Logo: Proton VPN

Proton VPN

Swiss Proton AG VPN with open-source clients, Securitum-audited no-logs infrastructure, Secure Core/Stealth, free unlimited-data tier, and Business SSO/SCIM packaging.

Open source

Proton VPN is the virtual private network from Proton AG, the Swiss company behind Proton Mail. It encrypts device traffic to Proton-operated servers, hides the client IP from destination sites, and applies a vendor-stated strict no-logs policy to VPN session activity. Clients cover Windows, macOS, Linux, Android, iOS, browsers, and several TV platforms.

The product exists as a Swiss-jurisdiction alternative to US and Caribbean consumer VPNs, and as part of the wider Proton account (mail, drive, pass). It spans a free unlimited-data tier, paid consumer plans, family and bundle packaging, and Proton VPN for Business with SSO, SCIM, and dedicated servers or IPs.

The concrete differentiator is Secure Core, plus Stealth routing for hostile networks: traffic can enter via extra-hardened servers in privacy-friendly jurisdictions before exiting elsewhere. Open-source clients sit behind that routing story.

Swiss-operated (Proton AG)Open-source clientsSecuritum no-logs auditsSecure Core double-hopFree unlimited-data tierBusiness SSO / SCIM

Shortlist Proton VPN when you want a Swiss Proton AG VPN with open-source clients, publicly linked Securitum no-logs infrastructure audits, Secure Core/Stealth, a real free tier, and optional Business SSO/SCIM inside the Proton suite. Skip when you need anonymous numbered accounts without email (prefer Mullvad) or first-class remote port forwarding/DDNS (prefer AirVPN).

Key capabilities

Strict no-logs policy for VPN session activity (no traffic content, destination, or session metadata that identifies a user to a server, per published Securitum infrastructure reviews). Account data lives on Proton-controlled servers in Switzerland, Germany, or Norway; Secure Core machines are Proton-owned in CH/IS/SE. Suits privacy officers who need public audit PDFs, not NDA-only claims.

Paid Secure Core routes traffic through hardened Proton-owned entry servers in Switzerland, Iceland, or Sweden before the exit country—extra hop against network-level attacks if an exit were compromised. Adds latency; best for high-threat models, not every streaming session.

Stealth obfuscates the tunnel (TLS-over-TCP style) to reduce DPI/VPN-block detection and is available on Free as well as paid apps. Free plan: one device, unlimited data, no ads, limited country set, kill switch; paid unlocks multi-device, streaming profiles, Secure Core, and full NetShield packaging.

Official apps for Windows, macOS, Linux, Android, iOS, and browser extensions are open source on GitHub (ProtonVPN org) with third-party app security reviews published over time. Server-side VPN stack is not a public full OSS product—inspect clients and audit reports, not the entire backend.

NetShield is Proton's DNS-based blocker for ads, trackers, and malware domains (feature depth varies by plan). Protocols include WireGuard, OpenVPN, IKEv2, and Stealth; kill switch and leak protections are first-class client features for untrusted Wi-Fi.

Proton VPN for Business adds organization admin, private gateways, dedicated servers/IPs, enforced 2FA, SSO, and SCIM provisioning (docs cover Okta/Google examples). Fits SMB remote access and policy control—not a numbered-account anonymity product.

At a glance

HQ / entity
Proton AG, Plan-les-Ouates (Geneva), Switzerland
Governance
Primary shareholder: non-profit Proton Foundation (vendor claim)
Protocols
WireGuard, OpenVPN, IKEv2, Stealth
Network (vendor)
20,000+ servers, 140+ countries (re-check live)
Free tier
1 device, unlimited data, limited countries, no ads
Paid consumer devices
Up to 10 simultaneous (typical Plus packaging)
Open source
Official clients yes; not a self-host server product
Business
SSO, SCIM, dedicated IPs/gateways, DPA published

Best fit when

  • Privacy-conscious individuals who want Swiss jurisdiction, open-source apps, and audited no-logs packaging
  • Users already on Proton Mail/Drive/Pass who want one account for VPN plus suite
  • People under network censorship who need Stealth (including on Free) and Secure Core on paid plans
  • SMBs needing managed VPN with SSO/SCIM, dedicated IPs/gateways, and a published DPA
  • Orgs that require downloadable third-party no-logs infrastructure reports rather than NDA-only claims

Poor fit when

  • Teams that require anonymous numbered accounts with no email (Mullvad-style)
  • Workloads whose primary need is multi-port remote forwarding and Dynamic DNS (AirVPN-style)
  • Policies that forbid any US-group SaaS for billing or support (Zendesk/Stripe/Chargebee/PayPal listed)
  • Buyers who need a fully self-hosted VPN control plane rather than Proton SaaS

Consider instead when

  • When: You need maximum account anonymity (no email identity)

    Consider: Mullvad

    Numbered accounts and cash/crypto-friendly privacy posture; less suite/Business packaging.

  • When: You need remote port forwarding and Dynamic DNS as core features

    Consider: AirVPN

    Technical inbound reachability; different product emphasis than Proton Free/Plus.

  • When: You want a large consumer network with different brand/jurisdiction tradeoffs

    Consider: NordVPN or catalog peers such as CyberGhost

    Re-check ownership, audit publication model, and streaming for your regions.

  • When: You need enterprise zero-trust mesh rather than a privacy VPN

    Consider: Tailscale, NetBird, or self-hosted WireGuard

    Different product class from consumer/privacy VPN.

Jurisdiction & ownership

Legal entity
Proton AG (Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva); EU rep Proton Europe sàrl (Luxembourg)
Governing law
Switzerland (vendor privacy/legal framework)
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
VPN/account infrastructure: Proton-owned/controlled servers; account data stated in CH/DE/NO; Secure Core owned in CH/IS/SE; global VPN exits with full-disk encryption. Support/payments processors include US-group Zendesk, Stripe, Chargebee, PayPal (and HubSpot for sales forms) per privacy policy—not the VPN tunnel path.

No known US corporate parent; Foundation is primary shareholder per Proton. Indicative CLOUD Act exposure is medium because of named US SaaS subprocessors for support/billing, despite Swiss VPN operator and no-logs tunnel design. Not legal advice.

  • Independent no-logs / security auditVerified
  • ISO 27001Vendor claimed
  • SOC 2 / SOC 3Vendor claimed
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumUS SaaS for support and payments

    Privacy policy lists Zendesk, Stripe, Chargebee, PayPal (and HubSpot for sales) as processors. This is not VPN traffic logging, but billing/support identity can leave the Swiss-only path—map to your transfer assessment.

  • MediumGlobal exit nodes outside EU/CH

    Large multi-country network means traffic can exit outside the EU depending on server choice. Strict residency policies need operational controls (allowed countries, Secure Core preferences), not HQ alone.

  • LowFree tier capacity and country limits

    Free is one device and a limited country pool; shared free capacity can mean slower peaks. Not a full substitute for paid multi-device org rollout.

  • LowAccount identity vs numbered anonymity

    Standard Proton account (email or external address options) is not the same threat model as cash/number-only VPN accounts. Cash/Bitcoin payment options exist for paid plans but account recovery fields may still apply.

  • LowISO/SOC scope verification

    ISO 27001 and SOC 2 Type II are vendor-asserted on Trust Center; procurement should confirm certificate/attestation scope covers the VPN services in use.

Open questions for due diligence

  • Which current Securitum no-logs PDF applies to the server regions and features you will enable?
  • For Business, which subprocessors apply to your SKU and will Proton countersign the published DPA without material carve-outs?
  • Can org policy force EU/CH-only or Secure Core-only exits for all managed devices?
  • Do ISO 27001 / SOC 2 Type II reports' scope statements explicitly cover Proton VPN infrastructure used by your tenants?
  • If policy bans US payment processors, which payment methods (e.g. Bitcoin) meet your residual-risk tolerance?

Frequently Asked Questions

Shortlist Proton VPN when Swiss Proton AG entity, open-source clients, publicly linked Securitum no-logs infrastructure audits, a free unlimited-data tier, Secure Core/Stealth packaging, or Proton suite + Business SSO/SCIM matter. Prefer Mullvad for anonymous numbered accounts without email. Prefer AirVPN when remote port forwarding and Dynamic DNS are the primary need. Re-test streaming and latency for your regions on any vendor.

Proton Free VPN offers unlimited data, no ads, kill switch, and Stealth on supported apps, with one simultaneous device and a small set of server countries (vendor materials describe a limited/random country pool—confirm live UI). Paid plans raise concurrent devices (commonly up to 10 on consumer Plus packaging), open more of the global network, and unlock streaming-oriented features, Secure Core, P2P servers, and fuller NetShield. No retail prices here—see protonvpn.com/pricing.

Yes, as a vendor-published diligence package: Proton links multi-year Securitum infrastructure audits that examine server-side logging configuration and conclude no activity/metadata logs of the kinds tested. Client apps are open source with separate security reviews. Legal anecdotes (inability to produce connection logs) appear in Proton transparency materials. Your security team should still download the latest Securitum PDF and map scope to your threat model.

There is no known US corporate parent; the operator is Swiss Proton AG with primary shareholding described as the Swiss Proton Foundation. VPN session content is designed no-logs on Proton-controlled paths. However, account support and payments use US-group processors listed in the privacy policy (e.g. Zendesk, Stripe, Chargebee, PayPal; HubSpot for sales forms). Treat CLOUD Act exposure as indicative medium for billing/support identity data—not as 'zero US touch'—and request current subprocessors/DPA for business deals. Not legal advice.

Business packaging documents SSO, SCIM (including Okta examples), dedicated gateways/servers, and admin controls. Proton publishes a Data Processing Agreement at https://proton.me/legal/dpa and Trust Center materials for ISO 27001 / SOC 2 Type II claims. Confirm plan SKU, subprocessors, and any BAA/HIPAA needs directly with Proton sales for regulated workloads.

Official client apps (desktop, mobile, browser extension) are open source under the ProtonVPN GitHub org and have been third-party reviewed. That does not mean the entire server infrastructure is open-source software you can self-host. Self-host is not the product model; evaluation is SaaS VPN plus inspectable clients and published audits.