Logo: Surfshark

Surfshark

Dutch-registered VPN and Surfshark One cybersecurity suite: unlimited devices, RAM-only servers, audited no-logs claims, and optional antivirus, leak alerts, and identity tools.

Surfshark is a consumer and small-team cybersecurity product from Surfshark B.V. in Amsterdam. Its core offer is a commercial VPN with unlimited simultaneous device connections on one subscription, plus optional Surfshark One extras such as antivirus, leak alerts, and identity helpers.

It exists as a Dutch-registered, large-network alternative to US consumer VPNs for households that want one plan across every device rather than a numbered-account privacy boutique. The fleet is marketed as RAM-only. A published no-logs policy denies activity logging.

The concrete differentiator is that unlimited-device packaging, with Teams admin for small groups. Confirm current plan bundles and refund terms on the official site.

Unlimited devicesRAM-only serversNL legal entityDeloitte no-logs (claimed)VPN + One suiteClosed source

Shortlist Surfshark when you need unlimited concurrent devices, a large RAM-only commercial VPN network, and optional Surfshark One suite tools under a Dutch legal entity. Skip when you need ownership diversification away from the Nord Security group, open-source clients, cash-only anonymous accounts, or hard EU-only account processing without US-group SaaS — consider Proton VPN or Mullvad instead.

Key capabilities

One subscription covers every concurrent device the account can run — phones, laptops, TVs, routers — without the 5–12 device caps common on rival plans. Best for households and multi-device freelancers; confirm current ToS limits for free trials.

Vendor-stated 4,500+ RAM-only servers across 100+ countries; WireGuard, OpenVPN, IKEv2, and in-house Dausos. Nexus features include MultiHop, IP Rotator, Everlink self-healing, and FastTrack routing. Server counts and locations change — verify live map before region-critical use.

Optional bundling of antivirus (AV-TEST scored), Alert leak monitoring, Alternative ID (disposable persona/email/number), private Search, and Incogni data-broker removal on higher tiers. Suite tools process extra personal data by design — read the Privacy Policy scopes before enabling them.

Dynamic MultiHop for entry/exit pairing, periodic IP rotation without full disconnect, CleanWeb ad/tracker blocking, plus kill switch and bypass controls. Useful for privacy-sensitive browsing and shared networks; not a substitute for endpoint hardening on high-risk devices.

Deloitte no-logs assurance reported for 2023 and 2025 (account-gated full reports); public Cure53 and SecuRing assessment PDFs for infrastructure/apps. Treat as strong consumer-grade transparency, not automatic enterprise ISO/SOC coverage.

At a glance

HQ / legal entity
Surfshark B.V., Amsterdam, Netherlands
Ownership
Merged holding with Nord Security (2022); brands operate separately
Deployment
Cloud VPN / SaaS suite (not self-hosted)
Open source
No (closed-source clients)
Device model
Unlimited simultaneous connections (paid plans)
VPN network
4,500+ RAM-only servers, 100+ countries (vendor-stated)
Primary audits
Deloitte no-logs 2023/2025; Cure53; SecuRing

Best fit when

  • Households and multi-device users who need one VPN account across many concurrent endpoints
  • Buyers wanting a consumer privacy suite (VPN + antivirus, leak alerts, optional Incogni) rather than tunnel-only software
  • Travelers and remote workers needing a large country list, WireGuard/OpenVPN clients, and kill-switch/CleanWeb controls
  • Small teams evaluating a simple Teams admin panel for seat assignment (not full SASE/ZTNA)
  • EU buyers who accept a Dutch B.V. controller with published no-logs and security assessment materials

Poor fit when

  • Organizations requiring open-source VPN clients or self-hosted control planes
  • Buyers who must diversify away from the Nord Security–Surfshark ownership group (NordVPN is a sibling, not an independent alternative)
  • Procurement needing proven ISO 27001 / SOC 2 company certification or a self-serve public B2B DPA without sales engagement
  • Threat models that forbid US-group subprocessors for account, support, analytics, or payments data
  • Users seeking cash-only / account-number anonymity comparable to Mullvad-style signup

Consider instead when

  • When: You want open-source clients, a free tier option, and a privacy stack outside the Nord/Surfshark group

    Consider: Proton VPN

    Smaller device cap than Surfshark’s unlimited concurrent connections; stronger open-source posture.

  • When: You prioritize account-number privacy, minimal identity linkage, and a tunnel-focused product

    Consider: Mullvad

    Fewer lifestyle suite tools; different commercial and account model.

  • When: You want peer-reviewed AirVPN-style advanced networking features and a non-Nord ownership path

    Consider: AirVPN

    Different audience and ops model; check current catalog status and docs.

  • When: You already standardize on Nord products and only need another brand under the same holding

    Consider: NordVPN

    Sibling brand after 2022 merger — not ownership diversification.

Jurisdiction & ownership

Legal entity
Surfshark B.V. (Kabelweg 57, 1014BA Amsterdam, the Netherlands)
Governing law
Netherlands / EU GDPR as controller per Privacy Policy
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
Global RAM-only VPN server network (vendor: 4,500+ servers / 100+ countries). Account/support/analytics/payments subprocessors per Privacy Policy include Google (Firebase Analytics, BigQuery), Cloudflare, Zendesk, Stripe and other PSPs, AppsFlyer, Iterable, Purchasely, Telnyx, plus group companies in EEA, UK, and the United States. Transfers use SCCs or adequacy.

No known US corporate parent after public merger with Nord Security (European private group). CLOUD Act judgment is medium because of extensive US-group SaaS subprocessors and US group companies for non-tunnel data — not because of a US HQ. Indicative only; not legal advice.

  • Independent security / no-logs auditVendor claimed
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +4

Considerations & known limitations

  • MediumShared holding with Nord Security

    After the 2022 merger, Surfshark and Nord brands sit under one industry group even if infrastructure is separate. Shortlists that need ownership diversification should not treat NordVPN as an independent alternative.

  • MediumUS-group SaaS in account data path

    Privacy Policy names Google, Cloudflare, Zendesk, Stripe, AppsFlyer, Telnyx and US group companies among recipients. Practical impact: account, support, billing, and marketing data may be reachable via US legal process even when VPN activity is claimed unlogged.

  • MediumLimited public enterprise certs / DPA

    Strong consumer-facing audit marketing (Deloitte, Cure53, SecuRing) but ISO 27001/SOC 2 and a self-serve DPA were not found on primary pages. Regulated buyers need extra contract and evidence work.

  • LowSuite features expand personal data processing

    Alert, Alternative ID/number, email scam checker, and Incogni process additional identifiers or content by design. Enabling the full One suite widens the privacy surface beyond pure VPN tunneling.

  • LowClosed-source client applications

    Clients are not open source; buyers who require public code review of VPN apps should prefer peers with OSS clients.

Open questions for due diligence

  • Will Surfshark sign a B2B DPA that lists subprocessors and clarifies controller vs processor roles for Teams seats?
  • Which regions host account databases and support tooling in practice, beyond the high-level Privacy Policy country list?
  • Can procurement obtain the full Deloitte no-logs package and latest infrastructure reports under NDA without a personal consumer account?
  • What is the current operational separation between Surfshark and Nord Security infrastructure for logging, staff access, and incident response?
  • Are company-wide ISO 27001 or SOC 2 programs in progress or available only under NDA?

Frequently Asked Questions

Surfshark and Nord Security finalized a merger under a shared holding in 2022 while stating they would keep separate infrastructure and product roadmaps. They are not ownership-independent peers. For procurement diversification away from that group, shortlist non-group options such as Proton VPN or Mullvad.

The controller entity on the Privacy Policy is Surfshark B.V. in Amsterdam, Netherlands, with additional offices in Lithuania, Poland, and Germany. EU entity status does not mean all account data stays in the EEA: the Privacy Policy lists US-based processors (e.g. Google analytics/storage tools, Cloudflare, Zendesk, Stripe, AppsFlyer, Telnyx) and group companies including the United States, with SCCs/adequacy for transfers.

Surfshark publishes Deloitte no-logs assurance summaries for 2023 and 2025 (full packages via user account) and public Cure53 / SecuRing security and infrastructure materials. Activity logging is denied for VPN use; temporary connection details are described as short-lived. Full enterprise ISO 27001 / SOC 2 company certifications were not found on primary Trust Center pages reviewed for this entry.

Shortlist Surfshark when unlimited concurrent devices and optional suite tools (AV, Alert, Incogni) matter most. Prefer Proton VPN when open-source clients and Proton’s privacy product stack are the priority. Prefer Mullvad when account-number style privacy and a tunnel-focused product beat lifestyle add-ons. Avoid treating sibling NordVPN as an independent ownership alternative.

There is no full free VPN tier comparable to some rivals; commercial access is subscription-based with a stated money-back trial window on consumer purchases (confirm current terms). Surfshark is not self-hosted — it is a cloud VPN and SaaS suite. Dedicated IP and some identity tools create different privacy trade-offs; review those product pages before enabling.