Aller au contenu
Vérifié indépendamment · Ré-audit trimestriel
EU VETTED

NordVPN

VéRIFIé
VPN · Lithuania
Founded 2012 · nordvpn.com ↗

Panama-incorporated VPN (NordVPN S.A.) under NL holding Nord Security, LT operations; Deloitte + PwC no-logs audits, RAM-only diskless servers, ISO 27001.

Pourquoi ce score ?

NordVPN's ownership chain is genuinely complex and not EU-owned in the strict sense: the VPN service is operated by NordVPN S.A. (Panama) — historically Tefincom S.A., a Panamanian entity chosen for its no-data-retention jurisdiction — under the Nord Security holding company in Amsterdam, Netherlands, with operations and staff in Vilnius, Lithuania, and the 2022 $100M funding round was co-led by US VC General Catalyst alongside Novator (IS) and Burda (DE); the product itself is one of the most rigorously audited consumer VPNs (Deloitte 2023 + PwC no-logs audits, full transition to colocated diskless RAM-only servers, ISO 27001) — so it is included as a privacy-pick rather than a sovereignty-pick and the score is held at 2/5 reflecting the Panama incorporation, US-VC participation and the structural fact that this is not an EU-owned company.

SCORE
2.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About NordVPN

NordVPN is the flagship product of Nord Security, the Lithuanian cybersecurity group that also operates NordPass, NordLayer, NordLocker, NordStellar and — since the 2022 merger — Surfshark. It is one of the largest consumer VPN services in the world (Nord Security reports more than 20M users across its products with NordVPN accounting for around 15M). It is included in this directory as a **privacy-pick rather than an EU-sovereignty pick** — and the distinction matters, because the ownership chain is unusually layered. The legal entity that operates the VPN service is **NordVPN S.A.**, registered in **Panama** — historically named Tefincom S.A., this entity was deliberately set up in Panama for its absence of mandatory data-retention laws, which is itself a privacy positioning. The group **holding company** is Nord Security in **Amsterdam, Netherlands**. Day-to-day operations and the bulk of the engineering team are in **Vilnius, Lithuania**. And the cap-table includes US venture capital: the 2022 $100M round was co-led by **General Catalyst** (US) alongside Novator (Iceland) and Burda (Germany). None of those layers makes NordVPN US-incorporated — the CLOUD Act does not apply directly to a Panamanian entity — but the company is also clearly not EU-owned in the way Mullvad (founder-owned Swedish AB) or ProtonVPN (Swiss non-profit Foundation) are. Where NordVPN is genuinely strong is product security and audit history. Independent **no-logs audits by Deloitte (December 2023) and PwC** validated the no-retention claim; the entire server fleet has been transitioned to **colocated, diskless RAM-only servers** so configuration is loaded fresh on every boot and nothing persists; Nord Security holds **ISO/IEC 27001**; and the product offers WireGuard (NordLynx), kill-switch, multi-hop, Tor-over-VPN, and threat-protection extras. cloud_act_exposure is set to `minor` rather than `material` to reflect the Panama incorporation + RAM-only architecture (no data-at-rest exposure) — the US-VC stake and likely US payment / CDN sub-processors keep it above `none`. Pricing is paid-only (no free tier; 30-day money-back): Basic from around €3.99/month on a 2-year plan, Plus and Complete tiers above. The affiliate programme is one of the most lucrative in the entire VPN category — see affiliate block. Best fit: mainstream privacy-conscious buyers who want a heavily audited, RAM-only no-logs VPN with broad device coverage and aggressive pricing on long commitments. EU buyers who specifically want sovereignty rather than just privacy should prefer Mullvad (SE), ProtonVPN (CH), IVPN, or AirVPN (IT) — all elsewhere in this directory.
SUB-PROCESSORS

Carte des sous-traitants · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Référentiels & certifications

ISO/IEC 27001
ACTIVE
FEATURES

Matrice de fonctionnalités

INTEGRATION & ACCESS
REST API No
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Tarifs & paliers

PAYANT
à partir de €4/mois
Voir la page tarifs ↗
PUBLIC DOCUMENTS

Documents publics

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    business.nordsec.com/legal…
    Open ↗
  • Sub-processors list
    — missing
    missing
  • Terms of Service
    my.nordaccount.com/legal…
    Open ↗
ALTERNATIVES

Alternatives dans cette catégorie