Logo: Xeovo

Xeovo

Finland-based Xeovo Oy VPN with WireGuard/OpenVPN plus stealth proxies (Shadowsocks, AmneziaWG, VLESS/VMess/Trojan, Hysteria) for censorship resistance, no-logs policy claims, and privacy-friendly payments.

Xeovo is a consumer VPN and stealth-proxy service operated by Xeovo Oy in Helsinki, Finland. The product encrypts device traffic to Xeovo exit nodes and substitutes a server IP from a chosen location. The company presents itself as independent and bootstrapped, with a public timeline starting in April 2016.

It exists for people who need censorship resistance as well as a standard VPN. Core tunnels are WireGuard and OpenVPN. For networks that block or fingerprint standard VPN handshakes, Xeovo layers stealth proxies such as Shadowsocks, AmneziaWG, VLESS/VMess, Trojan, and Hysteria.

The concrete differentiator is that stealth-proxy catalog plus a vendor-stated no-logs policy and privacy-friendly payment options, from a small Finnish operator rather than a mass-market streaming brand.

Finnish Xeovo OyWireGuard + OpenVPNStealth proxies + AmneziaWGCash & crypto paymentsAnnual transparency reports

Shortlist Xeovo when you need a Finnish EU operator with WireGuard/OpenVPN plus a real stealth-proxy toolkit (AmneziaWG, multi-protocol obfuscation, Hysteria 2) and cash/crypto payment options. Skip when you require independent no-logs audits, port forwarding, dedicated IPs, or streaming reliability—prefer Mullvad or Proton VPN instead.

Key capabilities

Official features page documents WireGuard (ChaCha20/Poly1305, Curve25519; ports 51280/53/80/443, AmneziaWG configs) and OpenVPN (AES-256-GCM, TLS 1.3, TCP 443 and UDP 1196). Suits teams that want modern defaults without proprietary tunnels—still validate leaks on your OS stack.

Shadowsocks (+ v2ray plugin), VLESS/VMess (WS+TLS), Trojan (TLS/WS+TLS), AmneziaWG, and Hub-announced Hysteria 2.0 for networks that block plain VPN. Subscription generators target tested third-party clients; no SOCKS5. Availability claims for restricted countries are vendor status-matrix based.

Built-in generators produce VPN and stealth subscription configs. WireGuard/AmneziaWG/OpenVPN can use custom DNS or Xeovo’s ad/tracker-blocking DNS (lists such as pgl.yoyo.org, AdAway, oisd). Useful for power users; block lists may break some sites.

Marketing cites ~27 countries / ~60 servers with quality-over-quantity positioning. status.xeovo.com shows per-node health and which VPN/stealth locations allow P2P. Five concurrent devices, unlimited bandwidth marketing, IPv6, WireGuard kill-switch—no port forwarding or dedicated IPs.

Accepts cash, Monero, Bitcoin, and Litecoin alongside cards and PayPal. Registration needs a username/password; email is optional for recovery and billing notices. Prepaid plans with a one-time 30-day money-back window (crypto refunds excluded per terms).

At a glance

HQ
Helsinki, Finland (Xeovo Oy)
Legal entity
Xeovo Oy, reg. 3233901-7
Timeline
Public product history from April 2016
Protocols
WireGuard, OpenVPN, AmneziaWG, Shadowsocks, VLESS/VMess, Trojan, Hysteria 2
Network
~27 countries / ~60 servers (vendor); live status map
Open source
No (uses open protocols; service not OSS)
Self-host
No (SaaS VPN)
Commercial model
Prepaid subscription; 5 devices; 30-day refund (limits apply)

Best fit when

  • Users under active DPI/censorship who need Shadowsocks, AmneziaWG, VLESS/VMess/Trojan, or Hysteria—not only plain WireGuard
  • Buyers who want a Finnish EU legal entity and GDPR-framed privacy policy with claimed EEA storage for account data
  • Privacy-oriented individuals who value optional email, cash/Monero/BTC/LTC payments, and prepaid subscriptions
  • Power users comfortable with config generators and third-party stealth clients rather than a single mega-app
  • Teams fine with a compact ~27-country map and live status/P2P labels instead of thousands of cities

Poor fit when

  • Procurement that requires independent no-logs audits, ISO 27001/SOC 2 evidence, and a public B2B DPA with subprocessors
  • Users who need port forwarding, dedicated/residential IPs, or reliable access to major streaming catalogues
  • Organisations standardising only on audited multi-hop or RAM-only infrastructure claims Xeovo does not publish
  • Households seeking a free tier or free trial (only prepaid + limited money-back)
  • Anyone who will treat vendor no-logs claims as verified without third-party evidence

Consider instead when

  • When: You need stronger anonymous-account culture and long-standing independent reputation

    Consider: Mullvad

    Better default when stealth protocols are secondary to audited privacy ops

  • When: You want a larger EU brand suite, free tier options, and deeper corporate security programme material

    Consider: Proton VPN

    Prefer for broader product integration and procurement packaging

  • When: You want simple Dutch consumer apps and lifetime packaging more than censorship tooling

    Consider: GOOSE VPN

    Different protocol story; fewer stealth-focused features

Jurisdiction & ownership

Legal entity
Xeovo Oy (reg. no. 3233901-7), Rautiontie 5G 30, 00640 Helsinki, Finland
Governing law
Finnish courts for unresolved disputes (terms of service)
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
No public infrastructure/subprocessor register. Privacy policy claims stored personal data is not transferred outside the EEA. VPN and stealth exit nodes on status.xeovo.com include EU/EEA locations plus Australia, Brazil, Canada, Japan, Singapore, South Korea, and multiple US cities. Payment rails include global card networks, PayPal, and crypto; Xeovo states it does not store full card data.

No known US parent; company markets as independent/bootstrapped. CLOUD Act residual risk is driven by unknown hosting operators and optional US exit routing, not by HQ alone. Account-data EEA claim does not equal zero US-touch on tunnel path. Indicative only—not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • HighNo public independent no-logs audit

    High-sensitivity buyers must treat no-logs and transparency reports as first-party claims. Demand external evidence or shortlist an audited peer.

  • MediumInfrastructure and subprocessors not published

    Without a DC/payment/email/hosting register, residual transfer and CLOUD Act analysis stays incomplete even with Finnish HQ and EEA storage claims for account data.

  • MediumOptional US and other non-EU exit nodes

    Status map includes multiple US cities and other non-EU locations. Choose EU exits deliberately when residency of tunnel egress matters.

  • MediumNo port forwarding or dedicated IPs; streaming weak

    FAQ denies port forwarding and dedicated/residential IPs; major streaming services likely blocked. Hard blockers for some use cases.

  • LowFive concurrent devices; personal accounts

    Five simultaneous connections and terms against multi-person account sharing constrain household or team rollouts.

Open questions for due diligence

  • Will Xeovo publish or provide under NDA a current infrastructure and subprocessor list (DCs, payment processors, email, CDN for stealth)?
  • Is an independent no-logs or application security audit planned or available on request?
  • For B2B: will Xeovo Oy sign a GDPR DPA with a named subprocessor schedule?
  • What exact retention periods apply to payment metadata, tickets, and WireGuard/proxy keys after account deletion?
  • Which official first-party apps (if any) ship kill-switch and DNS controls vs config import only per platform?

Frequently Asked Questions

No independent third-party no-logs or infrastructure audit PDF was found on official Xeovo pages at research time. The privacy policy claims no session usage logs and no logging of IP, traffic, timestamps, DNS, MAC, or individual bandwidth. Annual first-party transparency reports on the Hub (e.g. 2024–2025) state zero valid law-enforcement disclosures in those years. Treat no-logs as vendor-claimed, corroborated only by self-published transparency posts unless an external audit appears.

Use standard WireGuard or OpenVPN when the path is not actively fingerprinting or blocking VPN handshakes—lower complexity and official kill-switch behaviour on WireGuard. Switch to stealth stacks (Shadowsocks, AmneziaWG, VLESS/VMess, Trojan, Hysteria 2) when DPI or blocks break plain VPN, as the FAQ describes for environments such as China, Russia, Iran, or the UAE. Stealth often means third-party clients and subscription URLs rather than a single proprietary app feature.

Official FAQ: no port forwarding and no dedicated or residential IPs. Popular streaming services such as Netflix are described as blocking Xeovo IPs and most likely will not work; less popular services might. Choose another provider if those capabilities are mandatory.

Privacy policy separates tunnel no-logs from account records: username, hashed password, optional email, account creation date, payment metadata (order number, method, status, expiry), referral link, WireGuard/proxy keys, and support tickets. Xeovo says it does not store full payment card data and will not transfer stored personal data outside the EEA. That is still not a zero-knowledge anonymous account model like number-only designs at some peers.

Xeovo sells prepaid subscriptions only (no free tier or free trial). Concurrent use is capped at five devices. A 30-day money-back guarantee applies once per customer/account; terms exclude refunds for cryptocurrency payments. Cancel anytime on the billing page and keep access through the paid period. Confirm current packaging on xeovo.com.