Back to the Bitdefender VPN review

Research record

What the public record says about Bitdefender VPN privacy and security

We read what auditors, courts, security researchers and the press have published about Bitdefender VPN, then kept only the claims that two separate sources back. This is a record of what is published, not a lab test.

Claims researched
19
Cleared for this page
4
Separate sources behind them
9
Research completed
October 3, 2026

What the evidence supports

Claims that two or more separate sources back

Each statement below is followed by the sources it rests on. A verdict describes what the sources say. It is not our endorsement.

Ownership and jurisdiction

Where the company is incorporated, who owns it, and which laws reach it.

Sources agree

Bitdefender VPN is operated by Bitdefender S.R.L., headquartered in Bucharest, Romania (an EU member state, outside the Five/Nine/Fourteen Eyes alliances), which Bitdefender's policy says processes personal data under EU GDPR.

2 separate sources: PCMag and Wikipedia

Sources and caveats (4)
  1. Bitdefender · Provider own statement · Published August 18, 2026

    15A Sos. Orhideelor, Orhideea Towers Building, 10-12 floors, 6th District, Bucharest, Romania

    Listed for context, adds no independence

    Conflict of interest: The provider describing its own practices.

  2. PCMag · Analysis · Published August 16, 2023

    Bitdefender Premium VPN is owned by Bitdefender SRL, which is based in Romania and operates under Romanian law.

    Counts toward the two-source rule

    Conflict of interest: PCMag is owned by Ziff Davis, which also owns IPVanish (the review carries an editors note saying so); affiliate links on review pages were not checked. The review is dated August 2023, before the August 2026 privacy policy that names IPVanish.

  3. Wikipedia · Analysis · No publication date stated

    Headquarters in Bucharest, Romania Type Private

    Counts toward the two-source rule

    Conflict of interest: Encyclopedia article; cites Business Review (Romanian) for the 2017 Vitruvian stake.

  4. Bitdefender · Provider own statement · No publication date stated

    Bitdefender has a privacy-friendly jurisdiction sitting outside of the 5/9/14 eyes

    Listed for context, adds no independence

    Conflict of interest: Marketing page of the provider.

Researcher notes

Corporate jurisdiction only. A VPN's processor (Hotspot Shield / Pango in Delaware and Boston, IPVanish / Ziff Davis in the US) may be under US jurisdiction; Tech Advisor and Tom's Guide both flag the Hotspot Shield US link. Romanian and EU data-retention law exposure was not researched (see not_covered). The 5/9/14 Eyes statement is Bitdefender's marketing and describes where Bitdefender sits, not the backend.

Sources agree

The Hotspot Shield service reviewers identify as Bitdefender VPN's backend belongs to Pango, which Aura acquired in 2020 and spun out on 3 September 2024 before merging with Total Security into Point Wild on 12 December 2024; PCMag (2023) describes Hotspot Shield as Aura's.

3 separate sources: PCMag, Aura, and Point Wild

Sources and caveats (3)
  1. PCMag · Analysis · Published August 16, 2023

    Aura's Hotspot Shield VPN provides Bitdefender with the underlying infrastructure and technology

    Counts toward the two-source rule

    Conflict of interest: PCMag is owned by Ziff Davis, which also owns IPVanish (the review carries an editors note saying so); affiliate links on review pages were not checked. The review is dated August 2023, before the August 2026 privacy policy that names IPVanish.

  2. Aura · Provider own statement · Published September 3, 2024

    Aura today announced that it has split the company into two, standalone entities: Aura

    Counts toward the two-source rule

    Conflict of interest: Owner announcing its own split.

  3. Point Wild · Provider own statement · Published December 12, 2024

    Point Wild’s brands include Total AV, HotSpot Shield, UltraAV, Betternet, CyEx, Simpluris, Comparitech and more.

    Counts toward the two-source rule

    Conflict of interest: Owner announcing its own merger.

Researcher notes

Applies to Bitdefender only if Hotspot Shield is still the backend (see T3-01). Comparitech is owned by Point Wild and is not used. Point Wild is a US company; see providers/hotspot-shield.json T5-01/T5-02 for the full chain and legal-entity detail.

Sources agree

IPVanish, the data processor named in Bitdefender's 2026 privacy policy, is owned by Ziff Davis, Inc. under its VIPRE Security Group; J2 Global (Ziff Davis's former name) acquired it in 2019.

2 separate sources: U.S. Securities and Exchange Commission and TechRadar

Sources and caveats (3)
  1. U.S. Securities and Exchange Commission (EDGAR) · Regulator record · Published February 24, 2026

    The VIPRE Security Group offers its services under the following brands. IPVanish offers one of the leading virtual private network services in the industry.

    Counts toward the two-source rule

  2. TechRadar · Press report · Published May 7, 2019

    The note states that IPVanish and StrongVPN are owned by J2 Global

    Counts toward the two-source rule

  3. PCMag · Analysis · Published August 16, 2023

    (Editors' Note: StrongVPN and IPVanish are owned by Ziff Davis, PCMag's parent company.)

    Listed for context, adds no independence

    Conflict of interest: PCMag is owned by Ziff Davis, which also owns IPVanish (the review carries an editors note saying so); affiliate links on review pages were not checked. The review is dated August 2023, before the August 2026 privacy policy that names IPVanish.

Researcher notes

Relevant only if IPVanish is in fact operating Bitdefender's service (T3-01). PCMag's editors note is a conflict disclosure (Ziff Davis owns PCMag) and is not counted. IPVanish's own record (2016 summons, 2022 and 2025 audits) is in providers/ipvanish.json.

Incidents and vulnerabilities

Breaches and published software flaws, and how they came to light.

Sources agree

CVE-2021-4198 (March 2022, CVSS 6.1): a NULL pointer dereference in messaging_ipc.dll let a local attacker crash product processes, affecting Bitdefender VPN Standalone before 25.5.0.48 as well as Total Security, Internet Security, Antivirus Plus and Endpoint Security Tools; Bitdefender says an automatic update fixed it.

3 separate sources: NIST National Vulnerability Database, Bitdefender, and Zero Day Initiative

Sources and caveats (3)
  1. NIST National Vulnerability Database · Legal or government record · Published March 7, 2022

    Bitdefender VPN Standalone versions prior to 25.5.0.48.

    Counts toward the two-source rule

  2. Bitdefender · Provider own statement · Published March 7, 2022

    An automatic update to these new product versions fixes the issue

    Counts toward the two-source rule

    Conflict of interest: Vendor advisory: an admission against interest, not marketing. Also the CVE Numbering Authority text NVD carries.

  3. Zero Day Initiative · Analysis · Published March 9, 2022

    This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Bitdefender Total Security.

    Counts toward the two-source rule

Researcher notes

Counts: NVD record (carries the CNA text), Bitdefender's advisory VA-10016, and Zero Day Initiative's ZDI-22-483, which lists only Total Security as affected product but carries the same CVE. NVD and the advisory share origin; ZDI is the independent reporter. The flaw is local denial of service, not data exposure. It sits in a component shared with the antivirus products, so it is not specific to the VPN service or to the Hotspot Shield/IPVanish backend.

What we cannot yet show

Where the record is thin

A claim stays off this page until two separate sources back it and an editor has cleared its wording. Each dot is one claim we researched. A filled dot is on this page. A hollow dot is not, yet.

  • Logging and no-logs audits0 of 3 shown
  • Security reviews0 of 1 shown
  • Servers and protocols0 of 3 shown
  • Ownership and jurisdiction3 of 4 shown
  • Incidents and vulnerabilities1 of 4 shown
  • Legal actions0 of 1 shown
  • Transparency0 of 2 shown
  • pr_topic_other0 of 1 shown

Not shown means one of two things: fewer than two separate sources, or still waiting for an editor to settle the wording or check a document. It does not mean the claim is false.

How this feeds the Trust Score

The evidence trail behind the number

The Trust Score has a criterion for security track record: audits, breaches and incidents. This page is the written trail for that kind of question, showing what was published, by whom, and how many separate sources agree.

Points are still assigned by the published formula. Read how in the methodology.

How the Trust Score works

See every published research record

How we research

Four rules we hold ourselves to

  1. Two separate sources, minimum

    Two outlets repeating one press release count as one source. Independence is decided by where the information came from, not by how many sites carry it.

  2. Primary documents first

    Auditor reports, court filings and regulator records come before commentary. A provider own page is evidence of what the provider says, never proof that it is true.

  3. Nothing found is a result

    When a search turns up nothing we record what we searched. We never present an empty search as a clean bill of health.

  4. No softening for partners

    A finding that the evidence qualifies is recorded as qualified, whoever the provider is.

VPN.com does not run its own testing lab. Every audit listed here was commissioned and paid for by the provider it examined, and we say so where it applies. We earn commission from some providers; see our disclosures.Read our disclosures