Surfshark vs Xeovo

Compare Surfshark and Xeovo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: ExpressVPN

Logo: Surfshark

Surfshark

Netherlands· VPN Services

Needs review

Shortlist Surfshark when you need unlimited concurrent devices, a large RAM-only commercial VPN network, and optional Surfshark One suite tools under a Dutch legal entity. Skip when you need ownership diversification away from the Nord Security group, open-source clients, cash-only anonymous accounts, or hard EU-only account processing without US-group SaaS — consider Proton VPN or Mullvad instead.

Unlimited devicesRAM-only serversNL legal entityDeloitte no-logs (claimed)VPN + One suiteClosed source
Logo: Xeovo

Xeovo

Finland· VPN Services

Needs review

Shortlist Xeovo when you need a Finnish EU operator with WireGuard/OpenVPN plus a real stealth-proxy toolkit (AmneziaWG, multi-protocol obfuscation, Hysteria 2) and cash/crypto payment options. Skip when you require independent no-logs audits, port forwarding, dedicated IPs, or streaming reliability—prefer Mullvad or Proton VPN instead.

Finnish Xeovo OyWireGuard + OpenVPNStealth proxies + AmneziaWGCash & crypto paymentsAnnual transparency reports
Surfshark vs Xeovo: Snapshot
FeatureLogo: SurfsharkSurfsharkLogo: XeovoXeovo
Country of originNetherlandsFinland
CategoryVPN ServicesVPN Services
Open sourceNoNo
Self-hostedNoNo
HeadquartersNetherlandsFinland
Legal entitySurfshark B.V. (Kabelweg 57, 1014BA Amsterdam, the Netherlands)Xeovo Oy (reg. no. 3233901-7), Rautiontie 5G 30, 00640 Helsinki, Finland
Governing lawNetherlands / EU GDPR as controller per Privacy PolicyFinnish courts for unresolved disputes (terms of service)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyGlobal RAM-only VPN server network (vendor: 4,500+ servers / 100+ countries). Account/support/analytics/payments subprocessors per Privacy Policy include Google (Firebase Analytics, BigQuery), Cloudflare, Zendesk, Stripe and other PSPs, AppsFlyer, Iterable, Purchasely, Telnyx, plus group companies in EEA, UK, and the United States. Transfers use SCCs or adequacy.No public infrastructure/subprocessor register. Privacy policy claims stored personal data is not transferred outside the EEA. VPN and stealth exit nodes on status.xeovo.com include EU/EEA locations plus Australia, Brazil, Canada, Japan, Singapore, South Korea, and multiple US cities. Payment rails include global card networks, PayPal, and crypto; Xeovo states it does not store full card data.
Summary

Dutch-registered VPN and Surfshark One cybersecurity suite: unlimited devices, RAM-only servers, audited no-logs claims, and optional antivirus, leak alerts, and identity tools.

Finland-based Xeovo Oy VPN with WireGuard/OpenVPN plus stealth proxies (Shadowsocks, AmneziaWG, VLESS/VMess/Trojan, Hysteria) for censorship resistance, no-logs policy claims, and privacy-friendly payments.

Tags
At a glance: Surfshark vs Xeovo
At a glanceLogo: SurfsharkSurfsharkLogo: XeovoXeovo
HQ / legal entitySurfshark B.V., Amsterdam, NetherlandsNot listed
OwnershipMerged holding with Nord Security (2022); brands operate separatelyNot listed
DeploymentCloud VPN / SaaS suite (not self-hosted)Not listed
Open sourceNo (closed-source clients)No (uses open protocols; service not OSS)
Device modelUnlimited simultaneous connections (paid plans)Not listed
VPN network4,500+ RAM-only servers, 100+ countries (vendor-stated)Not listed
Primary auditsDeloitte no-logs 2023/2025; Cure53; SecuRingNot listed
HQNot listedHelsinki, Finland (Xeovo Oy)
Legal entityNot listedXeovo Oy, reg. 3233901-7
TimelineNot listedPublic product history from April 2016
ProtocolsNot listedWireGuard, OpenVPN, AmneziaWG, Shadowsocks, VLESS/VMess, Trojan, Hysteria 2
NetworkNot listed~27 countries / ~60 servers (vendor); live status map
Self-hostNot listedNo (SaaS VPN)
Commercial modelNot listedPrepaid subscription; 5 devices; 30-day refund (limits apply)
Key capabilities: Surfshark vs Xeovo
Key capabilitiesLogo: SurfsharkSurfsharkLogo: XeovoXeovo
Unlimited devicesYesNot listed
RAM-only serversYesNot listed
NL legal entityYesNot listed
Deloitte no-logs (claimed)YesNot listed
VPN + One suiteYesNot listed
Closed sourceYesNot listed
Finnish Xeovo OyNot listedYes
WireGuard + OpenVPNNot listedYes
Stealth proxies + AmneziaWGNot listedYes
Cash & crypto paymentsNot listedYes
Annual transparency reportsNot listedYes

Surfshark

  • Unlimited simultaneous VPN connections

    One subscription covers every concurrent device the account can run — phones, laptops, TVs, routers — without the 5–12 device caps common on rival plans. Best for households and multi-device freelancers; confirm current ToS limits for free trials.

  • RAM-only global VPN network with modern protocols

    Vendor-stated 4,500+ RAM-only servers across 100+ countries; WireGuard, OpenVPN, IKEv2, and in-house Dausos. Nexus features include MultiHop, IP Rotator, Everlink self-healing, and FastTrack routing. Server counts and locations change — verify live map before region-critical use.

  • Surfshark One security suite (beyond the tunnel)

    Optional bundling of antivirus (AV-TEST scored), Alert leak monitoring, Alternative ID (disposable persona/email/number), private Search, and Incogni data-broker removal on higher tiers. Suite tools process extra personal data by design — read the Privacy Policy scopes before enabling them.

  • Nexus MultiHop, IP Rotator, and CleanWeb

    Dynamic MultiHop for entry/exit pairing, periodic IP rotation without full disconnect, CleanWeb ad/tracker blocking, plus kill switch and bypass controls. Useful for privacy-sensitive browsing and shared networks; not a substitute for endpoint hardening on high-risk devices.

  • Audited no-logs posture and public security tests

    Deloitte no-logs assurance reported for 2023 and 2025 (account-gated full reports); public Cure53 and SecuRing assessment PDFs for infrastructure/apps. Treat as strong consumer-grade transparency, not automatic enterprise ISO/SOC coverage.

Xeovo

  • WireGuard and OpenVPN with published crypto details

    Official features page documents WireGuard (ChaCha20/Poly1305, Curve25519; ports 51280/53/80/443, AmneziaWG configs) and OpenVPN (AES-256-GCM, TLS 1.3, TCP 443 and UDP 1196). Suits teams that want modern defaults without proprietary tunnels—still validate leaks on your OS stack.

  • Stealth proxies for DPI and censorship resistance

    Shadowsocks (+ v2ray plugin), VLESS/VMess (WS+TLS), Trojan (TLS/WS+TLS), AmneziaWG, and Hub-announced Hysteria 2.0 for networks that block plain VPN. Subscription generators target tested third-party clients; no SOCKS5. Availability claims for restricted countries are vendor status-matrix based.

  • Config generator, custom DNS, optional ad/tracker block lists

    Built-in generators produce VPN and stealth subscription configs. WireGuard/AmneziaWG/OpenVPN can use custom DNS or Xeovo’s ad/tracker-blocking DNS (lists such as pgl.yoyo.org, AdAway, oisd). Useful for power users; block lists may break some sites.

  • Compact multi-region map with live P2P labels

    Marketing cites ~27 countries / ~60 servers with quality-over-quantity positioning. status.xeovo.com shows per-node health and which VPN/stealth locations allow P2P. Five concurrent devices, unlimited bandwidth marketing, IPv6, WireGuard kill-switch—no port forwarding or dedicated IPs.

  • Privacy-oriented payments and optional email accounts

    Accepts cash, Monero, Bitcoin, and Litecoin alongside cards and PayPal. Registration needs a username/password; email is optional for recovery and billing notices. Prepaid plans with a one-time 30-day money-back window (crypto refunds excluded per terms).

Assurance & compliance: Surfshark vs Xeovo
Assurance & complianceLogo: SurfsharkSurfsharkLogo: XeovoXeovo
Independent security / no-logs audit
Vendor claimed

Deloitte no-logs assurance reports for 2023 and 2025 (ISAE 3000 framing per vendor; full reports account-gated). Public Cure53 and SecuRing security/infrastructure PDFs also published on Trust Center.

Not found

Privacy policy claims detailed no-logs; annual Hub transparency reports are first-party only. No public third-party audit PDF located.

ISO 27001
Not found

Not found as a primary advertised company-wide certification on Trust Center pages reviewed for this draft.

Not found
SOC 2 / SOC 3
Not found

Not found as a primary advertised company-wide certification on Trust Center pages reviewed for this draft.

Not found
GDPR / EU data protection
Vendor claimed

Dutch B.V. controller; Privacy Policy cites GDPR, DSAR rights, SCCs/adequacy for transfers. Not legal advice.

Vendor claimed

Finnish controller Xeovo Oy; privacy policy cites GDPR and Finnish DPA (tietosuoja.fi); claims no transfer of stored personal data outside EEA.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but Privacy Policy lists US-group subprocessors (Google analytics/storage, Cloudflare, Zendesk, Stripe, AppsFlyer, Telnyx, US group companies) for account/support/marketing/payments paths. VPN no-logs claims do not eliminate account-data exposure. Indicative only — not legal advice.

Partial

EU entity / no known US parent and claimed EEA storage for account data, but no public hosting/subprocessor list and public US exit locations. Residual exposure medium. Not legal advice.

Data processing agreement (B2B)
Not found

No clear public self-serve B2B DPA package found on primary pages; Teams is sales/quote-driven. Confirm contract language before enterprise use.

Not found

No public B2B DPA download or subprocessor schedule found; privacy policy is consumer-oriented.

EU AI Act
Not applicable

Consumer VPN/security suite; AI-assisted scam-check features exist but product is not AI-centric as primary category.

Not applicable

Consumer VPN/stealth-proxy service, not an AI system offering under typical AI Act scoping.

VPN Trust Initiative seal
Vendor claimed

Vendor displays VTI certification/seal on About and Trust materials; confirm current listing on vpntrust.net if required.

Not listed
Considerations & known limitations: Surfshark vs Xeovo
Considerations & known limitationsLogo: SurfsharkSurfsharkLogo: XeovoXeovo
Shared holding with Nord Security
Medium

After the 2022 merger, Surfshark and Nord brands sit under one industry group even if infrastructure is separate. Shortlists that need ownership diversification should not treat NordVPN as an independent alternative.

Not listed
US-group SaaS in account data path
Medium

Privacy Policy names Google, Cloudflare, Zendesk, Stripe, AppsFlyer, Telnyx and US group companies among recipients. Practical impact: account, support, billing, and marketing data may be reachable via US legal process even when VPN activity is claimed unlogged.

Not listed
Limited public enterprise certs / DPA
Medium

Strong consumer-facing audit marketing (Deloitte, Cure53, SecuRing) but ISO 27001/SOC 2 and a self-serve DPA were not found on primary pages. Regulated buyers need extra contract and evidence work.

Not listed
Suite features expand personal data processing
Low

Alert, Alternative ID/number, email scam checker, and Incogni process additional identifiers or content by design. Enabling the full One suite widens the privacy surface beyond pure VPN tunneling.

Not listed
Closed-source client applications
Low

Clients are not open source; buyers who require public code review of VPN apps should prefer peers with OSS clients.

Not listed
No public independent no-logs auditNot listed
High

High-sensitivity buyers must treat no-logs and transparency reports as first-party claims. Demand external evidence or shortlist an audited peer.

Infrastructure and subprocessors not publishedNot listed
Medium

Without a DC/payment/email/hosting register, residual transfer and CLOUD Act analysis stays incomplete even with Finnish HQ and EEA storage claims for account data.

Optional US and other non-EU exit nodesNot listed
Medium

Status map includes multiple US cities and other non-EU locations. Choose EU exits deliberately when residency of tunnel egress matters.

No port forwarding or dedicated IPs; streaming weakNot listed
Medium

FAQ denies port forwarding and dedicated/residential IPs; major streaming services likely blocked. Hard blockers for some use cases.

Five concurrent devices; personal accountsNot listed
Low

Five simultaneous connections and terms against multi-person account sharing constrain household or team rollouts.

Fit

Surfshark

Best fit when

  • Households and multi-device users who need one VPN account across many concurrent endpoints
  • Buyers wanting a consumer privacy suite (VPN + antivirus, leak alerts, optional Incogni) rather than tunnel-only software
  • Travelers and remote workers needing a large country list, WireGuard/OpenVPN clients, and kill-switch/CleanWeb controls
  • Small teams evaluating a simple Teams admin panel for seat assignment (not full SASE/ZTNA)
  • EU buyers who accept a Dutch B.V. controller with published no-logs and security assessment materials

Poor fit when

  • Organizations requiring open-source VPN clients or self-hosted control planes
  • Buyers who must diversify away from the Nord Security–Surfshark ownership group (NordVPN is a sibling, not an independent alternative)
  • Procurement needing proven ISO 27001 / SOC 2 company certification or a self-serve public B2B DPA without sales engagement
  • Threat models that forbid US-group subprocessors for account, support, analytics, or payments data
  • Users seeking cash-only / account-number anonymity comparable to Mullvad-style signup

Consider instead when

  • When: You want open-source clients, a free tier option, and a privacy stack outside the Nord/Surfshark group

    Consider: Proton VPN

    Smaller device cap than Surfshark’s unlimited concurrent connections; stronger open-source posture.

  • When: You prioritize account-number privacy, minimal identity linkage, and a tunnel-focused product

    Consider: Mullvad

    Fewer lifestyle suite tools; different commercial and account model.

  • When: You want peer-reviewed AirVPN-style advanced networking features and a non-Nord ownership path

    Consider: AirVPN

    Different audience and ops model; check current catalog status and docs.

  • When: You already standardize on Nord products and only need another brand under the same holding

    Consider: NordVPN

    Sibling brand after 2022 merger — not ownership diversification.

Xeovo

Best fit when

  • Users under active DPI/censorship who need Shadowsocks, AmneziaWG, VLESS/VMess/Trojan, or Hysteria—not only plain WireGuard
  • Buyers who want a Finnish EU legal entity and GDPR-framed privacy policy with claimed EEA storage for account data
  • Privacy-oriented individuals who value optional email, cash/Monero/BTC/LTC payments, and prepaid subscriptions
  • Power users comfortable with config generators and third-party stealth clients rather than a single mega-app
  • Teams fine with a compact ~27-country map and live status/P2P labels instead of thousands of cities

Poor fit when

  • Procurement that requires independent no-logs audits, ISO 27001/SOC 2 evidence, and a public B2B DPA with subprocessors
  • Users who need port forwarding, dedicated/residential IPs, or reliable access to major streaming catalogues
  • Organisations standardising only on audited multi-hop or RAM-only infrastructure claims Xeovo does not publish
  • Households seeking a free tier or free trial (only prepaid + limited money-back)
  • Anyone who will treat vendor no-logs claims as verified without third-party evidence

Consider instead when

  • When: You need stronger anonymous-account culture and long-standing independent reputation

    Consider: Mullvad

    Better default when stealth protocols are secondary to audited privacy ops

  • When: You want a larger EU brand suite, free tier options, and deeper corporate security programme material

    Consider: Proton VPN

    Prefer for broader product integration and procurement packaging

  • When: You want simple Dutch consumer apps and lifetime packaging more than censorship tooling

    Consider: GOOSE VPN

    Different protocol story; fewer stealth-focused features

Open questions for due diligence

Surfshark

  • Will Surfshark sign a B2B DPA that lists subprocessors and clarifies controller vs processor roles for Teams seats?
  • Which regions host account databases and support tooling in practice, beyond the high-level Privacy Policy country list?
  • Can procurement obtain the full Deloitte no-logs package and latest infrastructure reports under NDA without a personal consumer account?
  • What is the current operational separation between Surfshark and Nord Security infrastructure for logging, staff access, and incident response?
  • Are company-wide ISO 27001 or SOC 2 programs in progress or available only under NDA?

Xeovo

  • Will Xeovo publish or provide under NDA a current infrastructure and subprocessor list (DCs, payment processors, email, CDN for stealth)?
  • Is an independent no-logs or application security audit planned or available on request?
  • For B2B: will Xeovo Oy sign a GDPR DPA with a named subprocessor schedule?
  • What exact retention periods apply to payment metadata, tickets, and WireGuard/proxy keys after account deletion?
  • Which official first-party apps (if any) ship kill-switch and DNS controls vs config import only per platform?