Back to the ExpressVPN review

Research record

What the public record says about ExpressVPN privacy and security

We read what auditors, courts, security researchers and the press have published about ExpressVPN, then kept only the claims that two separate sources back. This is a record of what is published, not a lab test.

Claims researched
27
Cleared for this page
8
Separate sources behind them
13
Research completed
October 3, 2026

What the evidence supports

Claims that two or more separate sources back

Each statement below is followed by the sources it rests on. A verdict describes what the sources say. It is not our endorsement.

Logging and no-logs audits

Whether outside firms have checked the no-logs promise, and what they could see.

Sources agree

KPMG LLP (UK) issued an ISAE (UK) 3000 Type I reasonable-assurance report dated 8 May 2025 on ExpressVPN's TrustedServer, as at 28 February 2025, with no exceptions on the control objective covering user-activity logging.

3 separate sources: KPMG LLP, Engadget, and ExpressVPN

Sources and caveats (3)
  1. KPMG LLP (hosted by ExpressVPN) · Audit report · Published May 8, 2025

    Controls provide reasonable assurance that the ExpressVPN TrustedServer does not collect logs of users’ activity, including no logging of browsing history, traffic destination, data content, DNS queries, or specific connection logs.

    Counts toward the two-source rule

    Conflict of interest: Commissioned by the auditee (Express Technologies Limited); addressed to it; KPMG disclaims all duty to readers. Hosted behind a click-through of KPMG's terms (no login).

  2. Engadget · Press report · Published June 26, 2025

    KPMG's assessment was an ISAE 3000 Type I audit. That means it focused on ExpressVPN's control design and implementation at a specific point in time.

    Counts toward the two-source rule

    Conflict of interest: Engadget lists ExpressVPN among its top VPN picks (page says so) and carries VPN affiliate links; treat as corroboration. Engadget quotes the KPMG paper directly, so it read the report.

  3. ExpressVPN (expressvpn.com) · Provider own statement · Published June 25, 2025

    KPMG provided reasonable assurance that our systems functioned as designed, with no identified issues regarding our technical safeguards against activity logging

    Counts toward the two-source rule

Researcher notes

Three groups: the KPMG report itself (read in full), Engadget (read the report, restates its terms), and ExpressVPN's blog. The report is public behind a click-through, unlike NordVPN's Deloitte/PwC reports, which need a Nord account. Limits stated by KPMG and Engadget: Type I, a point in time (28 Feb 2025), design and implementation not sustained operation; scope is the TrustedServer VPN service and the Privacy Policy claims, not the company's apps, billing or website. Report is addressed to Express Technologies Limited and KPMG accepts no duty to any reader. Control objective 1 rows C1.1.1 to C1.2.1 show 'No exceptions'.

Security reviews

Penetration tests and code reviews of the apps and servers.

Sources agree

Two independent firms audited ExpressVPN's Rust rewrite of the Lightway protocol in autumn 2024: Cure53 found one High-severity denial-of-service issue and four lower-rated issues; Praetorian found two Low-risk issues, all fixed on retest.

2 separate sources: Cure53 and Praetorian

Sources and caveats (2)
  1. Cure53 · Audit report · Published December 3, 2024

    Cure53's very limited number of findings, especially with only one exploitable vulnerability, can be interpreted as a positive sign for the security of the ExpressVPN Lightway protocol.

    Counts toward the two-source rule

    Conflict of interest: Requested and paid for by ExpressVPN (report states the audit was requested by ExpressVPN)

  2. Praetorian (hosted by ExpressVPN) · Audit report · Published December 20, 2024

    Praetorian uncovered two (2) low-risk findings related to security configuration and insufficient validation issues

    Counts toward the two-source rule

    Conflict of interest: Engaged and paid for by ExpressVPN; report marked Confidential but published by ExpressVPN

Researcher notes

Two independent auditors, each read in full from the PDF. Cure53: report EXP-16, 3 Dec 2024, five findings (EXP-16-004 High: unauthenticated data fragments facilitate server DoS; four Medium/Low/Info). Praetorian: engagement 16 Sep to 10 Oct 2024, report 20 Dec 2024, retest 16-17 Dec 2024, 2 Low findings both fixed. Both were commissioned and paid by ExpressVPN. Scope is the Lightway protocol code only, not the apps or servers. Cure53 recommends implementing all fixes; the report does not itself state they were fixed (Praetorian's retest does for its two).

Sources agree

Cure53's own website links at least 16 distinct ExpressVPN pentest reports (2018 to 2026) covering apps, extensions, routers, the Lightway protocol, TrustedServer and newer products; ExpressVPN's trust page lists about 30 audit reports in total.

2 separate sources: Cure53 and ExpressVPN

Sources and caveats (2)
  1. Cure53 · Audit report · No publication date stated

    pentest-report_expressvpn-trusted-server.pdf

    Counts toward the two-source rule

    Conflict of interest: Auditor's own site; ExpressVPN is a repeat paying client

  2. ExpressVPN (expressvpn.com) · Provider own statement · No publication date stated

    We’re committed to commissioning in-depth third-party audits of our products with great frequency. Here is a comprehensive list of our external audits, ordered chronologically:

    Counts toward the two-source rule

    Conflict of interest: Provider's own list of audits, transparency numbers and bug bounty

Researcher notes

Two groups: the auditor's index (Cure53) and ExpressVPN. The trust page lists audits by Cure53, KPMG, PwC, Praetorian and F-Secure and one Nettitude verification of the 2024 DNS fix (linked from a blog post; not read here). The Cure53 front page did not link the ExpressKeys (March 2026) report that the trust page lists, so the 16 count is a floor. ExpressVPN's own blog posts in 2025 say '23 third-party audits published'; the later trust page list is longer. Only the reports quoted in T1/T3/T4 claims were read.

Ownership and jurisdiction

Where the company is incorporated, who owns it, and which laws reach it.

Sources agree

In 2023 Kape Technologies was taken private by Unikmind Holdings Limited, a vehicle of Israeli businessman Teddy Sagi who already held about 55% of Kape; the offer closed 19 May 2023 and delisting from AIM was expected 31 May 2023.

3 separate sources: London Stock Exchange RNS, Tech Monitor, and The Register

Sources and caveats (3)
  1. London Stock Exchange RNS (via lse.co.uk) · Regulator record · Published April 27, 2023

    Unikmind has formally requested that Kape seeks cancellation of its admission to trading on AIM.

    Counts toward the two-source rule

    Conflict of interest: Issued by the bidder, Unikmind Holdings Limited; regulatory-news announcement under the UK Takeover Code

  2. Tech Monitor · Press report · Published January 16, 2023

    vendor Kape Technologies is set to be taken over by major shareholder Teddy Sagi’s Unikmind Group, the company revealed today.

    Counts toward the two-source rule

    Conflict of interest: None seen. Date inferred: article says the board accepted the offer 'this morning' and refers to the Friday close; page shows no date

  3. The Register · Press report · Published September 14, 2021

    In 2012, billionaire Teddy Sagi took control of it for $37m.

    Counts toward the two-source rule

    Conflict of interest: None seen; quotes ExpressVPN's blog and its VP Harold Li

Researcher notes

Two groups for the 2023 transaction (the bidder's RNS and Tech Monitor); The Register supports the earlier Sagi connection (he took control of Crossrider in 2012 for $37m). The RNS names the bidder and the timetable; the link between Unikmind and Sagi and the 55% figure come from Tech Monitor. RNS and Tech Monitor note both Kape and Unikmind are organised under Isle of Man law. As of the RNS, Unikmind held or had acceptances for about 75.53% (about 79.69% with commitments). Effect for readers: ExpressVPN's ultimate parent is a privately held group, so there is no public-company disclosure regime for it after May 2023.

Sources agree

In March 2021 Kape bought Webselenese, parent of the VPN review sites vpnMentor and Wizcase (reported price $149.1 million), so reviews on those sites of ExpressVPN, a Kape brand since 2021, are owner-conflicted.

2 separate sources: CyberInsider and Pixel Envy

Sources and caveats (2)
  1. CyberInsider · Analysis · Published May 20, 2021

    In March 2021, news broke that Kape had purchased Webselenese, which is the parent company of vpnMentor and Wizcase.

    Counts toward the two-source rule

    Conflict of interest: CyberInsider is itself a VPN review publisher (affiliate model); page updated 2024-11-18

  2. Pixel Envy · Analysis · No publication date stated

    This year, Kape additionally bought a group of VPN review sites that give top ratings to the VPN services it owns.

    Counts toward the two-source rule

    Conflict of interest: Blog quoting an NYT column; the NYT original was not read (paywalled)

Researcher notes

Two groups: CyberInsider (which carries the $149.1 million figure, read raw) and the New York Times column by Brian X. Chen as quoted by Pixel Envy (NYT original paywalled, not read). Relevance to this ledger: vpnMentor, Wizcase and Safety Detectives are Kape-owned, so any review there of ExpressVPN, CyberGhost or PIA is an owner's own opinion; our affiliate-conflicted list should include them. Search results also name Safety Detectives as a Kape-owned site; not read raw. CyberInsider is itself an affiliate-model review publisher.

Incidents and vulnerabilities

Breaches and published software flaws, and how they came to light.

Sources agree

ExpressVPN's Windows v12 app (12.23.1 to 12.72.0, from May 2022) sent some DNS requests to the user's ISP instead of ExpressVPN when split tunneling was used in one mode; ExpressVPN disabled split tunneling in February 2024 after a CNET writer reported it, and NVD records it as CVE-2024-25728.

2 separate sources: NIST National Vulnerability Database and ExpressVPN

Sources and caveats (3)
  1. NIST National Vulnerability Database · Legal or government record · No publication date stated

    ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers)

    Counts toward the two-source rule

  2. ExpressVPN (expressvpn.com) · Provider own statement · Published February 8, 2024

    the bug allowed some of those requests to go instead to a third-party server, which in most cases would be the user’s internet service provider, or ISP.

    Counts toward the two-source rule

  3. SecurityWeek · Press report · Published February 12, 2024

    The issue, introduced in May 2022 in version 12.23.1 of ExpressVPN, resulted in DNS requests remaining unprotected in certain conditions, the VPN solutions provider announced.

    Listed for context, adds no independence

    Conflict of interest: Restates ExpressVPN's announcement ('the VPN solutions provider announced'); headline wording ('user data exposed') is stronger than the body

Researcher notes

Two groups (NVD record and ExpressVPN's disclosure); the NVD description matches ExpressVPN's. SecurityWeek (12 Feb 2024, read raw) restates ExpressVPN's announcement and is counted as derived, not independent; it gives the affected version range (12.23.1 through 12.72.0) and says 12.73.0 disabled split tunneling. The NVD record cites BleepingComputer's 'bug has been leaking some DNS requests for years' article, not read raw in this pass. ExpressVPN states the issue affected under 1% of users on one platform and only in the 'Only allow selected apps to use the VPN' mode, and that encryption and page contents were unaffected; those figures are ExpressVPN's. ExpressVPN published a Nettitude verification audit of the fix in April 2024 (listed on its trust page; report not read here). CNET is also an affiliate-disclosing outlet.

Sources agree

ExpressVPN's Windows app (versions 12.97 to 12.101.0.2-beta) let traffic on TCP port 3389 (including RDP) bypass the VPN tunnel because debug code reached production; a researcher reported it through the bug bounty on 25 April 2025 and version 12.101.0.45 fixed it.

2 separate sources: ExpressVPN and BleepingComputer

Sources and caveats (2)
  1. ExpressVPN (expressvpn.com) · Provider own statement · Published July 18, 2025

    The problem was traced to a piece of debug code (originally intended for internal testing) that mistakenly made it into production builds (versions 12.97 to 12.101.0.2-beta).

    Counts toward the two-source rule

  2. BleepingComputer · Press report · Published July 21, 2025

    On April 25, 2025, a security researcher known as "Adam-X" reported a vulnerability through ExpressVPN's bug bounty program that exposed RDP and other TCP traffic transmitted over port 3389.

    Counts toward the two-source rule

    Conflict of interest: BleepingComputer has disclosed affiliate relationships with VPN vendors on other pages (NordVPN, in 2019); no ExpressVPN disclosure seen on this page. Quotes ExpressVPN's advisory.

Researcher notes

Two groups: ExpressVPN's advisory (dated 18 July 2025, read raw) and BleepingComputer (21 July 2025, read raw, quotes the advisory so it is not wholly independent of it). DATE DISCREPANCY: ExpressVPN says it 'released a fix five days later' after the 25 April report; BleepingComputer says 12.101.0.45 was 'released on June 18, 2025'. Both agree on the report date and the fixed version. ExpressVPN says encryption was unaffected, exposure was limited to the real IP and the fact of RDP connections, and real-world exploitation was 'extremely low' likelihood; the researcher (a BleepingComputer commenter, unverified) says ExpressVPN rated it critical and paid $2,500. No CVE assigned (none in NVD). ExpressVPN says it is strengthening checks to catch debug code before production.

Transparency

What the provider publishes about requests and bug reports.

Sources agree

ExpressVPN has run a bug bounty since 2016 (internally managed until 2020, then Bugcrowd, now YesWeHack), and a 2025 report to that programme led to the RDP-leak fix.

2 separate sources: ExpressVPN and BleepingComputer

Sources and caveats (3)
  1. ExpressVPN (expressvpn.com) · Provider own statement · Published September 16, 2021

    We have been running a bug bounty program since 2016. That was internally managed until 2020, when we transitioned to using BugCrowd instead.

    Counts toward the two-source rule

    Conflict of interest: Provider's own account of its hiring decision

  2. ExpressVPN (expressvpn.com) · Provider own statement · No publication date stated

    Our bug bounty program is managed by YesWeHack.

    Counts toward the two-source rule

    Conflict of interest: Provider's own list of audits, transparency numbers and bug bounty

  3. BleepingComputer · Press report · Published July 21, 2025

    On April 25, 2025, a security researcher known as "Adam-X" reported a vulnerability through ExpressVPN's bug bounty program that exposed RDP and other TCP traffic transmitted over port 3389.

    Counts toward the two-source rule

    Conflict of interest: BleepingComputer has disclosed affiliate relationships with VPN vendors on other pages (NordVPN, in 2019); no ExpressVPN disclosure seen on this page. Quotes ExpressVPN's advisory.

Researcher notes

Two groups: ExpressVPN's own pages (the 2021 post and the current trust page) and BleepingComputer's independent report of a researcher using the programme. The NVD record for CVE-2020-29238 also links a Bugcrowd disclosure for the router bug (not read). Payout size ($2,500) is a researcher's unverified comment. Programme scope and safe-harbour terms per the trust page; not independently reviewed.

What we cannot yet show

Where the record is thin

A claim stays off this page until two separate sources back it and an editor has cleared its wording. Each dot is one claim we researched. A filled dot is on this page. A hollow dot is not, yet.

  • Logging and no-logs audits1 of 5 shown
  • Security reviews2 of 4 shown
  • Servers and protocols0 of 2 shown
  • Ownership and jurisdiction2 of 5 shown
  • Incidents and vulnerabilities2 of 4 shown
  • Legal actions0 of 4 shown
  • Transparency1 of 3 shown

Not shown means one of two things: fewer than two separate sources, or still waiting for an editor to settle the wording or check a document. It does not mean the claim is false.

How this feeds the Trust Score

The evidence trail behind the number

The Trust Score has a criterion for security track record: audits, breaches and incidents. This page is the written trail for that kind of question, showing what was published, by whom, and how many separate sources agree.

Points are still assigned by the published formula. Read how in the methodology.

How the Trust Score works

See every published research record

How we research

Four rules we hold ourselves to

  1. Two separate sources, minimum

    Two outlets repeating one press release count as one source. Independence is decided by where the information came from, not by how many sites carry it.

  2. Primary documents first

    Auditor reports, court filings and regulator records come before commentary. A provider own page is evidence of what the provider says, never proof that it is true.

  3. Nothing found is a result

    When a search turns up nothing we record what we searched. We never present an empty search as a clean bill of health.

  4. No softening for partners

    A finding that the evidence qualifies is recorded as qualified, whoever the provider is.

VPN.com does not run its own testing lab. Every audit listed here was commissioned and paid for by the provider it examined, and we say so where it applies. We earn commission from some providers; see our disclosures.Read our disclosures