Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Surfshark

VERIFIED
VPN · Netherlands
Founded 2018 · surfshark.com ↗

NL-incorporated VPN (Surfshark B.V., Amsterdam, KvK 81967985) — moved from BVI to NL Oct 2021, merged with Nord Security 2022, RAM-only, Deloitte-audited.

Why this score?

Surfshark is operated by Surfshark B.V. (Kabelweg 57, 1014BA Amsterdam, the Netherlands; KvK 81967985, VAT NL862287339B01) — moved its registration from the British Virgin Islands to the Netherlands on 1 October 2021, which is the structural reason it qualifies as an EU listing — founded 2018 with operations still in Vilnius, Lithuania; in early 2022 it merged with Nord Security under one holding company while keeping independent brands and infrastructure, runs 4500+ RAM-only diskless servers across 100+ countries, and has a Deloitte no-logs audit on record; score held at 3/5 reflecting the Dutch entity (good) plus the same Nord Security holding-level US-VC minority (General Catalyst, 2022 round) and the necessarily global VPN-server fleet (which includes US locations) — better than NordVPN's 2/5 (NL > Panama for an EU buyer) but a notch below pure-EU founder-owned picks like Mullvad.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About Surfshark

Surfshark is operated by Surfshark B.V., a Dutch company at Kabelweg 57, 1014BA Amsterdam (Netherlands chamber of commerce KvK 81967985, VAT NL862287339B01). It was founded in 2018, originally registered in the British Virgin Islands, and **moved its corporate registration to the Netherlands on 1 October 2021** — that move is the structural reason Surfshark qualifies as an EU listing in this directory at all. Day-to-day operations are still in Vilnius, Lithuania. In early 2022 Surfshark and Nord Security announced a merger under a single holding company, but both brands continue to operate independently with separate infrastructure and product roadmaps — Surfshark is a Nord Security sister-brand, not a sub-product. As a product, Surfshark is one of the better-audited consumer VPNs. The server fleet is **4500+ RAM-only diskless servers across 100+ countries**, so configuration is loaded fresh on every boot and nothing persists. **Deloitte performed an independent no-logs audit** confirming the policy. The product offers WireGuard, Nexus mesh routing, Dynamic MultiHop, and an IP Rotator that changes the user's IP every 10 minutes. The marketing site supports 17 languages including all major EU locales. For an EU-sovereignty audit Surfshark is a **mid-tier pick**. It scores notably better than its sister NordVPN (NL incorporation beats Panama for an EU buyer) and better than CyberGhost (clean Dutch B.V. with full KvK transparency, no Kape/Sagi/Crossrider history). It scores below Mullvad (founder-owned Swedish AB, no holding complexity) and below ProtonVPN (Swiss non-profit Foundation). The compliance score of 3/5 reflects three things: the Nord Security holding-level US-VC minority (General Catalyst co-led the 2022 $100M round), the company's pre-2021 BVI history, and the structural reality that any global VPN service operates servers in the United States. The RAM-only architecture genuinely mitigates the data-at-rest exposure those US locations would otherwise create. Pricing is paid-only (no free tier; 30-day money-back): Surfshark Starter from around €2.50-3/month on a 2-year plan; One and One+ tiers add encrypted email/storage/data-removal extras above. Best fit: mainstream privacy-conscious EU buyers who want a multi-device VPN with audited no-logs and a Dutch corporate entity, at the lower end of the price range. Buyers who prioritise sovereignty over price and feature breadth should prefer Mullvad or ProtonVPN.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-15).
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API No
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
from €3/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
  • Terms of Service
    surfshark.com/terms-of-service…
    Open ↗
ALTERNATIVES

Alternatives in this category