# Are VPNs safe? An honest answer for ordinary users URL: https://webvpn.org/are-vpns-safe/ Updated: 2026-09-11 Are VPNs safe to use? They move your trust from your ISP to one company. Learn the real risks, how to judge a provider, and whether Proton VPN and free VPNs hold up. ## The honest short answer Yes, a VPN from a reputable provider is safe, and it makes public Wi-Fi and untrusted networks safer than using them bare. No, a VPN does not make you anonymous, does not stop malware, and does not protect you from a provider that lies about its logging. The question are VPNs safe really means: is this particular company safe to hand my traffic to. That framing matters because the VPN server sees everything your internet provider used to see. If you would not trust the company with a full copy of your browsing history, do not install its app. The rest of this article shows how to make that judgement with public evidence rather than marketing. ## What a VPN protects you from A VPN opens an encrypted tunnel from your device to a server run by the provider. Everything you send passes through that tunnel before it reaches the open internet. Three benefits follow from that design: - The owner of the local network, whether a cafe, hotel or employer, sees only encrypted traffic to one address and cannot see which sites you visit. - Your internet provider or mobile carrier sees the same encrypted stream and can no longer build a record of your browsing by destination. - Websites see the VPN server's IP address instead of yours, which hides your location and your home connection. A traveller checking email on hotel Wi-Fi gets real protection from the first point alone. Someone whose provider sells browsing data benefits from the second. The hide your IP address guide covers the third in detail. ## What a VPN does not protect you from A VPN changes where your traffic exits. It does not change what you do once it exits. It will not stop you from downloading a malicious file, entering a password on a phishing page, or being tracked by the account you are logged into. Websites recognise you by cookies, logins and browser fingerprints regardless of your address. It also does not hide the fact that you use a VPN. Your provider can see an encrypted connection to a known VPN server, and some services block those servers outright. If your safety depends on nobody knowing you use a privacy tool at all, that is a different threat model and Tor with a bridge is the better fit. ## The real risk: the provider itself Every risk that a VPN removes from your local network reappears at the VPN server. The company can log your connection times, your real address and every destination. It can be compelled by a court to hand that over, it can be hacked, or it can quietly sell what it collects. The industry has documented examples of all three. You reduce that risk in one of two ways. Either the provider keeps no logs, so there is nothing to hand over or steal, or you use Tor, which spreads trust across relays so that no single operator sees both ends. For most people a VPN with a strict no-logs policy that has been audited is the practical middle ground, and the no-logs VPN guide explains how to read those policies. ## How to judge whether a VPN is safe Use this checklist before installing any VPN app. A provider that passes all six is rare, and one that fails two or more should be avoided: - A written no-logs policy that names exactly what is not stored: connection timestamps, source IP addresses, bandwidth per user and DNS queries. - At least one independent audit of that policy or of the server infrastructure, published in full with the auditor named. - Open-source client apps, so that the code that runs on your device can be inspected by people who do not work for the company. - Modern protocols, WireGuard or OpenVPN, with no proprietary protocol as the only option. - A kill switch on every platform you use, so a dropped tunnel does not silently expose your real address. - Clear ownership: a named company, a named country, and no history of undisclosed acquisitions by advertising firms. Two providers that publish this information openly are Proton VPN at protonvpn.com and Mullvad at mullvad.net. Confirm the current details on their sites rather than relying on any third-party review, including this one. ## Is ProtonVPN safe? This is the most searched brand question in this space, so it deserves a direct answer based on the public record. Proton VPN is run by Proton AG, a Swiss company that also operates Proton Mail. Its apps are open source, its no-logs policy has been audited by an external firm more than once, and the company publishes transparency reports describing legal requests it has received. Those facts put it among the more accountable providers. They do not make it magic. Proton's servers still see your traffic destinations while you are connected, and Swiss law can compel the company to comply with valid orders. What the no-logs policy means in practice is that Proton has stated, and auditors have checked, that there is no historical record to hand over. Check the audit dates on Proton's own site before relying on that, because a policy is only as current as its last verification. ## Are free VPNs safe? Servers, bandwidth and developers cost money every month. A free VPN with no paid product has to cover those costs somehow, and the documented ways are logging and selling traffic data, injecting advertising into pages, or bundling other software. Security vendor reports have repeatedly found free VPN apps that did exactly this. There is one safe form of free VPN. Some providers, Proton VPN among them, offer a free tier as a limited version of the paid product, under the same no-logs policy and the same audits. The free tier is the marketing budget rather than the revenue source. If a free VPN cannot show you a paid tier and an audit, assume that you are the product. ## Context from public sources - Court records in several jurisdictions show VPN providers served with orders to produce logs. Providers that genuinely stored nothing produced nothing. For you, this is the clearest proof that a no-logs policy matters, and that an audit is the closest you can get to that proof in advance. - Security vendor incident reports have documented VPN apps, mostly free ones, that leaked user data through misconfigured servers or shipped tracking libraries. It matters because the app store rating tells you nothing about what the app sends home. - Tor Project documentation describes the difference between a VPN, which is a single trusted party, and Tor, which is designed so that no single relay is trusted. It matters because it clarifies when a VPN is the wrong tool. - Browser and operating system vendors document that a VPN does not affect cookies, logins or location permissions. It matters because most tracking happens at those layers, not at the IP address. ## Use the tool for what it is A VPN is a trust transfer, not a shield. On a trusted provider it turns hostile networks into safe ones and hides your address from the sites you visit, and that is worth having. Pick one company you can name and check, turn on the kill switch, and stop expecting it to do the job of a password manager or an antivirus. Your next step is a single check: open the provider's website, find the most recent audit report, and read the first page. If you cannot find one, that is your answer. ## FAQ Q: Are VPNs safe to use on public Wi-Fi? A: Yes, and this is one of their clearest benefits. A VPN encrypts everything between your device and the VPN server, so the owner of a cafe or airport network sees only an encrypted stream. Most sites already use HTTPS, but a VPN also hides which sites you open and protects any app that does not encrypt properly. Q: Is ProtonVPN safe? A: Proton VPN publishes open-source apps, a no-logs policy that has been independently audited more than once, and is operated by a Swiss company that also runs Proton Mail. Based on the public record it is among the more accountable providers. Verify the current audit reports on protonvpn.com, because policies and ownership can change. Q: Are free VPNs safe? A: Most are not. Running servers costs money, and free apps with no paid tier usually pay for it by logging and selling traffic data or injecting advertising. The exception is a free tier offered by a provider whose paid product has an audited no-logs policy, where the same policy covers both. Q: Can a VPN see what I do online? A: The VPN server sees the destinations of your traffic and, for unencrypted connections, the content. This is why the logging policy is the whole question. A provider that keeps no logs cannot later reveal what it saw, and an audit or a documented court case is the only outside evidence of that. Q: Is it safe to use a VPN for banking? A: It is safe in the sense that your bank connection is already encrypted with HTTPS and a VPN adds a second layer. Some banks flag logins from unusual locations, so choose a server in your own country to avoid account lockouts.