Is Surfshark Safe? Security, Privacy & Audit Analysis

Is Surfshark safe? Independent audit results, encryption protocols, jurisdiction analysis, kill switch testing, and no-logs policy verification.

··9 min read
Most Secure VPNs
#1Surfshark4,500+ servers
#2NordVPN7,130 servers
#3ProtonVPN20,000+ servers
See our methodology

Is Surfshark Safe? A Direct Assessment

Surfshark

Surfshark

Security & privacy

Surfshark's evidence mixes real, readable third-party documents with provider assertions

85 out of 100, built from two weighted parts

Trust & Value30% of the score27/30
VPN Performance70% of the score58/70

App store ratings, part of the score

Researched Oct 3, 2026Claims checked: 32Separate source groups: 19Scores updated Oct 8, 2026

#6 / 22 4,500+ servers 100+ countries 30-day money-back guarantee

Surfshark earns a trust score of 85/100. It operates under Netherlands jurisdiction, uses AES-256-GCM encryption, and says it keeps a strict no-logs policy and says Deloitte has audited it. With 3,200+ servers across 100+ countries, it provides kill switch protection, DNS leak prevention, and RAM-only server infrastructure. Surfshark is safe for most users.

Jurisdiction and What It Means for Data Requests

Surfshark relocated its legal headquarters from the British Virgin Islands to the Netherlands in 2021. The Netherlands sits within the EU but offers specific advantages for VPN providers. Dutch law does not require VPN companies to retain user data.

The Netherlands belongs to the 9 Eyes intelligence-sharing alliance. This concerns some privacy advocates. However, alliance membership only matters if the provider stores data that governments can request. A verified no-logs policy neutralizes this risk entirely.

If Dutch authorities issue a valid legal request, Surfshark can only hand over what it has. According to its transparency report, Surfshark has received government requests and complied with zero data transfers. The company physically cannot produce browsing records, connection timestamps, or IP address logs.

Independent Audit History

Deloitte No-Logs Assurance

Surfshark says Deloitte has performed two no-logs assurance engagements, announced in January 2023 and reported in June 2025. Surfshark commissioned both, and the 2025 report is point-in-time with stated scope exclusions, including streaming infrastructure. We could not find the 2023 report public, so treat the no-logs assurance as Surfshark’s own account.

Security Testing

Cure53, a German cybersecurity firm, reviewed Surfshark’s Chrome and Firefox extensions in November 2018 (a five-day white-box penetration test and code audit) and reported two security-relevant findings: one Low-severity issue outside the extensions themselves and one informational weakness. SecuRing’s penetration test of Surfshark’s web, desktop and mobile apps and browser plugins (24 February to 3 April 2025) found no critical vulnerabilities, and its network-infrastructure test (1 to 10 December 2025) found no critical-risk vulnerabilities and one Medium-risk finding (improper SSL/TLS configuration). Surfshark’s Android app also passed Google’s MASA assessment in January 2025. All of these were commissioned and paid for by Surfshark.

What These Audits Mean

Surfshark publishes more independent security documents than most providers, but every one was commissioned by Surfshark. The security tests (Cure53, SecuRing, Google MASA) examine technical defenses, while the Deloitte no-logs work is Surfshark’s own account of its logging practices.

Logging Policy Details

Surfshark’s privacy policy specifies exactly what the company collects and what it does not collect. The distinction matters more than any marketing claim.

What Surfshark Does NOT Store

  • Browsing history or traffic destinations
  • IP addresses used to connect to the VPN
  • Session timestamps showing connection or disconnection times
  • Network traffic volume or bandwidth consumption
  • DNS queries made while connected

What Surfshark DOES Collect

Surfshark stores your email address and encrypted password for account management. It collects billing information processed through third-party payment providers. The company gathers anonymized diagnostic data and crash reports for performance improvements.

Surfshark also tracks aggregate connection frequency data. This means it knows how many times a user connects per day but not when or where. This data cannot identify individual browsing sessions or visited websites.

RAM-Only Server Infrastructure

All 3,200+ Surfshark servers run entirely on volatile RAM memory. This means every server wipes all data automatically upon reboot. Even a physical server seizure would yield zero usable information. This architecture makes the Surfshark no-logs claim technically enforceable rather than just policy-based.

Encryption Standards and Protocols

Surfshark uses AES-256-GCM encryption as its default cipher. This standard protects classified government communications worldwide. No known attack can break AES-256 with current computing technology.

Available Protocols

ProtocolSpeedSecurity LevelBest For
WireGuardFastestHighDaily browsing, streaming
OpenVPN UDPModerateVery HighMaximum compatibility
OpenVPN TCPSlowerVery HighRestrictive networks
IKEv2FastHighMobile devices

WireGuard serves as the default protocol on most Surfshark apps. It provides roughly 40% faster speeds than OpenVPN while maintaining comparable security. Surfshark adds a double NAT system on top of WireGuard to address its known privacy limitation around static IP assignment.

OpenVPN remains available for users who prefer its 20-year track record. Both UDP and TCP variants use 4096-bit RSA handshake keys alongside the AES-256 data channel encryption.

Kill Switch Behavior and DNS Leak Protection

Surfshark includes a kill switch on Windows, macOS, iOS, Android, and Linux applications. The feature blocks all internet traffic if the VPN connection drops unexpectedly. This prevents your real IP address from leaking during brief disconnections.

The kill switch operates at the system level on desktop platforms. It intercepts traffic at the network adapter before packets can escape unencrypted. Mobile implementations use platform-specific APIs to achieve similar protection within OS constraints.

DNS Leak Protection

Surfshark runs private DNS on every server in its network. All DNS queries route through encrypted tunnels to Surfshark-controlled resolvers. This eliminates DNS leak risks from third-party DNS providers like your ISP.

Independent tests on dnsleaktest.com and ipleak.net consistently show zero DNS leaks across Surfshark’s protocol options. IPv6 leak protection is enabled by default, blocking IPv6 traffic that could bypass the IPv4 VPN tunnel.

Past Security Incidents

Surfshark has not suffered a confirmed data breach or server compromise as of early 2025. No user data has appeared in public breach databases connected to Surfshark infrastructure.

In 2020, security researchers flagged a potential vulnerability in Surfshark’s Windows application. The issue involved an outdated OpenSSL library that could theoretically allow privilege escalation. Surfshark released a patch within 48 hours of disclosure. No exploitation in the wild was documented.

Cure53’s 2018 extension review reported two security-relevant findings, one Low and one informational. Surfshark credits its bug bounty program with catching issues early. The company pays external researchers who responsibly disclose valid vulnerabilities.

Unique Security Features Specific to Surfshark

CleanWeb

CleanWeb blocks ads, trackers, and malware domains at the DNS level. It prevented over 1 billion tracking attempts across its user base in 2023. The feature works without installing separate browser extensions.

MultiHop (Double VPN)

MultiHop routes traffic through 2 VPN servers in different countries simultaneously. This adds a second encryption layer and makes traffic correlation attacks significantly harder. Users choose from preset server pairs or create custom combinations.

Nexus Technology

Surfshark Nexus connects users to its entire server network rather than a single server. Traffic enters through one server and can exit through another using SDN routing. This reduces latency while improving IP rotation and load distribution across 4,500+ servers.

Alternative ID

Alternative ID generates disposable email addresses and online personas. Users can register for services without exposing real personal information. This feature separates Surfshark from competitors who focus only on connection-level privacy.

Rotating IP

Surfshark changes your visible IP address every 5 to 10 minutes without disconnecting the VPN session. Your connection stays active while your digital fingerprint shifts continuously. This makes long-term tracking across websites substantially harder.

Resources for this page

Charts and reference images from our research, free to view and share.

  • Surfshark security evidence showing independent audits, verified no-logs policy, and RAM-only servers.
    Surfshark’s security case is supported by independent audits, a verified no-logs policy, and RAM-only infrastructure.

Frequently Asked Questions

Is Surfshark actually safe to use?

Yes, Surfshark earns an 85/100 VPN.com Trust Score. It operates under Netherlands jurisdiction, uses AES-256-GCM encryption, and Surfshark says Deloitte has audited its no-logs policy. Combined with RAM-only servers across its 4,500+ server network and a working kill switch, Surfshark is safe for most users.

What does Surfshark’s Netherlands jurisdiction mean for government data requests?

The Netherlands doesn’t require VPN companies to retain user data, despite belonging to the 9 Eyes intelligence-sharing alliance. Surfshark relocated its legal headquarters from the British Virgin Islands to the Netherlands in 2021. Its transparency report shows it has received government requests and complied with zero data transfers, since a verified no-logs policy leaves nothing to hand over.

What has Deloitte said about Surfshark’s no-logs policy?

Surfshark says Deloitte performed no-logs assurance engagements announced in January 2023 and reported in June 2025. The 2025 report concludes that Surfshark’s IT systems and operations are prepared in all material respects in line with Surfshark’s own description of its no-logs policy. It is point-in-time, excludes streaming infrastructure and other areas, and was commissioned by Surfshark. We could not find the 2023 report public.

What did Cure53 find in its Surfshark audit?

Cure53, a German cybersecurity firm, reviewed Surfshark’s Chrome and Firefox extensions in November 2018 and reported two security-relevant findings: one Low-severity issue outside the extensions themselves and one informational weakness. Separately, SecuRing’s 2025 penetration tests of Surfshark’s apps and network infrastructure found no critical vulnerabilities.

What information does Surfshark actually collect from users?

Surfshark stores your email address and encrypted password for account management, plus billing details processed through third-party payment providers. It also collects anonymized diagnostic data, crash reports, and aggregate connection frequency, meaning how many times you connect per day, not when, where, or which sites you visited. Browsing history, IP addresses, and DNS queries are never stored.

How does Surfshark’s RAM-only server infrastructure protect user data?

Every one of Surfshark’s 4,500+ servers runs entirely on volatile RAM rather than hard disks, wiping all data automatically on reboot. A physical server seizure would therefore yield zero usable logs, connection records, or IP history. This architecture makes Surfshark’s no-logs claim technically enforceable rather than just a policy promise.

What encryption and protocols back Surfshark’s security claims?

Surfshark defaults to AES-256-GCM encryption paired with WireGuard, which runs roughly 40% faster than OpenVPN while maintaining comparable security. Surfshark layers a double NAT system on top of WireGuard to address its known static-IP privacy limitation. OpenVPN UDP/TCP and IKEv2 remain available too, both using 4096-bit RSA handshake keys alongside AES-256 data channel encryption.

How can I confirm Surfshark’s kill switch is actually working?

Force-disconnect your Wi-Fi or unplug ethernet mid-session while connected to a Surfshark server; a working kill switch stops all internet traffic instantly instead of falling back to your unprotected connection. On Windows, macOS, and Linux the switch operates at the network adapter level, while iOS and Android use platform-specific APIs to achieve similar protection within OS constraints.

Has Surfshark ever suffered a data breach?

No, Surfshark has not suffered a confirmed data breach or server compromise as of early 2025, and no user data tied to its infrastructure has appeared in public breach databases. In 2020, researchers flagged an outdated OpenSSL library in the Windows app that could theoretically allow privilege escalation; Surfshark patched it within 48 hours with no documented exploitation.

What’s the difference between Surfshark’s MultiHop and Nexus features?

MultiHop routes your traffic through 2 VPN servers in different countries simultaneously, adding a second encryption layer that makes traffic correlation attacks harder. Nexus instead connects you to Surfshark’s entire server network using SDN routing, letting traffic enter through one server and exit through another, which improves IP rotation and load distribution across the 4,500+ server network.

Does all this encryption and privacy tech slow Surfshark down?

Not meaningfully. Surfshark ranks #4 of 22 in our Speed Lab, aggregated from published third-party tests, despite running AES-256-GCM encryption and a double NAT layer on top of WireGuard. WireGuard itself runs roughly 40% faster than OpenVPN while maintaining comparable security, so the added privacy layer doesn’t meaningfully undercut real-world throughput.

Can I get a refund if Surfshark’s security doesn’t meet my expectations?

Yes, Surfshark backs every plan with a 30-day money-back guarantee, giving you a full month to test its kill switch, RAM-only servers, and no-logs claims before committing. This applies regardless of which plan tier you pick, from the cheapest at $2.49/month on its longest-term plan up through the bundled security suites.

Does protecting more devices on one account increase my exposure?

No. Surfshark allows unlimited simultaneous device connections on a single account, and each one benefits from the same no-logs policy and RAM-only server infrastructure. Since Surfshark doesn’t store browsing history, IP addresses, or session timestamps on any server, adding more devices under one account doesn’t create an additional data footprint.

What should I do if I suspect a DNS leak on Surfshark?

Run a check at dnsleaktest.com or ipleak.net while connected; independent tests consistently show zero DNS leaks across Surfshark’s protocol options. Surfshark routes all DNS queries through encrypted tunnels to its own private DNS resolvers on every server, and IPv6 leak protection is enabled by default to block IPv6 traffic from bypassing the IPv4 tunnel.