Zum Inhalt springen
CLOUD-Act-Risiko ausgewiesen
EU VETTED

NordVPN

VERIFIZIERT
VPN · Litauen
Gegründet 2012 · nordvpn.com ↗

Panama-incorporated VPN (NordVPN S.A.) under NL holding Nord Security, LT operations; Deloitte + PwC no-logs audits, RAM-only diskless servers, ISO 27001.

Kurzfassung

NordVPN aus der Kategorie VPN ist ein europäischer Dienst mit Litauen als Hosting-Standort und höchstens geringfügigem, vorübergehendem US-Bezug nach dem CLOUD Act.

Bewertungsnotizen

NordVPN's ownership chain is genuinely complex and not EU-owned in the strict sense: the VPN service is operated by NordVPN S.A. (Panama), historically Tefincom S.A., a Panamanian entity chosen for its no-data-retention jurisdiction, under the Nord Security holding company in Amsterdam, Netherlands, with operations and staff in Vilnius, Lithuania, and the holding company has taken $200M of US-led growth capital across two rounds, the 2022 $100M round co-led by US VC General Catalyst alongside Novator (IS) and Burda (DE), and a second $100M round led by Warburg Pincus (US) on 28 September 2023 at a $3B valuation, both minority; the product itself is one of the most rigorously audited consumer VPNs (annual no-logs assurance engagements by PwC and then Deloitte, most recently Deloitte Lithuania under ISAE 3000 for November to December 2025, full transition to colocated diskless RAM-only servers, ISO 27001), so it is included as a privacy-pick rather than a sovereignty-pick. Ownership signals: Panama operating entity (not EU-owned), US minority stakes in the holding (General Catalyst, Warburg Pincus), CLOUD Act exposure rated minor due to Panama incorporation + RAM-only architecture eliminating data-at-rest exposure. No public DPA at the NordVPN S.A. level for individual consumers; a business DPA is available at business.nordsec.com.

CLOUD ACT
Eigentümer
Unterauftr.
nicht offengelegt
Geprüfte Signale
Jurisdiktion
  • EU-/Angemessenheits-Hosting
  • EU-/Angemessenheits-Betreiber
  • Keine US-CLOUD-Act-Exposition
Transparenz
  • Öffentlicher AVV
  • Unterauftragsverarbeiter offengelegt
  • Open-Source-Clients
  • Zertifizierung durch Dritte
Springen zu
Überblick

Über NordVPN

NordVPN is the flagship product of Nord Security, the Lithuanian cybersecurity group that also operates NordPass, NordLayer, NordLocker, NordStellar and, since the 2022 merger, Surfshark. It is one of the largest consumer VPN services in the world (Nord Security reports more than 20M users across its products with NordVPN accounting for around 15M). It is included in this directory as a privacy-pick rather than an EU-sovereignty pick. The distinction matters, because the ownership chain is unusually layered.

The legal entity that operates the VPN service is NordVPN S.A., registered in Panama. Historically named Tefincom S.A., this entity was deliberately set up in Panama for its absence of mandatory data-retention laws, which is itself a privacy positioning. The group holding company is Nord Security in Amsterdam, Netherlands. Day-to-day operations and the bulk of the engineering team are in Vilnius, Lithuania. And the cap table includes US capital across two rounds: the 2022 $100M round was co-led by General Catalyst (US) alongside Novator (Iceland) and Burda (Germany), and a second $100M round led by Warburg Pincus (US growth equity) closed on 28 September 2023 at a $3B valuation, with Novator and Burda participating again. Both US stakes are minority and the founders are still reported as the largest holders after dilution. None of those layers makes NordVPN US-incorporated (the CLOUD Act does not apply directly to a Panamanian entity), but the company is also clearly not EU-owned in the way Mullvad (founder-owned Swedish AB) or ProtonVPN (Swiss non-profit Foundation) are.

Where NordVPN is genuinely strong is product security and audit history. Independent no-logs assurance engagements have validated the no-retention claim, first by PwC and since by Deloitte on what is now an annual cadence: the sixth engagement was run by Deloitte Lithuania under ISAE 3000 (Revised) with access from 10 November to 12 December 2025 and announced on 6 February 2026; the entire server fleet has been transitioned to colocated, diskless RAM-only servers so configuration is loaded fresh on every boot and nothing persists; Nord Security holds ISO/IEC 27001; and the product offers WireGuard (NordLynx), kill-switch, multi-hop, Tor-over-VPN, and threat-protection extras. cloud_act_exposure is set to minor rather than material to reflect the Panama incorporation + RAM-only architecture (no data-at-rest exposure). The US minority stakes and likely US payment / CDN sub-processors keep it above none.

Pricing is paid-only (no free tier; 30-day money-back): Basic from around €3.99/month on a 2-year plan, Plus and Complete tiers above. The affiliate programme is one of the most lucrative in the entire VPN category (see affiliate block). Best fit: mainstream privacy-conscious buyers who want a heavily audited, RAM-only no-logs VPN with broad device coverage and aggressive pricing on long commitments. EU buyers who specifically want sovereignty rather than just privacy should prefer Mullvad (SE), ProtonVPN (CH), IVPN, or AirVPN (IT), all elsewhere in this directory.

Unterauftragsverarbeiter

Unterauftragsverarbeiter-Karte · nicht offengelegt

Anbieter veröffentlicht keine Liste der Unterauftragsverarbeiter. Schrems-II-Konformität und CLOUD-Act-Risiko lassen sich ohne sie nicht unabhängig prüfen.
Zertifizierungen

Rahmenwerke & Zertifizierungen

ISO/IEC 27001
AKTIV
Funktionen

Funktionsmatrix

Länder 129 Länder
Gleichzeitige Geräte 10 Geräte
Protokolle WireGuard OpenVPN IKEv2
Kill-Switch Ja
Geprüfte No-Logs-Politik Ja
Port-Forwarding Nein
Plattformen iOS macOS Windows Android Linux
INTEGRATION & ZUGRIFF
REST API No
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
Preise

Preise & Tarife

KOSTENPFLICHTIG
ab 4 €/Monat
Preisseite ansehen ↗
Öffentliche Dokumente

Öffentliche Dokumente

Anbieter veröffentlicht keine Liste der Unterauftragsverarbeiter. Schrems-II-Konformität und CLOUD-Act-Risiko lassen sich ohne sie nicht unabhängig prüfen.
  • Auftragsverarbeitungsvertrag (AVV)
    business.nordsec.com/legal…
    Öffnen ↗
  • Liste der Unterauftragsverarbeiter
    — fehlt
    fehlt
  • Nutzungsbedingungen
    my.nordaccount.com/legal…
    Öffnen ↗
Alternativen

Alternativen in dieser Kategorie

AirVPN
Italien · Gegründet 2010
EU-SOUVERäN

Italian hacktivist-founded VPN (Perugia, 2010), no-logs, port forwarding, but no longer serves Italian residents (Piracy Shield).

Öffentl. AVV Subprozessoren Open Source
FROM
7 €/Mt.
CLOUD ACT
NONE
AzireVPN
Schweden · Gegründet 2012
EU-GEHOSTET

Swedish privacy VPN (Stockholm, est. 2012): Blind Operator, RAM-only, audited no-logs; acquired by Malwarebytes (US) 7 Nov 2024.

Öffentl. AVV Subprozessoren Open Source
FROM
3.75 €/Mt.
jährliche Abrechnung
CLOUD ACT
MATERIAL
CyberGhost
Rumänien · Gegründet 2011
EU-ANSäSSIG

Romanian-operated VPN (CyberGhost S.R.L., 2011) under Kape Technologies (UK; ex-Crossrider) → Unikmind/Teddy Sagi (IM) since 2023; listed as a warning.

Öffentl. AVV Subprozessoren Open Source
FROM
2.19 €/Mt.
jährliche Abrechnung
CLOUD ACT
MINOR

In diesen Übersichten gelistet