes anonymity needs, security researchers and journalists often recommend pairing a trustworthy VPN with the Tor Browser — a combination that distributes trust across multiple layers rather than concentrating it in a single commercial provider.
The core message from CipherWatch is this: a VPN is a tool, not a talisman. Its value depends entirely on the integrity of the provider offering it, the legal environment that provider operates within, and the user's clear-eyed understanding of what that tool can and cannot accomplish. Treat every no-log claim as a hypothesis to be verified — not a promise to be trusted.