Is NordVPN Safe? Audits, Encryption, and the 2018 Breach Explained

Is NordVPN Safe? Audits, Encryption, and the 2018 Breach Explained

Is NordVPN safe? Yes, it is a safe choice for most people. The evidence is an independently audited no-logs policy, RAM-only servers, a Panama base, and how the company responded after a 2018 server breach.

We check every VPN the same way before it earns a recommendation. We ran IP, DNS and WebRTC leak tests on ipleak.net across 12 NordVPN servers, and none of them leaked. Below, we explain who owns the service, what data it keeps, and where its record has weak spots.

Is NordVPN Safe to Use? The Short Answer

Is NordVPN safe to use for browsing, public Wi-Fi, streaming and torrenting? Yes. Keep its kill switch on and know what a VPN can and cannot do.

This page covers safety only. For speed results, streaming tests and plan details, read our NordVPN review.

NordVPN Safety Pros and Cons

Here is how the audits and incidents balance out.

Pros

  • No-logs policy verified by six independent assurance engagements
  • Every regular server runs from RAM, so data does not survive a reboot
  • Panama jurisdiction with no mandatory data retention law
  • Kill switch and DNS leak protection held up when we forced the connection down
  • Optional post-quantum encryption on NordLynx
  • Public bug bounty plus repeated Cure53 penetration tests

Cons

  • A 2018 server breach that stayed undisclosed until October 2019
  • Steep renewal pricing, with auto-renewal on by default
  • Full Threat Protection Pro sits in the higher tiers only
  • No port forwarding for torrent setups that need it
  • Past advertising overstated how dangerous public Wi-Fi is

Is Nord VPN Legit? Who Owns It and Where It Is Based

Yes, NordVPN is a legitimate company with a traceable ownership chain. Lithuanian founders Tomas Okmanas and Eimantas Sabaliauskas launched it in 2012. Anyone asking "is Nord VPN legit" can follow that trail to today's parent company.

The same founders created Tesonet, a startup accelerator that supported NordVPN early on. Tesonet does not own it today. NordVPN sits under Nord Security, which raised $100 million in 2022 in a round led by Novator Ventures. That same year, Surfshark and Nord Security merged under one holding company.

Nord Security and the Panama Jurisdiction

NordVPN operates under Panama's jurisdiction through a Panama-registered company. Panama has no mandatory data retention law, so the company is not required to store user activity. The country also sits outside the Five Eyes intelligence-sharing alliance, the surveillance pact between the US, UK, Canada, Australia and New Zealand.

Nord Security itself, though, is headquartered in the Netherlands. Jurisdiction is only as strong as the no-logs setup behind it, so we weigh the audits more heavily. Past behavior helps too. NordVPN shut its Russian servers in 2019 rather than join the state censorship registry. It pulled its India servers in 2022 after CERT-In ordered VPNs to retain user data.

A simple diagram showing Nord Security as the parent company in the Netherlands, with NordVPN operated by a Panama-registered company.

What Data Does NordVPN Collect?

NordVPN collects only the account data it needs to bill you. According to NordVPN's privacy policy, it stores your email address, username, encrypted login credentials, billing information and an order ID for refunds. None of that describes what you do online.

There is one short-lived exception. The service keeps your username and a session timestamp to enforce its limit of 10 simultaneous connections. That record is deleted within 15 minutes after the session ends.

What the No-Logs Policy Covers

A no-logs policy is a promise that the VPN does not record your activity while connected. NordVPN says it does not track your IP address, the servers you use, the websites you visit, the files you download or your time online.

That promise matters most when someone comes asking. In January 2022, NordVPN clarified that it complies with valid legal requests. It also said it has no activity logs to hand over.

Independent Audits and Transparency Reports

A no-logs claim only means something when outsiders check it. NordVPN has completed six independent no-logs assurance engagements. PricewaterhouseCoopers (PwC) ran the first in November 2018 and a second in 2020. Deloitte handled the next four.

The most recent was Deloitte's no-logs audit, run by Deloitte Lithuania under the ISAE 3000 (Revised) standard. Fieldwork ran from November 10 to December 12, 2025, and results were announced in February 2026. Deloitte interviewed staff and inspected server configurations and technical logs, including Double VPN, Onion Over VPN and obfuscated servers. It found those systems match the no-logs statement.

Security testing runs on a separate track. VerSprite's 2020 app penetration test found no critical issues. Cure53's 2024 app assessment, published March 7, 2025, found none either. Cure53's 2025 security assessment used 19 testers on apps and servers and found five high-severity flaws, all fixed and re-verified.

Independent audits and security assessments of NordVPN by auditor, year and scope
Auditor Year Scope
PwC2018, 2020No-logs policy
VerSprite2020Apps and API
Deloitte2022 to 2024No-logs policy
Cure532024, 2025Apps, extensions, servers
Deloitte2025 (published February 2026)All server types

The company also publishes its transparency reports, which replaced its old warrant canary. Between January and April 2024, NordVPN received 81 inquiries from government institutions. None resulted in disclosure of user information.

How Secure Is NordVPN? Encryption and Protocols

At the encryption layer, NordVPN is as secure as any mainstream VPN we test. Every protocol it offers uses modern, standard ciphers. So how secure is NordVPN day to day? Mostly that depends on the protocol you pick and the settings you leave on.

AES-256 Encryption

AES-256 is a cipher with a 256-bit key, and it is the standard most security teams rely on. NordVPN's OpenVPN connections use AES-256-GCM with a 4096-bit Diffie-Hellman key. IKEv2/IPsec also uses AES-256-GCM, with perfect forward secrecy through 3072-bit Diffie-Hellman. Forward secrecy gives each session fresh keys, so one stolen key cannot unlock the others.

NordLynx, OpenVPN, and IKEv2/IPsec

NordLynx is the default protocol in most NordVPN apps. It is built on WireGuard and uses ChaCha20-Poly1305 encryption. WireGuard normally keeps a user's IP address on the server, so NordVPN adds a double-NAT system that avoids storing it.

OpenVPN remains available over UDP and TCP, and IKEv2/IPsec appears on some platforms. For restrictive networks that block VPN traffic, NordVPN added NordWhisper in 2025.

NordVPN's Windows app settings screen with the VPN protocol dropdown open, listing NordLynx, OpenVPN UDP, OpenVPN TCP and NordWhisper options.

Post-Quantum Encryption

NordVPN first shipped post-quantum encryption on Linux in September 2024. It reached all its main apps in May 2025. The hybrid scheme adds NIST's ML-KEM standard (FIPS 203) to NordLynx, aiming to protect today's traffic from future quantum computers.

It works with NordLynx only, not with OpenVPN, Dedicated IP, obfuscated servers or Meshnet. The default state has varied across app versions. Check the toggle under Settings, then Connections, rather than assuming it is on.

Kill Switch and DNS Leak Protection

Encryption guards traffic inside the tunnel, and a kill switch keeps it from leaking outside. It blocks all traffic the moment the VPN connection drops, so your real IP address never slips out. NordVPN's version held up in our testing. When we deliberately crashed the connection with the system-level kill switch on, our real IP stayed hidden.

We ran the same forced-disconnect check with both kill switch options on Windows. The Internet Kill Switch blocks all traffic, while the App Kill Switch closes only chosen apps and is off by default. Both stopped data from leaking. Our explainer on how a VPN kill switch works covers the difference.

Coverage differs by device. iOS has a system-wide kill switch that is on by default but no per-app option. Android 8.0 and later handle it at the system level, and the Fire TV Stick app has none.

DNS leak protection keeps your lookups inside the tunnel. In our checks, the IP address changed correctly and no IPv6 leaks appeared. DNS requests went to NordVPN's own servers rather than our ISP's.

Tip

Run a leak check yourself after any app update or network change. Connect to NordVPN, load a leak-test site, and confirm every DNS server listed belongs to NordVPN. Our guide shows how to test your VPN for DNS leaks step by step.

An ipleak.net results page while connected to a NordVPN server, showing a NordVPN IP address, NordVPN DNS servers and no WebRTC or IPv6 address exposed.

RAM-Only Servers, Double VPN, and Onion Over VPN

Leak protection guards the tunnel, while RAM-only servers guard what is left on the server. They run from memory instead of hard drives, so everything on them is wiped at each restart. NordVPN moved all its regular servers to RAM by 2020, so a seized server holds no old data. In October 2020, it also began deploying colocated servers it owns outright, starting in Finland.

Double VPN sends your traffic through two servers, adding a second layer of encryption. That layer costs speed. In our testing, Double VPN cut speeds by up to about 80%. The app also showed only the exit location, not the middle server.

Onion Over VPN routes your traffic into the Tor network after it leaves the VPN. For a wider tour of these features and the rest of the toolkit, see our rundown of what NordVPN does.

Threat Protection: Malware, Tracker, and Phishing Blocking

Beyond the tunnel itself, Threat Protection is NordVPN's built-in cybersecurity layer, added in February 2022. It blocks malicious sites, phishing pages, ads and trackers, even when the VPN is disconnected. Threat Protection Pro adds malware scanning of downloads, but plan contents vary by region, and the full Pro version sits in the higher tiers.

We found it does most of what it promises. It stripped almost all ads from ad-heavy news sites and flagged a harmful download before the file could run. The antivirus also caught EICAR test files and a test phishing page with the VPN off. Ad and tracker blocking scored 90/100 on AdBlock Tester, though YouTube pre-roll ads still got through.

Lab results back this up. In AV-Comparatives' Anti-Phishing Certification 2026, Threat Protection blocked 96% of phishing URLs with zero false positives across 200 banking sites. Its 2025 annual average in that lab was 90%.

A NordVPN Threat Protection alert on Windows reporting that a downloaded file was flagged as malware and blocked before it could open.

The 2018 Server Breach: What Happened and What Changed

Much of NordVPN's current security setup grew out of its worst incident. In March 2018, an attacker got into a single rented NordVPN server in a Finnish data center run by Creanova. The attacker used an insecure remote management system the provider had left on the machine. NordVPN says it did not know that system existed.

NordVPN did not disclose the intrusion until October 21, 2019, after the leaked key surfaced on Twitter. It said it learned of the breach a few months earlier and waited to check the rest of its network for the same flaw. That delay is the fairest criticism of how it handled the incident.

Good to know

What the 2018 breach did and did not expose: the attacker obtained an expired TLS key, plus OpenVPN configuration files and keys from that one server. In theory, that key could have enabled a man-in-the-middle attack on that server's users. There is no evidence such an attack took place, and the server held no user credentials or activity logs.

The response was concrete. NordVPN ended its Creanova contract, shredded every server rented there, and launched a public bug bounty on HackerOne on December 9, 2019. Recurring audits, the RAM-only rollout and owned hardware followed.

Is Nord VPN Safe for Banking, Torrenting, and Public Wi-Fi?

Yes, NordVPN is safe for all three, with a few practical limits. Is Nord VPN safe for online banking in particular? Mostly, though that depends more on your bank. Some banks flag logins from VPN IP addresses, so pick a nearby server in your own country.

For torrenting, NordVPN offers P2P-optimized servers. On one of them, we downloaded a 1.16GB copyright-free file in under 3 minutes. The missing port forwarding is the main limit.

On public Wi-Fi, a VPN encrypts your traffic so others on the network cannot read it. Keep perspective, though: in 2019, the UK Advertising Standards Authority ruled a NordVPN TV ad misleading for implying public Wi-Fi is inherently insecure.

One caveat covers all three. Apps you exclude through NordVPN split tunneling are not protected by the tunnel. On Android, split tunneling worked as intended for us, routing one browser through the VPN while another bypassed it. The feature is not available on iOS.

NordVPN Android split tunneling screen with one browser routed through the VPN and another excluded.

Customer Support and the 30-Day Money-Back Guarantee

When you do need help, support is quick to reach. Live chat connected us to an agent within about a minute, and email replies took 3 to 24 hours. For common connection problems, our list of fixes for NordVPN not connecting solves most issues without a ticket.

Every plan includes a 30-day money-back guarantee. When we requested a refund through live chat inside that window, it was processed in about five days without pushback. Plans start at $3.49 per month on the 2-year Basic plan.

The billing side needs more care. Renewal is noticeably higher than the intro price, and auto-renewal stays on unless you switch it off. Several US class actions allege deceptive auto-renewal practices, though these remain unresolved allegations.

NordVPN's live chat window open on the support site, with an agent replying to a refund request inside the 30-day money-back period.

NordVPN Alternatives Worth Considering

NordVPN is not the only audited option, and the right alternative depends on what you value most. For a provider with a different jurisdiction, read our explainer Is Proton VPN safe?. If you want the leanest account setup, our Mullvad VPN review covers a privacy-first service.

For a mainstream option at a similar price, compare our ExpressVPN review. For a wider shortlist ranked on privacy, see our roundup of no-logs VPNs we tested.

Final Verdict: Can You Trust NordVPN?

The bottom line is that you can trust NordVPN for normal privacy needs. Its record since 2019 shows a company that learned from its worst mistake.

It is a weaker fit in three cases. Journalists or activists facing state-level threats should pair any VPN with Tor. Users in China should know that access is unreliable even with obfuscated servers. Anyone who dislikes managing subscriptions should set a renewal reminder.

If you sign up, take a few minutes to set it up properly. Turn on the Internet Kill Switch, check the post-quantum toggle, and switch off auto-renewal until you decide to stay.

NordVPN logo
NordVPN
The 30-day money-back guarantee gives you a risk-free month to run your own leak test before you commit.
$3.49/mo2-year plan
Check price →

Frequently Asked Questions

Is Nord VPN safe to use in 2026?
Yes. In January 2026, an actor on BreachForums claimed to have stolen data from a NordVPN Salesforce development server. NordVPN said the files were dummy data from a third-party vendor trial never connected to production, with no customer data involved.
Is NordVPN legit or a scam?
It is legit. Trustpilot rates NordVPN 4.2 out of 5 across about 50,660 reviews. Most complaints there concern billing, especially unwanted auto-renewals and refunds, rather than security.
Is NordVPN owned by China?
No. No part of its ownership chain leads to China. The practical China link runs the other way: China restricts VPN use, and NordVPN access there is unreliable.
Can I be tracked while using NordVPN?
A VPN hides your IP address, but it does not stop tracking inside your browser. Websites can still identify you through cookies, logged-in accounts and browser fingerprinting.
Has NordVPN ever been hacked?
The 2018 intrusion is the only confirmed breach of its own systems. In November 2019, about 2,000 NordVPN logins appeared online, but they came from credential stuffing with passwords leaked elsewhere. A unique password prevents that kind of takeover.
Which independent firms have audited NordVPN?
PwC, Deloitte, VerSprite and Cure53. The HackerOne bug bounty adds ongoing outside testing, with launch payouts of $100 to $5,000 or more per bug.
Does NordVPN sell or share my data?
Its no-logs design leaves no browsing history to sell or share. Your billing details do pass through a payment processor, so NordVPN also accepts cryptocurrency through CoinPayments for more anonymous payment options.
Should I leave NordVPN on all the time?
For most people, yes. Speed loss on nearby servers is small, around 3 to 5%. Distant servers such as Australia can take up to 45 seconds to connect, and Quick Connect avoids faulty servers better than manual picks.
Can I try NordVPN risk-free?
Yes, through the 30-day money-back guarantee. On Android and iOS, the app stores may also offer a 7-day free trial, depending on store and region. It converts to a paid subscription unless you cancel first.