Is ExpressVPN Safe? Security, Privacy & Audit Analysis
Is ExpressVPN safe? Independent audit results, encryption protocols, jurisdiction analysis, kill switch testing, and no-logs policy verification.
86 out of 100, built from two weighted parts
App store ratings, part of the score
4.684.69
Researched Oct 3, 2026Claims checked: 27Separate source groups: 27Scores updated Oct 8, 2026
NordVPN's privacy and security record is strong on process and mixed on proof
93 out of 100, built from two weighted parts
App store ratings, part of the score
4.664.59
Researched Oct 3, 2026Claims checked: 31Separate source groups: 23Scores updated Oct 8, 2026
85 out of 100, built from two weighted parts
App store ratings, part of the score
4.614.70
Researched Oct 3, 2026Claims checked: 23Separate source groups: 19Scores updated Oct 8, 2026
Is ExpressVPN Safe? A Security Deep-Dive
ExpressVPN
Security & privacy
86 out of 100, built from two weighted parts
App store ratings, part of the score
4.684.69
Researched Oct 3, 2026Claims checked: 27Separate source groups: 27Scores updated Oct 8, 2026
ExpressVPN earns an 86/100 trust score based on a published KPMG no-logs assurance report, AES-256 encryption, and RAM-only servers across 113 countries. It operates under British Virgin Islands jurisdiction, outside 14 Eyes surveillance alliances. A KPMG assurance report and repeated Cure53 security audits support its privacy and security claims, within the limits described below.
Jurisdiction: Why the British Virgin Islands Matter
ExpressVPN is incorporated in the British Virgin Islands, a self-governing British Overseas Territory. The BVI has no mandatory data retention laws for VPN providers. This single fact shapes how ExpressVPN responds to government data requests.
The BVI sits outside the 5 Eyes, 9 Eyes, and 14 Eyes intelligence-sharing alliances. Foreign government requests must pass through the BVI High Court before reaching ExpressVPN. The BVI has no legal obligation to honor foreign subpoenas or surveillance orders directly.
This jurisdiction advantage proved real in 2017. Turkish authorities seized an ExpressVPN server during a political investigation. The server contained zero user data, confirming the no-logs policy worked under actual government pressure.
Independent Audit History
ExpressVPN has completed more third-party security audits than most competitors. Each audit examined different aspects of the service’s privacy and security claims.
KPMG No-Logs Assurance Report
KPMG LLP (UK) issued an ISAE (UK) 3000 Type I reasonable-assurance report dated 8 May 2025 on ExpressVPN’s TrustedServer, as at 28 February 2025, with no exceptions on the control objective covering user-activity logging. It is a point-in-time report commissioned by ExpressVPN, not continuous monitoring, and it is readable after accepting KPMG’s terms. ExpressVPN says it has commissioned earlier assurance engagements as well.
Cure53 Security Audits
Cure53, a respected German cybersecurity firm, links at least 16 ExpressVPN pentest reports (2018 to 2026) on its own website, covering apps, extensions, routers, the Lightway protocol and TrustedServer. In autumn 2024, Cure53 and Praetorian both audited ExpressVPN’s Rust rewrite of Lightway. Cure53 found one High-severity denial-of-service issue and four lower-rated issues, and Praetorian found two Low-risk issues, all fixed on retest.
ExpressVPN’s trust page lists about 30 audit reports in total, and Cure53 links its own ExpressVPN reports publicly, which shows above-average transparency for the VPN industry.
Logging Policy: What Gets Stored and What Does Not
ExpressVPN’s privacy policy states clearly what data it collects. Understanding the specifics matters more than marketing claims.
Data ExpressVPN Does NOT Store
ExpressVPN does not log your browsing history, traffic destination, DNS queries, or IP address. It does not record connection timestamps, session duration, or assigned VPN IP addresses. No content of your communications passes through any logging system.
Data ExpressVPN DOES Collect
ExpressVPN collects aggregate connection data: which app version you use, which server location you chose (not specific server), and total bandwidth consumed per day. This data cannot identify individual users or link activity to specific accounts. It uses this information to maintain server capacity across its 3,000+ server network.
Your account email, payment information, and support ticket history are stored for billing purposes. Users who want maximum anonymity can pay with Bitcoin or use a disposable email address.
Encryption Standards and Protocols
ExpressVPN uses AES-256-GCM encryption as its default standard. This is the same encryption level used by the U.S. government for classified information. Breaking AES-256 would require computational power that does not currently exist.
Available Protocols
ExpressVPN offers 4 VPN protocols across its apps. Lightway is its proprietary protocol, built on wolfSSL and using ChaCha20 or AES-256 encryption. OpenVPN runs over both UDP and TCP with AES-256-GCM. IKEv2/IPSec is available on select platforms for fast mobile connections.
Lightway deserves special attention. Its codebase contains roughly 2,000 lines of code, compared to OpenVPN’s 70,000+. Fewer lines mean fewer potential vulnerabilities and faster connection times under 1 second. Cure53 and Praetorian audited the 2024 Rust rewrite of Lightway, and ExpressVPN published the code as open source on GitHub.
Perfect Forward Secrecy
ExpressVPN negotiates a new encryption key for every connection session. If an attacker somehow compromised one session key, past and future sessions remain protected. This feature prevents bulk retroactive decryption of captured traffic.
Kill Switch and DNS Leak Protection
ExpressVPN calls its kill switch “Network Lock.” It activates by default on Windows, Mac, Linux, and routers. Network Lock blocks all internet traffic if the VPN connection drops unexpectedly.
Network Lock works at the firewall level, not the application level. This approach prevents leaks during brief reconnection windows that application-level kill switches often miss. It allows traffic only through the VPN tunnel and to ExpressVPN’s DNS servers.
ExpressVPN runs its own private, encrypted DNS on every server. Your DNS queries never touch third-party DNS providers like Google or Cloudflare. This eliminates DNS leak risk at the infrastructure level rather than relying on software patches.
Independent testing tools consistently show zero DNS leaks, zero WebRTC leaks, and zero IPv6 leaks across ExpressVPN’s major apps. The router firmware extends this protection to every device on your network.
Past Security Incidents
No security product exists without scrutiny. ExpressVPN has faced two notable incidents worth examining.
The Turkey Server Seizure (2017)
Turkish authorities investigated the assassination of Russian Ambassador Andrei Karlov. They seized an ExpressVPN server seeking suspect communications. The server contained zero usable data, validating the no-logs infrastructure under real-world law enforcement pressure.
The Kape Technologies Acquisition (2021)
Kape Technologies acquired ExpressVPN for approximately $936 million in September 2021. Kape previously operated as Crossrider, a company associated with adware distribution before rebranding. This acquisition raised legitimate concerns among privacy advocates.
ExpressVPN responded by maintaining its independent operations and BVI jurisdiction. ExpressVPN has since commissioned further assurance work, including a KPMG report dated May 2025 with no exceptions on user-activity logging, though that is a point-in-time review. The company retained its leadership team and continued publishing audit results transparently. Users should monitor future audits to verify continued independence.
Unique Security Features
ExpressVPN offers several security features that distinguish it from competitors with similar encryption standards.
TrustedServer Technology
Every ExpressVPN server runs entirely on volatile RAM, not hard drives. Servers load a read-only image at every boot. All data is wiped completely with each server reboot. This architecture makes persistent data storage physically impossible on VPN servers.
Threat Manager
Threat Manager blocks apps and websites from communicating with known trackers and malicious servers. It operates at the DNS level across all connected devices. ExpressVPN updates its blocklists regularly based on threat intelligence data.
Express Keys (Password Manager)
ExpressVPN bundles a built-in password manager called Keys with all subscriptions. Keys uses zero-knowledge encryption, meaning ExpressVPN cannot access your stored passwords. This integration adds practical security value beyond the VPN tunnel itself.
Post-Quantum Protection
ExpressVPN implemented post-quantum cryptography support in its Lightway protocol. This feature protects against future quantum computing attacks that could break current encryption standards. Few VPN providers have implemented this protection as of current testing.
Resources for this page
Charts and reference images from our research, free to view and share.
Frequently Asked Questions
Is ExpressVPN safe to use overall?
Yes. ExpressVPN holds an 86/100 trust score, backed by AES-256 encryption, RAM-only TrustedServer infrastructure, and a strict no-logs policy covered by a KPMG Type I assurance report dated May 2025 (no exceptions on user-activity logging). It’s incorporated in the British Virgin Islands, outside 14 Eyes surveillance alliances, and its no-logs claim held up when Turkish authorities seized a server in 2017 and found no user data.
Why does ExpressVPN’s British Virgin Islands jurisdiction matter for user privacy?
The BVI has no mandatory data retention laws and sits outside the 5, 9, and 14 Eyes intelligence alliances, so foreign government requests must clear the BVI High Court before reaching ExpressVPN. That legal insulation was tested directly in 2017, when Turkish authorities seized a server during a political investigation and found zero user data stored.
What have independent audits actually verified about ExpressVPN?
KPMG issued a Type I assurance report dated 8 May 2025 on TrustedServer, as at 28 February 2025, with no exceptions on the control objective covering user-activity logging. It is commissioned by ExpressVPN and point-in-time, not continuous monitoring. Cure53 links at least 16 ExpressVPN pentest reports (2018 to 2026) on its own site, and Cure53 and Praetorian audited the Rust rewrite of Lightway in 2024, with all findings fixed on retest.
What data does ExpressVPN actually collect if it doesn’t log activity?
ExpressVPN does not store browsing history, IP addresses, DNS queries, or connection timestamps. It does collect aggregate data unlinked to individual accounts: app version, general server location chosen, and total daily bandwidth used, purely to manage server capacity. Billing details like your email and payment method are kept separately; Bitcoin or a disposable email limit that footprint further.
How does ExpressVPN’s Lightway protocol compare to OpenVPN for security?
Lightway is ExpressVPN’s proprietary protocol built on wolfSSL, using roughly 2,000 lines of code versus OpenVPN’s 70,000+, meaning fewer potential vulnerabilities and faster connection times under a second. It supports ChaCha20 or AES-256 encryption, uses perfect forward secrecy to rotate keys per session, and Cure53 and Praetorian audited its Rust rewrite in 2024.
Does ExpressVPN’s kill switch actually stop leaks if the connection drops?
Yes. ExpressVPN’s kill switch, called Network Lock, activates by default on Windows, Mac, Linux, and routers, and operates at the firewall level rather than the application level, closing brief reconnection windows that app-level switches often miss. It blocks all traffic except through the VPN tunnel and ExpressVPN’s own private DNS servers, and you can confirm there are no DNS, WebRTC, or IPv6 leaks with a leak test.
Should I be concerned that Kape Technologies owns ExpressVPN?
It’s a legitimate question worth understanding, not a dealbreaker. Kape acquired ExpressVPN for a reported sum in September 2021 and previously operated as Crossrider, a company tied to adware. Since the acquisition, ExpressVPN has retained its leadership team, kept its BVI jurisdiction, and commissioned a KPMG no-logs assurance report in 2025 with no exceptions on user-activity logging, suggesting operational independence held.
What is post-quantum protection and does ExpressVPN actually have it?
Post-quantum cryptography protects encrypted traffic against future quantum computers powerful enough to break current standards like AES-256. ExpressVPN has implemented post-quantum protection support within its Lightway protocol, putting it ahead of most VPN providers that haven’t added this layer yet. It works alongside ExpressVPN’s existing perfect forward secrecy, which rotates encryption keys every session regardless of quantum risk.
What’s ExpressVPN’s refund policy if the security features don’t meet expectations?
ExpressVPN backs every plan with a 30-day money-back guarantee, giving you a full month to test Network Lock, DNS leak protection, and TrustedServer’s RAM-only architecture before committing. This matches the guarantee window offered by NordVPN and ProtonVPN, so testing the no-logs claims yourself carries no financial risk within that period.
How many devices does one ExpressVPN account protect at once?
ExpressVPN covers 10 to 14 simultaneous device connections depending on the plan tier you choose. Every connected device gets the same protections: AES-256 encryption, Network Lock’s firewall-level kill switch, and ExpressVPN’s private DNS servers, so a household running multiple phones, laptops, and a router setup stays covered under one subscription.
How can I confirm ExpressVPN’s DNS leak protection is actually working on my device?
ExpressVPN runs its own private, encrypted DNS on every server, so your queries never route through third-party providers like Google or Cloudflare. Run a leak test through a DNS leak checker while connected and confirm the results show only ExpressVPN’s own DNS servers, not your ISP’s.
What happens to my traffic if ExpressVPN disconnects unexpectedly?
Network Lock, ExpressVPN’s kill switch, blocks all internet traffic the moment the VPN connection drops, since it operates at the firewall level rather than the application level. That closes the brief reconnection windows where app-level kill switches on other services can leak your real IP. It’s enabled by default on Windows, Mac, Linux, and router installations.
Does ExpressVPN’s strong security come at the cost of speed?
Not significantly. ExpressVPN ranks #8 of 22 in our Speed Lab, aggregated from published third-party tests, despite running full AES-256 encryption plus its RAM-only TrustedServer architecture on every connection. Lightway’s lean codebase, roughly 2,000 lines versus OpenVPN’s 70,000+, helps offset the overhead that heavier security features typically add to throughput.
