AirVPN vs Xeovo

Compare AirVPN and Xeovo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: ExpressVPN, IVPN

Logo: AirVPN

AirVPN

Italy· VPN Services

Needs review

Strong European option when you need remote port forwarding, Dynamic DNS, and open-source clients. Skip for enterprise fleet VPN or ISO/SOC-led vendor risk — consider WireGuard mesh (e.g. Tailscale/NetBird) or audited privacy VPNs such as Mullvad.

EU-operatedOpen-source client (GPLv3)Remote port forwardingWireGuard + OpenVPNPrepaid access
Logo: Xeovo

Xeovo

Finland· VPN Services

Needs review

Shortlist Xeovo when you need a Finnish EU operator with WireGuard/OpenVPN plus a real stealth-proxy toolkit (AmneziaWG, multi-protocol obfuscation, Hysteria 2) and cash/crypto payment options. Skip when you require independent no-logs audits, port forwarding, dedicated IPs, or streaming reliability—prefer Mullvad or Proton VPN instead.

Finnish Xeovo OyWireGuard + OpenVPNStealth proxies + AmneziaWGCash & crypto paymentsAnnual transparency reports
AirVPN vs Xeovo: Snapshot
FeatureLogo: AirVPNAirVPNLogo: XeovoXeovo
Country of originItalyFinland
CategoryVPN ServicesVPN Services
Open sourceYesNo
Self-hostedNoNo
HeadquartersItalyFinland
Legal entityAirVPN di Paolo Brini (also Air di Paolo Brini), PerugiaXeovo Oy (reg. no. 3233901-7), Rautiontie 5G 30, 00640 Helsinki, Finland
Governing lawItalian courts / EU private international law framing (per ToS)Finnish courts for unresolved disputes (terms of service)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyMulti-region servers (EU and outside EU). Confirm exit-node policy if you need EU-only traffic.No public infrastructure/subprocessor register. Privacy policy claims stored personal data is not transferred outside the EEA. VPN and stealth exit nodes on status.xeovo.com include EU/EEA locations plus Australia, Brazil, Canada, Japan, Singapore, South Korea, and multiple US cities. Payment rails include global card networks, PayPal, and crypto; Xeovo states it does not store full card data.
Summary

Italian OpenVPN/WireGuard VPN with remote port forwarding, Dynamic DNS, and open-source Eddie clients—strong for technical privacy use, not enterprise fleet VPN.

Finland-based Xeovo Oy VPN with WireGuard/OpenVPN plus stealth proxies (Shadowsocks, AmneziaWG, VLESS/VMess/Trojan, Hysteria) for censorship resistance, no-logs policy claims, and privacy-friendly payments.

Tags
At a glance: AirVPN vs Xeovo
At a glanceLogo: AirVPNAirVPNLogo: XeovoXeovo
HQ / entityPerugia, Italy — AirVPN di Paolo Brini (sole proprietorship)Not listed
ProtocolsOpenVPN, WireGuard; OpenVPN over SSH/SSL/TorWireGuard, OpenVPN, AmneziaWG, Shadowsocks, VLESS/VMess, Trojan, Hysteria 2
ClientsEddie GPLv3 (desktop + Android); configs without GUINot listed
Inbound portsUp to 5 reserved remote ports + optional *.airdns.org DDNSNot listed
SessionsFive simultaneous connections per accountNot listed
Commercial modelPrepaid access (see vendor site for current plans)Prepaid subscription; 5 devices; 30-day refund (limits apply)
Independent auditNo public no-logs audit foundNot listed
B2B packagingSelf-serve ToS; no productized enterprise pack foundNot listed
HQNot listedHelsinki, Finland (Xeovo Oy)
Legal entityNot listedXeovo Oy, reg. 3233901-7
TimelineNot listedPublic product history from April 2016
NetworkNot listed~27 countries / ~60 servers (vendor); live status map
Open sourceNot listedNo (uses open protocols; service not OSS)
Self-hostNot listedNo (SaaS VPN)
Key capabilities: AirVPN vs Xeovo
Key capabilitiesLogo: AirVPNAirVPNLogo: XeovoXeovo
EU-operatedYesNot listed
Open-source client (GPLv3)YesNot listed
Remote port forwardingYesNot listed
WireGuard + OpenVPNYesNot listed
Prepaid accessYesNot listed
Finnish Xeovo OyNot listedYes
WireGuard + OpenVPNNot listedYes
Stealth proxies + AmneziaWGNot listedYes
Cash & crypto paymentsNot listedYes
Annual transparency reportsNot listedYes

AirVPN

  • Remote port forwarding and airdns.org DDNS

    Reserve up to five inbound remote ports (TCP/UDP) while a plan is active, optionally map to different local ports, and attach optional *.airdns.org names that follow the VPN exit IP—useful for P2P, seedboxes, and self-hosted services.

  • Open-source Eddie client with Network Lock

    Official GPLv3 client for major desktops and Android with firewall-based Network Lock (blocks traffic outside the tunnel), CLI, multi-provider mode, and hostile-network layering (SSH/SSL/Tor with AirVPN).

  • OpenVPN, WireGuard, and layered entry

    Choose WireGuard or OpenVPN; OpenVPN is available on multiple ports and can run over SSH, SSL, or Tor when middleboxes block or throttle plain VPN handshakes. Dual-stack IPv4/IPv6 and internal VPN DNS with optional block lists.

  • Minimal identity requirements

    Signup does not require real identity fields; email is optional for support. Payment processors handle their own data when used.

  • Transparent capacity and multi-session use

    Five simultaneous connections, free server switches, public live server load, and a stated minimum allocated bandwidth per session. Commercial access is prepaid—see the vendor site for current plans.

Xeovo

  • WireGuard and OpenVPN with published crypto details

    Official features page documents WireGuard (ChaCha20/Poly1305, Curve25519; ports 51280/53/80/443, AmneziaWG configs) and OpenVPN (AES-256-GCM, TLS 1.3, TCP 443 and UDP 1196). Suits teams that want modern defaults without proprietary tunnels—still validate leaks on your OS stack.

  • Stealth proxies for DPI and censorship resistance

    Shadowsocks (+ v2ray plugin), VLESS/VMess (WS+TLS), Trojan (TLS/WS+TLS), AmneziaWG, and Hub-announced Hysteria 2.0 for networks that block plain VPN. Subscription generators target tested third-party clients; no SOCKS5. Availability claims for restricted countries are vendor status-matrix based.

  • Config generator, custom DNS, optional ad/tracker block lists

    Built-in generators produce VPN and stealth subscription configs. WireGuard/AmneziaWG/OpenVPN can use custom DNS or Xeovo’s ad/tracker-blocking DNS (lists such as pgl.yoyo.org, AdAway, oisd). Useful for power users; block lists may break some sites.

  • Compact multi-region map with live P2P labels

    Marketing cites ~27 countries / ~60 servers with quality-over-quantity positioning. status.xeovo.com shows per-node health and which VPN/stealth locations allow P2P. Five concurrent devices, unlimited bandwidth marketing, IPv6, WireGuard kill-switch—no port forwarding or dedicated IPs.

  • Privacy-oriented payments and optional email accounts

    Accepts cash, Monero, Bitcoin, and Litecoin alongside cards and PayPal. Registration needs a username/password; email is optional for recovery and billing notices. Prepaid plans with a one-time 30-day money-back window (crypto refunds excluded per terms).

Assurance & compliance: AirVPN vs Xeovo
Assurance & complianceLogo: AirVPNAirVPNLogo: XeovoXeovo
Independent no-logs / security audit
Not found

Privacy notice describes no mass-storage activity/IP logs; architecture claims are first-party only.

Not found

Privacy policy claims detailed no-logs; annual Hub transparency reports are first-party only. No public third-party audit PDF located.

ISO 27001
Not found
Not found
SOC 2 / SOC 3
Not found
Not found
GDPR / EU data protection
Vendor claimed

EU (Italian) operator; privacy notice cites GDPR and related EU directives.

Vendor claimed

Finnish controller Xeovo Oy; privacy policy cites GDPR and Finnish DPA (tietosuoja.fi); claims no transfer of stored personal data outside EEA.

US CLOUD Act exposure (indicative)
Vendor claimed

No known US parent from public research — indicative exposure low vs US-owned brands; multi-region exits still matter.

Partial

EU entity / no known US parent and claimed EEA storage for account data, but no public hosting/subprocessor list and public US exit locations. Residual exposure medium. Not legal advice.

Data processing agreement (B2B)
Not found

No productized enterprise DPA flow found; consumer ToS/privacy notice only.

Not found

No public B2B DPA download or subprocessor schedule found; privacy policy is consumer-oriented.

EU AI Act
Not applicable

VPN connectivity product; not an AI system under typical procurement framing.

Not applicable

Consumer VPN/stealth-proxy service, not an AI system offering under typical AI Act scoping.

Considerations & known limitations: AirVPN vs Xeovo
Considerations & known limitationsLogo: AirVPNAirVPNLogo: XeovoXeovo
Italian resident restriction
High

ToS and footer ban residents of Italy. Orgs with Italian-based staff cannot use AirVPN as a universal approved VPN; exclude that population or choose another vendor.

Not listed
No public independent no-logs audit
Medium

If vendor risk requires ISO/SOC or a no-logs audit letter, treat this as a gap until evidence is obtained offline.

High

High-sensitivity buyers must treat no-logs and transparency reports as first-party claims. Demand external evidence or shortlist an audited peer.

Multi-region exit nodes
Medium

Traffic can exit outside the EU depending on server choice. Strict residency policies need operational controls, not just EU HQ.

Not listed
Small operator / sole proprietorship
Medium

Long-running activist project with a small operating structure; set continuity and support expectations accordingly.

Not listed
US CLOUD Act (indicative)
Low

No known US parent from public research. Not a guarantee against other LE cooperation or non-EU exits.

Not listed
Infrastructure and subprocessors not publishedNot listed
Medium

Without a DC/payment/email/hosting register, residual transfer and CLOUD Act analysis stays incomplete even with Finnish HQ and EEA storage claims for account data.

Optional US and other non-EU exit nodesNot listed
Medium

Status map includes multiple US cities and other non-EU locations. Choose EU exits deliberately when residency of tunnel egress matters.

No port forwarding or dedicated IPs; streaming weakNot listed
Medium

FAQ denies port forwarding and dedicated/residential IPs; major streaming services likely blocked. Hard blockers for some use cases.

Five concurrent devices; personal accountsNot listed
Low

Five simultaneous connections and terms against multi-person account sharing constrain household or team rollouts.

Fit

AirVPN

Best fit when

  • You need remote port forwarding and Dynamic DNS through a European-operated VPN
  • Open-source (GPLv3) clients and inspectable tunnel configs are a hard requirement
  • Users face ISP or state-level OpenVPN blocking and need SSH/SSL/Tor layering
  • Small technical teams or individuals comfortable with prepaid self-serve onboarding

Poor fit when

  • Italian-resident staff or contractors must use the service (contractually prohibited)
  • Security policy requires independent no-logs audit, ISO 27001, or SOC 2 from the VPN vendor
  • You need enterprise fleet controls (SSO/SAML, MDM-managed client, org-wide admin console)
  • Primary goal is streaming polish and maximum server footprint rather than inbound reachability

Consider instead when

  • When: You need enterprise fleet / zero-trust mesh connectivity

    Consider: Tailscale, NetBird, or self-hosted WireGuard

    Different product class: org network access vs consumer privacy VPN with inbound ports.

  • When: You prioritise audited no-logs / accountless anonymity over inbound ports

    Consider: Mullvad

    Mullvad is stronger on the public no-logs narrative; weaker on multi-port forwarding / airdns.org-style DDNS.

  • When: You want a free tier and a broader consumer privacy suite

    Consider: Proton VPN

Xeovo

Best fit when

  • Users under active DPI/censorship who need Shadowsocks, AmneziaWG, VLESS/VMess/Trojan, or Hysteria—not only plain WireGuard
  • Buyers who want a Finnish EU legal entity and GDPR-framed privacy policy with claimed EEA storage for account data
  • Privacy-oriented individuals who value optional email, cash/Monero/BTC/LTC payments, and prepaid subscriptions
  • Power users comfortable with config generators and third-party stealth clients rather than a single mega-app
  • Teams fine with a compact ~27-country map and live status/P2P labels instead of thousands of cities

Poor fit when

  • Procurement that requires independent no-logs audits, ISO 27001/SOC 2 evidence, and a public B2B DPA with subprocessors
  • Users who need port forwarding, dedicated/residential IPs, or reliable access to major streaming catalogues
  • Organisations standardising only on audited multi-hop or RAM-only infrastructure claims Xeovo does not publish
  • Households seeking a free tier or free trial (only prepaid + limited money-back)
  • Anyone who will treat vendor no-logs claims as verified without third-party evidence

Consider instead when

  • When: You need stronger anonymous-account culture and long-standing independent reputation

    Consider: Mullvad

    Better default when stealth protocols are secondary to audited privacy ops

  • When: You want a larger EU brand suite, free tier options, and deeper corporate security programme material

    Consider: Proton VPN

    Prefer for broader product integration and procurement packaging

  • When: You want simple Dutch consumer apps and lifetime packaging more than censorship tooling

    Consider: GOOSE VPN

    Different protocol story; fewer stealth-focused features

Open questions for due diligence

AirVPN

  • Can exit nodes be constrained to EU-only for all org devices, and how is that enforced?
  • Will the operator sign a DPA and provide a subprocessors list for a company account?
  • Is any independent security or no-logs assessment available under NDA?
  • Which payment processors receive identity data, and can crypto-only reduce that footprint for your policy?

Xeovo

  • Will Xeovo publish or provide under NDA a current infrastructure and subprocessor list (DCs, payment processors, email, CDN for stealth)?
  • Is an independent no-logs or application security audit planned or available on request?
  • For B2B: will Xeovo Oy sign a GDPR DPA with a named subprocessor schedule?
  • What exact retention periods apply to payment metadata, tickets, and WireGuard/proxy keys after account deletion?
  • Which official first-party apps (if any) ship kill-switch and DNS controls vs config import only per platform?