Back to the CyberGhost review

Research record

What the public record says about CyberGhost privacy and security

We read what auditors, courts, security researchers and the press have published about CyberGhost, then kept only the claims that two separate sources back. This is a record of what is published, not a lab test.

Claims researched
23
Cleared for this page
4
Separate sources behind them
6
Research completed
October 3, 2026

What the evidence supports

Claims that two or more separate sources back

Each statement below is followed by the sources it rests on. A verdict describes what the sources say. It is not our endorsement.

Ownership and jurisdiction

Where the company is incorporated, who owns it, and which laws reach it.

Sources agree

CyberGhost S.R.L. is a Romanian company headquartered in Bucharest and incorporated in 2011, per its auditor's addressee block and its own transparency report.

2 separate sources: Deloitte Audit SRL and CyberGhost

Sources and caveats (3)
  1. Deloitte Audit SRL (hosted by CyberGhost) · Audit report · Published December 19, 2025

    To the Board of Directors of CyberGhost S.R.L. 68-72 Polonă Street, Polonă Business Center, District 1, Bucharest, Romania

    Counts toward the two-source rule

    Conflict of interest: Engaging party (CyberGhost) pays for the engagement and writes the criteria and description the auditor tests against; report is restricted to CyberGhost management.

  2. CyberGhost · Provider own statement · Published January 1, 2024

    Incorporated in 2011, we're in the heart of Bucharest, in privacy-friendly Romania.

    Counts toward the two-source rule

  3. SeeNews · Press report · Published March 14, 2017

    Founded in 2011 in Bucharest, CyberGhost has some 45 employees - a development team in Germany and a team of marketing and IT experts in the company's headquarters in the Romanian capital.

    Listed for context, adds no independence

    Conflict of interest: Relays a Crossrider press release ('Crossrider said in a press release')

Researcher notes

The company registry entry was not read. The transparency report says most development is in Aachen, Germany, support is in Manila and the advertising team is in Tel Aviv; those details are CyberGhost's own and were not independently checked. 'Privacy-friendly' is CyberGhost's phrase, not a finding (see T5-05). The parent, Kape, is UK-headquartered (T5-02).

Sources agree

CyberGhost was acquired by Crossrider in March 2017 for 9.2 million euro; Crossrider was renamed Kape Technologies in 2018, and Kape also owns ExpressVPN, Private Internet Access and ZenMate.

3 separate sources: The Register, SecuritySenses (OpsMatters), republishing a CyberGhost press release, and Wikipedia

Sources and caveats (4)
  1. SeeNews · Press report · Published March 14, 2017

    Crossrider said on Tuesday it has acquired cyber security software-as-a service (SaaS) provider Romanian company CyberGhost for a total of 9.2 million euro

    Listed for context, adds no independence

    Conflict of interest: Relays a Crossrider press release ('Crossrider said in a press release')

  2. The Register · Press report · Published September 14, 2021

    Kape used to be known as Crossrider until it changed its name in 2018 to move away from its advert-slinging past and reinvent itself as a cybersecurity outfit.

    Counts toward the two-source rule

  3. SecuritySenses (OpsMatters), republishing a CyberGhost press release · Provider own statement · Published September 22, 2022

    CyberGhost has been part of Kape Technologies (LSE:KAPE) since 2017.

    Counts toward the two-source rule

    Conflict of interest: Press release issued by CyberGhost; page says 'By CyberGhost'

  4. Wikipedia · Analysis · No publication date stated

    In practical terms, the company stopped its browser SDK business to focus on the VPN sector, purchasing CyberGhost VPN in 2017.

    Counts toward the two-source rule

    Conflict of interest: Tertiary source (cites Reuters, The Register, Globes, RestorePrivacy)

Researcher notes

Three counted groups (The Register, CyberGhost, Wikipedia) plus SeeNews, which relays Crossrider's press release and is not counted. Wikipedia is tertiary. The SeeNews text read here gives the 9.2 million euro total; the cash/shares/earn-out split appeared only in search summaries and is not recorded. Same-owner siblings matter for comparison: ExpressVPN and Private Internet Access share CyberGhost's parent, so any trust claim about 'Kape' applies to three of the best-known VPN brands.

Incidents and vulnerabilities

Breaches and published software flaws, and how they came to light.

Sources agree

For two Windows-client CVEs the researchers report an unproductive first vendor response before a fix: Pen Test Partners (CVE-2023-30237) says disclosure paths all led to Bugcrowd and the fix shipped in 8.3.10.10015 on 24 February 2023; secuvera (CVE-2024-26330) says the vendor first called local-access attackers outside its threat model, then marked the issue resolved on 13 March 2024.

2 separate sources: Pen Test Partners and secuvera GmbH

Sources and caveats (2)
  1. Pen Test Partners · Audit report · Published May 5, 2023

    The latest 8.3.10.10015 version released on the 24 February 2023 fixes this issue.

    Counts toward the two-source rule

    Conflict of interest: Author describes a poor Bugcrowd disclosure experience and says the research was commissioned partly in retaliation for it; sells security consulting

  2. secuvera GmbH · Audit report · Published May 29, 2024

    2024/02/01 vendor responded, stating that attackers with local access are outside of application's threat model

    Counts toward the two-source rule

    Conflict of interest: Sells security consulting

Researcher notes

Both are the researchers' own accounts. Pen Test Partners also says it did not report via Bugcrowd partly in retaliation for how an earlier, separate report was handled; read that as context for tone. Kape's statement in the post thanks the researchers and says Bugcrowd would be followed up with. The vendor fixed both issues; the question these records answer is speed and channel, not whether a fix shipped. Pen Test Partners calls Kape's fix 'swift in comparison with other disclosure experiences'.

Transparency

What the provider publishes about requests and bug reports.

Sources agree

CyberGhost runs a public bug bounty on Bugcrowd (announced 10 November 2022, up to $1,250 per verified bug); for Q4 2025 it reports 19 submissions, 5 unique, 2 valid issues, both resolved.

2 separate sources: SecuritySenses (OpsMatters), republishing a CyberGhost press release and Pen Test Partners

Sources and caveats (3)
  1. SecuritySenses (OpsMatters), republishing a CyberGhost press release · Provider own statement · Published November 10, 2022

    CyberGhost is offering up to $1,250 USD, depending on the severity of the submission.

    Counts toward the two-source rule

    Conflict of interest: Press release issued by CyberGhost

  2. Pen Test Partners · Audit report · Published May 5, 2023

    Online support pointed me toward Bugcrowd or CyberGhosts own disclosure submission page which was also powered by Bugcrowd.

    Counts toward the two-source rule

    Conflict of interest: Author describes a poor Bugcrowd disclosure experience and says the research was commissioned partly in retaliation for it; sells security consulting

  3. CyberGhost (Privacy Hub) · Provider own statement · Published February 24, 2026

    In Q4 2025, we received 19 submissions, five of them unique. Two reports identified valid security issues, both of which were resolved.

    Counts toward the two-source rule

Researcher notes

Discrepancy: the transparency report's timeline lists 'We launched our Bug Bounty Program' under 2023; the press release is dated 10 November 2022 and Pen Test Partners was already using the Bugcrowd channel in January 2023. The Bugcrowd program page itself was not read, so current scope and payout limits are unconfirmed. Pen Test Partners' experience (T2-03) is the independent view of how the channel behaves.

What we cannot yet show

Where the record is thin

A claim stays off this page until two separate sources back it and an editor has cleared its wording. Each dot is one claim we researched. A filled dot is on this page. A hollow dot is not, yet.

  • Logging and no-logs audits0 of 4 shown
  • Security reviews0 of 1 shown
  • Servers and protocols0 of 3 shown
  • Ownership and jurisdiction2 of 5 shown
  • Incidents and vulnerabilities1 of 5 shown
  • Legal actions0 of 2 shown
  • Transparency1 of 3 shown

Not shown means one of two things: fewer than two separate sources, or still waiting for an editor to settle the wording or check a document. It does not mean the claim is false.

How this feeds the Trust Score

The evidence trail behind the number

The Trust Score has a criterion for security track record: audits, breaches and incidents. This page is the written trail for that kind of question, showing what was published, by whom, and how many separate sources agree.

Points are still assigned by the published formula. Read how in the methodology.

How the Trust Score works

See every published research record

How we research

Four rules we hold ourselves to

  1. Two separate sources, minimum

    Two outlets repeating one press release count as one source. Independence is decided by where the information came from, not by how many sites carry it.

  2. Primary documents first

    Auditor reports, court filings and regulator records come before commentary. A provider own page is evidence of what the provider says, never proof that it is true.

  3. Nothing found is a result

    When a search turns up nothing we record what we searched. We never present an empty search as a clean bill of health.

  4. No softening for partners

    A finding that the evidence qualifies is recorded as qualified, whoever the provider is.

VPN.com does not run its own testing lab. Every audit listed here was commissioned and paid for by the provider it examined, and we say so where it applies. We earn commission from some providers; see our disclosures.Read our disclosures