How We Rank the Best VPNs: Our Methodology Explained

A transparent, no-nonsense walkthrough of exactly how this site's VPN rankings are put together — and just as importantly, what they are not.

Quick answer

Our VPN ranking methodology evaluates a small, deliberately limited set of providers (NordVPN, Proton VPN, PureVPN, and FastestVPN) across four editorial categories — speed, streaming, security, and price positioning — using publicly known product information, provider documentation, and general industry-standard criteria rather than in-house lab benchmarks we'd present as independently verified. Each category gets a plain-language tier (such as "excellent" or "good"), clearly labeled as our own editorial judgment, never as a measured test result, a star rating, or a review count. We do not publish specific prices or aggregate ratings until we can confirm them directly from a provider's current pricing page, and we disclose upfront that we earn a commission through affiliate links, which is why we limit coverage to a short list rather than implying we've exhaustively tested the entire market.

Why We Publish a Methodology Page at All

Most "best VPN" content on the internet asserts a ranking without ever explaining how it was produced. A list appears, providers are numbered one through five, and readers are left to assume that some rigorous, standardized testing process sits behind it. Often it doesn't — and even when it does, the criteria are rarely disclosed clearly enough for a reader to judge whether that process actually matches what they personally care about.

This page exists to close that gap for our own site. If we're going to tell you that one VPN is positioned ahead of another for a given use case, you should be able to see exactly what that claim is based on, what it isn't based on, and where our financial interest sits in the process. That's the whole purpose of a published vpn ranking methodology: not to convince you our process is more sophisticated than it is, but to be precise about what it actually is, so you can weigh our conclusions accordingly rather than taking them on faith.

What "Best VPN" Means on This Site — and What It Doesn't

It's worth being direct about scope before anything else. This site currently covers four VPN providers: NordVPN, Proton VPN, PureVPN, and FastestVPN. That is not a claim that these are objectively the four best VPNs on the market out of the dozens that exist — it's a disclosure of the complete list of providers we have an affiliate relationship with and have researched in enough depth to write about responsibly. A "best VPN" ranking that only ever considers four providers is, by definition, a ranking within a limited pool, not a survey of the entire industry.

We think that's a more honest starting point than the alternative many sites choose, which is to imply exhaustive market coverage while actually promoting a similarly short list of affiliate partners without saying so. If your research process values seeing every major provider on the market compared side by side, this site alone shouldn't be your only source — it's one input among several you should be consulting, and we say that plainly rather than positioning ourselves as the final word.

Why we don't expand the list casually

Adding a fifth or sixth provider to the site isn't just a matter of writing another review page. It means establishing a real affiliate relationship, researching the provider's actual feature set, protocols, and policies in enough depth to write about them accurately, and maintaining that coverage going forward as the provider's product changes. We'd rather cover four providers with real care than pad the list with names we haven't actually done that work on, just to look more comprehensive.

Our VPN Ranking Methodology, Step by Step

With scope out of the way, here is the actual process, broken into the stages we go through for every provider on the site.

Step 1: Establish what the provider publicly documents

We start with the provider's own published documentation — supported platforms, protocols offered (WireGuard, OpenVPN, IKEv2, and any proprietary variants), server locations and count as the provider states them, stated logging policy, and any published third-party audit results the provider itself points to. This is foundational, not sufficient on its own, but it's the layer that's actually verifiable by anyone: you can go check the same pages we did.

Step 2: Cross-check against general, well-established industry knowledge

Beyond what a provider says about itself, we weigh that against broader, well-known context about the VPN industry: how mature and widely adopted a given protocol is, what a kill switch and split tunneling are generally expected to do, what jurisdiction-related considerations typically matter for a no-logs claim, and so on. This is general technical and industry knowledge, not a proprietary lab result — and we present it that way rather than dressing it up as original research.

Step 3: Assign editorial tiers across four categories

Each provider gets a plain-language tier — typically "excellent," "good," or similar — across four categories: speed, streaming, security, and price positioning. These tiers are explicitly our own editorial judgment about a provider's general positioning in the market, based on the two steps above. They are not the output of an in-house speed-test lab, they are not an aggregate of third-party user reviews, and we do not present them as either of those things.

Step 4: Write around what we can't confirm

Where we don't have confirmed, current information — specific pricing tiers, an aggregate star rating, a review count — we simply don't state a number. We say so directly and point you to the provider's own current pricing or review pages instead of guessing or reusing a stale figure that might already be wrong by the time you read it. This is one of the more consequential parts of the whole vpn ranking methodology: treating "we don't know this precisely right now" as a reason to omit a claim, not a reason to approximate one.

Step 5: Review and update periodically

VPN providers change pricing, features, server networks, and occasionally ownership or jurisdiction. A ranking methodology that's accurate on the day it's published and never revisited quietly becomes inaccurate over time. When we become aware of a material change to a provider's product — a protocol added, a policy changed, a feature deprecated — the relevant page gets updated, and where that's significant enough to affect a tier, the tier changes too.

The Four Categories We Evaluate, in Detail

Speed, streaming, security, and price positioning are broad category names, so here's what actually goes into each one.

Speed

Speed positioning weighs the protocols a provider supports (modern protocols like WireGuard generally deliver a meaningfully better throughput-to-overhead ratio than older ones), the apparent scale and geographic spread of the provider's server network as they document it, and general, widely-reported patterns about how that provider's infrastructure tends to perform. We do not run our own standardized speed-test suite across all four providers and publish raw megabit numbers — if we did, we'd say so explicitly, because presenting a single anecdotal speed test as representative of a provider's performance for every user, on every network, in every region, would be misleading on its own even if the process were disclosed.

Streaming

Streaming positioning looks at a provider's track record and stated capability for reaching commonly geo-restricted streaming platforms, and the general robustness of their approach to the ongoing cat-and-mouse dynamic between VPN providers and streaming services actively trying to detect and block VPN traffic. This category is inherently the least stable of the four, because streaming platforms change their VPN-detection methods regularly and a provider's access to a given service can shift with little warning on either side. We treat streaming tiers as a general positioning signal, not a guarantee that a specific service will work on a specific day — and we say that directly in our provider and comparison content, not just here.

Security

Security positioning is the category with the most concrete, checkable inputs: protocol support, the presence and apparent reliability of a kill switch, whether split tunneling is offered, the stated no-logs policy and whether it has been backed by an independent third-party audit the provider points to, and the jurisdiction the company operates under (which determines what a government could legally compel the provider to disclose, independent of any policy the company states). None of these individually prove a provider is secure in absolute terms — a stated no-logs policy is a claim we cannot independently verify happening inside a private company's own infrastructure, audit or not — but together they're a reasonable, checkable basis for an editorial tier.

Price positioning

This is the category we're most careful to distinguish from an actual price. "Price positioning" describes a provider's general market segment — budget-focused, mid-market, premium — based on their publicly known pricing structure and plan tiers, without us stating a specific current number as fact. Actual prices change frequently, vary by billing term and ongoing promotions, and quoting one here would likely be stale within weeks. Every page on this site that references pricing points you to the provider's own current pricing page rather than a number we've baked into our content.

What We Deliberately Do Not Claim

A methodology is defined as much by its limits as by its process, so here is an explicit list of things this site does not do, on purpose.

We don't publish a specific price as fact

Pricing fields on our provider data are intentionally left unset until we can confirm a current, accurate figure directly from a provider's own pricing page. Anywhere you see pricing discussed on this site, it's framed as "check current pricing" with a link, not a number presented as settled fact.

We don't publish a star rating or review count

We don't display an aggregate rating (like "4.6 out of 5 stars, based on 12,000 reviews") anywhere on this site, because we don't operate a review-collection system that would make such a number genuine, and reusing a number sourced from elsewhere without full context would misrepresent it as our own finding. If a page doesn't show a rating, that's the reason — not an oversight.

We don't claim to have independently tested every provider in a formal lab

Our editorial tiers are informed judgment based on documented, publicly available information, not the output of an in-house testing lab with reproducible, controlled speed and leak tests across multiple regions and networks. Sites that do run that kind of lab should say so and show their raw data; sites that don't — including this one — should say that too, rather than implying a rigor that isn't there.

We don't expand our recommendations beyond providers we actually cover

If a provider isn't one of the four listed on this site, we don't mention it, compare against it by name, or imply an opinion about it. Silence about a competitor is intentional, not a gap in our knowledge — we'd rather say nothing about a provider we haven't researched than guess.

We don't treat affiliate partnership as a reason to inflate a tier

All four providers on this site are affiliate partners, and we're paid a commission if you sign up through our links — see the section below for the full disclosure. That relationship is exactly why we hold the line on the previous four points: the fewer unverifiable claims we make, the less our recommendations can drift toward "whichever provider pays best" instead of an honest editorial read on each one's actual strengths.

How Affiliate Links Affect (and Don't Affect) Our Rankings

Full disclosure up front: this site earns a commission when you sign up for a VPN through the links on our pages, and all four providers we cover — NordVPN, Proton VPN, PureVPN, and FastestVPN — are affiliate partners. We think that fact matters enough to state clearly rather than bury in fine print, because it's exactly the kind of incentive that could, in principle, distort a ranking if left unchecked.

What the incentive structurally can't do here

Because none of our published tiers are backed by a hidden numeric score we could quietly adjust, there's no mechanism on this site for "which provider pays the highest commission" to silently move a provider up a rank. Our editorial tiers are qualitative judgments tied to publicly checkable criteria — protocols, documented policies, server networks — and a reader can push back on any specific one by pointing to the underlying fact it's based on. We'd rather be accountable to that kind of scrutiny than protected from it.

Why we don't pretend the incentive doesn't exist

Plenty of affiliate-funded sites either omit the disclosure entirely or bury it in a footer nobody reads. We think that approach undersells how much it matters to a reader deciding how much weight to put on any recommendation site's conclusions, ours included. Knowing we're commercially motivated to get you to click through doesn't mean our specific claims are false — but it's exactly the kind of context that should inform how you read them, and hiding it would be a worse outcome for you than stating it plainly.

How this shapes what we chose to build

The decision to keep the provider list to four, to leave pricing and rating fields unset rather than guess, and to publish this methodology page at all are all downstream of taking that conflict of interest seriously. None of those choices make the conflict disappear — an affiliate site is still an affiliate site — but they're the concrete, checkable ways we've tried to keep our incentives from quietly overriding accuracy.

How We Handle Security Claims Specifically

Security deserves its own deeper explanation, because it's the category where overclaiming does the most real damage — a reader who trusts an inflated security claim may make riskier decisions on the strength of it.

No-logs claims are claims, not verified facts

Every VPN provider we cover states some version of a no-logs policy. We report what each provider states, and where a provider points to an independent third-party audit of that policy, we note that too, because an audited claim is a meaningfully stronger signal than an unaudited one. But we're explicit, including in this article, that no outside party — including us — can directly verify what happens inside a private company's own infrastructure. A no-logs policy is a claim backed by varying degrees of external evidence, not a provable fact, and we don't present it as more certain than that.

Jurisdiction is context, not a verdict

We note which country a provider is legally based in, because that determines what a government could legally compel the company to hand over if pressed, independent of what the company's policy states. This is useful context for a reader forming their own judgment about how much to trust a given no-logs claim — it is not, by itself, a reason to rule a provider in or out, and we present it as one input among several rather than a disqualifying factor.

Protocol and feature checks are the most concrete part of security evaluation

Whether a provider supports WireGuard, whether the app includes a kill switch, whether split tunneling is available — these are checkable, documented facts rather than trust-based claims, and they make up the most objective part of how we assess a provider's security posture. When our security tier differs between two providers, it's most often grounded in a difference at this concrete level, not a vaguer impression.

Why We Don't Publish Star Ratings or Review Counts

It's worth expanding on this specific choice, because it's one of the more visible differences between this site and a lot of comparison content in this space.

A star rating implies a specific, aggregated measurement — some number of reviews collected through some defined process, averaged into a single figure. If we displayed "4.7/5" next to a provider without actually running a review collection system that number came from, we'd be presenting something as data when it's really just our overall impression dressed up to look more precise than it is. That's a common practice across the review-site industry, and we've deliberately chosen not to do it here.

Instead, our provider pages use the plain-language tier system described above — "excellent," "good," and similar labels, clearly attached to a named category (speed, streaming, security, price) and explained in prose rather than compressed into a single misleadingly precise number. It's a less flashy presentation than a five-star widget, but it's a more honest one, because it doesn't imply a measurement process we haven't actually run.

How Rankings Get Updated Over Time

A methodology page describing a one-time evaluation isn't especially useful if the underlying rankings never get revisited as providers change. Here's how that maintenance actually works.

What triggers a review

A provider adding or dropping a protocol, materially changing its logging policy or the jurisdiction it operates under, publishing a new independent audit, or significantly restructuring its plans and pricing are all the kinds of changes that would prompt us to revisit a provider's page and, where relevant, its editorial tiers. Minor cosmetic app updates or routine marketing pushes generally don't.

What updating actually changes

When a page is updated, we adjust the specific claims tied to whatever changed — a protocol added moves the relevant speed or security discussion, a policy change moves the relevant security discussion — rather than issuing a blanket re-ranking disconnected from an actual, identifiable reason. If you compare an older cached version of a page to the current one and see a tier changed, there should be a traceable reason behind it, not an arbitrary reshuffle.

What we don't do

We don't reorder providers based on which one is running a bigger promotion that week, and we don't treat a temporary marketing push as a reason to move a provider up in positioning. Tiers track the underlying product and policy facts, not short-term promotional noise.

Common Ranking-Site Practices We Deliberately Avoid

Some of what shapes our vpn ranking methodology is best explained by naming the practices we've seen elsewhere in this category and deciding, on purpose, not to use them. None of this is about calling out a specific competitor — it's about being explicit with you about the shortcuts a review site can take, so you can recognize them elsewhere even when they're not disclosed.

Fake urgency and countdown timers

"Offer expires in 04:59" widgets that reset every time you reload the page are a common pattern in this space, designed to rush a purchase decision rather than inform one. We don't use synthetic countdowns or invented scarcity ("only 3 spots left") anywhere on this site. If a provider is genuinely running a time-limited promotion, that information lives on their own pricing page, not manufactured on ours.

Vague "independently tested" badges with no methodology behind them

A badge or seal claiming a provider was "independently verified" or "lab tested" means very little without a linked methodology, a date, and ideally raw data behind it. We don't display badges like that unless we can point to the actual underlying source, and since we don't run our own testing lab, we don't manufacture the appearance of one with unlabeled seals.

Reordering rankings based on which affiliate program pays more

It's straightforward, mechanically, for a comparison site to quietly bump whichever provider currently offers the best commission terms to the top of a list, dressed up as an editorial update. Because our tiers are tied to disclosed, checkable criteria rather than a hidden internal score, doing that here would require us to falsify the stated reasoning behind a tier, not just reorder a list — a meaningfully higher bar that we don't cross.

Superlatives without a stated basis

Phrases like "the undisputed best VPN of the year" or "the only VPN you'll ever need" sound authoritative but rarely point to what they're actually measured against. Where we describe a provider as strong in a given category, we tie that description to the specific criteria behind it (protocol support, documented policy, server network) rather than a bare superlative floating free of any stated reasoning.

Reviews written without ever using the product

We rely primarily on each provider's own documentation, published policies, and general industry-standard technical context rather than claiming hands-on lab testing we haven't performed. Where our content describes what an app does, that's based on the provider's own current documentation and support materials — and we'd rather be clear about that boundary than imply a first-hand testing process that isn't happening.

What Independent Verification Actually Looks Like

Because we're upfront that we don't run our own testing lab, it's worth explaining what genuine independent verification of a VPN provider's claims looks like, so you know what to look for beyond this site.

Third-party security audits

A meaningful audit is conducted by a named, reputable security firm, covers a defined scope (the VPN apps, the server infrastructure, or specifically the no-logs claim), and results in a public report or at minimum a public summary you can read yourself. The strongest version of this is a repeated, recurring audit rather than a single one-time engagement from years ago — infrastructure and policies can change, and an audit is a snapshot of a specific point in time, not a permanent certification.

Court cases and real-world log requests

One of the more persuasive pieces of evidence for a no-logs claim, when it exists, is a documented instance where a government or law enforcement agency legally compelled a provider to produce user logs, and the provider was unable to comply because the data simply didn't exist. This kind of real-world test carries more weight than a policy statement alone, precisely because it wasn't something the provider controlled or could stage. Not every provider has a public instance like this, and its absence doesn't prove anything either way — it's a positive signal when present, not a requirement we hold every provider to.

Open-source components

Some providers publish parts of their apps or infrastructure tooling as open source, allowing independent security researchers to inspect the actual code rather than relying on the company's own description of what it does. This is a meaningfully stronger transparency signal than a closed-source app with only marketing claims behind it, though most consumer VPN apps remain at least partially closed-source, which is itself a normal, common state for the industry rather than a specific red flag.

How we treat these signals in our own tiers

Where a provider we cover has a published audit, a documented real-world test of their no-logs claim, or meaningful open-source components, that's a real input into our security tier for that provider, and we try to reference it directly rather than just asserting a conclusion. Where a provider doesn't have one of these stronger signals, our security tier reflects the more limited, policy-statement-only basis available, and we don't inflate the tier to imply stronger evidence exists than it does.

How We Decide a Product Change Is Significant Enough to Update

Not every change a provider makes to their product warrants revisiting our coverage, so it helps to walk through a few concrete, realistic scenarios and how each would be handled under this methodology.

Scenario: a provider adds WireGuard support

This is a meaningful, concrete change that affects both the speed and security discussion for that provider, since WireGuard is generally the faster, more modern protocol option. This kind of change would prompt an update to the relevant provider page and could plausibly move a speed tier upward if the provider was previously limited to older protocols only.

Scenario: a provider changes its headquarters jurisdiction

A jurisdiction change affects the legal-compulsion context behind a no-logs claim, which is a real input into our security assessment. This would prompt an update to the security discussion on that provider's page, though it wouldn't automatically move a tier up or down on its own — it depends on the specific jurisdictions involved and what that shift means in practice.

Scenario: a provider redesigns its app interface

A visual redesign, on its own, doesn't change protocol support, logging policy, or the underlying feature set, so it generally wouldn't trigger a tier change, even though it might warrant a small factual update to any screenshots or interface descriptions on the relevant page so they stay current.

Scenario: a provider runs a seasonal discount

A temporary promotional price doesn't affect our price-positioning tier, which reflects the provider's general market segment rather than a specific current number. We don't chase short-term promotions with ranking changes — you'll always find the current, live price by following the link to the provider's own pricing page rather than a number we've tried to keep in sync with a sale calendar.

Scenario: a provider discloses a security incident

A disclosed breach or security incident is exactly the kind of material change that would prompt an immediate review of the relevant provider's security tier and page content, since it directly bears on the trust basis behind our assessment. How it's handled would depend on the specifics — the nature of the incident, what data was affected, and how transparently and quickly the provider disclosed and responded to it.

How to Use Our Rankings — and When to Look Elsewhere Too

Given everything above, here's our honest suggestion for how to actually use this site's rankings as part of your own decision process, rather than as a final answer.

Use it for

A clear, disclosed explanation of what each of the four providers we cover generally does well, framed around concrete, checkable factors like protocols, server networks, streaming track record, and security features — without inflated numeric ratings or invented pricing standing in the way of your own comparison.

Don't rely on it alone for

An exhaustive market survey (we only cover four providers), a precise current price (always check the provider's own page), an aggregate customer-satisfaction figure (we don't publish one), or an independently audited performance benchmark (we don't run one). For any of those, cross-reference against the provider's own site, a genuinely independent audit report if one exists, and — for pricing specifically — the actual current checkout page, since promotional pricing shifts often enough that even a well-intentioned comparison site can go stale between updates.

The simplest practical test

If a specific claim on this site matters to your decision — a protocol, a policy, a feature — you should be able to verify it directly on the provider's own site in a couple of minutes. That's by design: a vpn ranking methodology that only holds up if you don't check it isn't one you should trust, ours included, and we'd rather you verify the parts that matter to you than take any of it purely on faith.

The Bottom Line

Our approach to ranking VPNs comes down to a short list of commitments: cover a small, honestly disclosed set of providers rather than implying exhaustive market coverage; base editorial tiers on checkable, documented facts rather than an in-house lab we don't operate; leave pricing and ratings unstated rather than guess or reuse stale figures; and disclose the affiliate relationship that funds the site plainly, rather than treating it as fine print. None of that makes our rankings infallible or a substitute for your own research — it makes them a starting point you can actually audit, which is the most useful thing a methodology page can honestly promise. If you want to see how that plays out for a specific provider, NordVPN, Proton VPN, PureVPN, and FastestVPN each have their own current pricing and plan pages linked directly, exactly as this methodology says they should be — checked at the source, not taken from us.

What is your VPN ranking methodology based on?

It's based on publicly documented information from each provider — supported protocols, server networks, kill switch and split tunneling availability, stated logging policies, and any independent audits the provider points to — combined with general, well-established industry context. We assign a plain-language editorial tier across four categories (speed, streaming, security, price positioning) rather than a single numeric score, and we're explicit that these tiers are our own judgment, not the output of an in-house testing lab.

Why does this site only cover four VPN providers?

Because those are the only four providers we have an affiliate relationship with and have researched in enough depth to write about responsibly: NordVPN, Proton VPN, PureVPN, and FastestVPN. We'd rather cover a short list thoroughly and honestly than pad the list with providers we haven't actually done that research on just to appear more comprehensive.

Do you publish star ratings or review counts for each VPN?

No. We don't operate a review-collection system that would make an aggregate star rating genuine, so displaying one would misrepresent an editorial impression as measured data. Instead, we use plain-language tiers ("excellent," "good," and similar) tied to named categories and explained in prose.

Do affiliate commissions influence your VPN rankings?

All four providers we cover are affiliate partners, and we disclose that directly rather than hiding it. Our tiers are tied to checkable, documented facts about each provider rather than a hidden numeric score, which limits how much a commission difference could quietly move a ranking — but we think the honest answer is to state the incentive clearly and let you weigh our conclusions with that in mind, not to claim the incentive has zero effect.

Why don't you list specific prices for each VPN?

VPN pricing changes frequently with billing terms and ongoing promotions, and a specific number stated here would likely be stale within weeks. Rather than publish a figure we can't keep current, we describe each provider's general price positioning and link directly to their current pricing page so you're always checking the actual, live number at the source.

How often do you update your VPN rankings?

We revisit a provider's page and tiers when something material changes — a protocol added or dropped, a logging policy or jurisdiction change, a new independent audit, or a significant pricing restructure. We don't reshuffle rankings based on short-term promotions or marketing pushes; changes are tied to an identifiable underlying reason.

Get Deal — NordVPNGet Deal — Proton VPNGet Deal — PureVPNGet Deal — FastestVPN