Back to the Surfshark review

Research record

What the public record says about Surfshark privacy and security

We read what auditors, courts, security researchers and the press have published about Surfshark, then kept only the claims that two separate sources back. This is a record of what is published, not a lab test.

Claims researched
32
Cleared for this page
5
Separate sources behind them
5
Research completed
October 3, 2026

What the evidence supports

Claims that two or more separate sources back

Each statement below is followed by the sources it rests on. A verdict describes what the sources say. It is not our endorsement.

Security reviews

Penetration tests and code reviews of the apps and servers.

Sources agree

Cure53 reviewed Surfshark's Chrome and Firefox extensions in November 2018 (white-box penetration test and code audit, five days, two testers) and reported two security-relevant findings: one Low-severity issue outside the extensions themselves and one informational weakness.

2 separate sources: Cure53 and Surfshark

Sources and caveats (2)
  1. Cure53 · Audit report · Published November 12, 2018

    Carried out by Cure53 in November 2018, this project yielded only two security-relevant findings with limited severities and impact.

    Counts toward the two-source rule

    Conflict of interest: Commissioned by Surfshark (paid engagement); report hosted by Cure53

  2. Surfshark (surfshark.com) · Provider own statement · No publication date stated

    2018 - audit by Cure53 revealed that our browser extensions stand out for their robust security.

    Counts toward the two-source rule

    Conflict of interest: Surfshark publishing about itself

Researcher notes

Two groups: Cure53's own report (hosted on cure53.de and in Cure53's public GitHub publications list, same origin) and Surfshark's page. The report is a full public document. Findings: SRF-01-002 (Low), the invitation email linked the download page over unencrypted HTTP, which Cure53 says is 'not even related to the browser extension itself'; SRF-01-001 (Info), unused insecure HTTP branch in proxy config, removed. Scope was the browser extensions only, not the VPN apps or servers. Eight years old: it speaks to 2018 code.

Sources agree

SecuRing confirmed in a signed letter dated 9 June 2025 that its penetration test of Surfshark's web, desktop, mobile apps and browser plugins (production, 24 February to 3 April 2025) found no critical vulnerabilities and made a few recommendations.

2 separate sources: SecuRing and Surfshark

Sources and caveats (2)
  1. SecuRing (hosted by Surfshark) · Audit report · Published June 9, 2025

    No critical vulnerabilities were found during the security assessment.

    Counts toward the two-source rule

    Conflict of interest: Commissioned by Surfshark; a signed confirmation letter, not the test report; covers Surfshark, Incogni and Ironwall

  2. Surfshark (surfshark.com) · Provider own statement · No publication date stated

    2025 - SecuRing conducted a security assessment. Our web, desktop, mobile applications, and browser plugins demonstrated strong protection against real-world attack scenarios.

    Counts toward the two-source rule

    Conflict of interest: Surfshark publishing about itself

Researcher notes

Two groups: SecuRing's signed letter and Surfshark's page. It is a confirmation letter, not the test report: the number and severity of non-critical findings are not disclosed ('a few security recommendations'). The same letter covers Surfshark B.V. plus Incogni and Ironwall. Black-box and gray-box, OWASP-based. The trust center's 'strong protection against real-world attack scenarios' is Surfshark's paraphrase; the letter says only that no critical vulnerabilities were found.

Sources agree

SecuRing's network-infrastructure penetration test of Surfshark (1 to 10 December 2025, report dated 12 December 2025) found no critical-risk vulnerabilities, one Medium-risk finding (improper SSL/TLS configuration) and one recommendation; the report is public in a redacted version.

2 separate sources: SecuRing and Surfshark

Sources and caveats (3)
  1. SecuRing (hosted by Surfshark) · Audit report · Published December 12, 2025

    During the penetration testing, no vulnerabilities with critical risk impact were found.

    Counts toward the two-source rule

    Conflict of interest: Commissioned by Surfshark; targets and scope redacted in the public version

  2. Surfshark (surfshark.com blog) · Provider own statement · Published January 23, 2026

    During the assessment, one SSL/TLS-related configuration improvement area was identified and promptly resolved.

    Counts toward the two-source rule

    Conflict of interest: Surfshark publishing about itself

  3. Surfshark (surfshark.com) · Provider own statement · No publication date stated

    2025 - we completed an infrastructure audit by SecuRing.

    Counts toward the two-source rule

    Conflict of interest: Surfshark publishing about itself

Researcher notes

Two groups: SecuRing's report and Surfshark. A real, readable (redacted) report: scope targets are redacted, grey-box, from the perspective of an anonymous and standard VPN user, with internal resources assessed via VPN. Wording difference worth keeping: SecuRing's text for F1 says the weaknesses 'in the presence of favorable conditions can lead to the interception of communication between the client and the server or to performing a Denial of Service attack' and rates it Medium; Surfshark's blog calls it a 'minor finding' that 'would have been difficult to take advantage of'. Whether the finding was fixed rests on Surfshark's statement; the report does not include a re-test. The trust center's FAQ gives December 2025 as the completion date.

Sources agree

Surfshark's Android app passed Google's MASA (OWASP MASVS-based) assessment, with a report dated 22 January 2025 rating every tested category Pass, including data storage and privacy.

2 separate sources: App Defense Alliance / Google LLC and Surfshark

Sources and caveats (2)
  1. App Defense Alliance / Google LLC (per report header) · Audit report · Published January 22, 2025

    No sensitive data storage outside the application container or logs were detected during testing.

    Counts toward the two-source rule

    Conflict of interest: Developer-commissioned lab assessment; Android app only

  2. Surfshark (surfshark.com blog) · Provider own statement · Published December 12, 2023

    Surfshark's Android mobile app passed an independent Mobile App Security Assessment (MASA) security audit!

    Counts toward the two-source rule

    Conflict of interest: Surfshark publishing about itself

Researcher notes

Two groups: the App Defense Alliance report and Surfshark's blog. Android app only (com.surfshark.vpnclient.android 3.11.2); tested on instrumented rooted devices against MASVS 1.4; the report header shows 'Google LLC' and does not name the lab in the text we extracted. The trust center says certificates were awarded in December 2023 and January 2025. A self-commissioned, checklist-style pass; it is not a penetration test of the VPN servers or protocol.

Transparency

What the provider publishes about requests and bug reports.

Sources agree

Surfshark runs a discretionary bug bounty program (surfshark.com/bounty-policy) and lists a security contact in security.txt; Google's MASA review recorded that the developer maintains a vulnerability disclosure program.

2 separate sources: Surfshark and App Defense Alliance / Google LLC

Sources and caveats (3)
  1. Surfshark (surfshark.com) · Provider own statement · No publication date stated

    While this is not a competition, it functions more as an experimental and discretionary rewards program.

    Counts toward the two-source rule

    Conflict of interest: Surfshark publishing about itself

  2. App Defense Alliance / Google LLC (per report header) · Audit report · Published January 22, 2025

    The developer maintains a vulnerability disclosure program which can be found at this link.

    Counts toward the two-source rule

    Conflict of interest: Developer-commissioned lab assessment; Android app only

  3. Surfshark (surfshark.com) · Provider own statement · No publication date stated

    Contact: security@surfshark.com

    Listed for context, adds no independence

    Conflict of interest: Surfshark publishing about itself

Researcher notes

Two groups: Surfshark and the App Defense Alliance report. Qualifiers: Surfshark reserves 'the right to cancel the program at any time' and whether to pay is 'entirely at our discretion'; this is not a platform-run program and no public reward table or disclosure history was found. The security.txt file's own Expires header (15 December 2025) had passed when fetched on 2026-10-03.

What we cannot yet show

Where the record is thin

A claim stays off this page until two separate sources back it and an editor has cleared its wording. Each dot is one claim we researched. A filled dot is on this page. A hollow dot is not, yet.

  • Logging and no-logs audits0 of 5 shown
  • Security reviews4 of 7 shown
  • Servers and protocols0 of 3 shown
  • Ownership and jurisdiction0 of 3 shown
  • Incidents and vulnerabilities0 of 5 shown
  • Legal actions0 of 4 shown
  • Transparency1 of 5 shown

Not shown means one of two things: fewer than two separate sources, or still waiting for an editor to settle the wording or check a document. It does not mean the claim is false.

How this feeds the Trust Score

The evidence trail behind the number

The Trust Score has a criterion for security track record: audits, breaches and incidents. This page is the written trail for that kind of question, showing what was published, by whom, and how many separate sources agree.

Points are still assigned by the published formula. Read how in the methodology.

How the Trust Score works

See every published research record

How we research

Four rules we hold ourselves to

  1. Two separate sources, minimum

    Two outlets repeating one press release count as one source. Independence is decided by where the information came from, not by how many sites carry it.

  2. Primary documents first

    Auditor reports, court filings and regulator records come before commentary. A provider own page is evidence of what the provider says, never proof that it is true.

  3. Nothing found is a result

    When a search turns up nothing we record what we searched. We never present an empty search as a clean bill of health.

  4. No softening for partners

    A finding that the evidence qualifies is recorded as qualified, whoever the provider is.

VPN.com does not run its own testing lab. Every audit listed here was commissioned and paid for by the provider it examined, and we say so where it applies. We earn commission from some providers; see our disclosures.Read our disclosures