AirVPN
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Italian hacktivist-founded VPN (Perugia, 2010), no-logs, port forwarding, but no longer serves Italian residents (Piracy Shield).
AirVPN is an EU-owned service hosted in Italy, with no identified CLOUD Act exposure. It is listed under VPN.
Assessment notes
AirVPN is an Italian-incorporated, founder-controlled (Paolo Brini), unfunded VPN service launched in 2010 by a hacktivist collective in Perugia with a more-than-decade record of no logging or security scandals: strong no-logs posture, transparency reports, port forwarding, multi-protocol. EU-owned, EU-incorporated, no US ties, no CLOUD Act exposure. Editorial flag: AirVPN terminated service for residents of Italy on 19 February 2024 in protest of the Italian ''Piracy Shield'' blocking regime, which is a structural procurement flag worth surfacing. Signal gap: AirVPN does not publish a DPA. Only ToS and a privacy notice are available, with no processor agreement for EU buyers to self-serve.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
Public DPA: No
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: No
Jump to
About AirVPN
AirVPN is an Italian privacy-focused VPN founded in 2010 by a Perugia-based hacktivist collective and owned today by Paolo Brini. The service is intentionally small, unfunded, and operated outside the venture-backed VPN consolidator economy that has absorbed most of the brand-name competition (NordVPN, ExpressVPN, Surfshark, etc.). The product targets technically-fluent users who care about hard privacy guarantees: no activity logs, OpenVPN and WireGuard multi-protocol support, IPv6 support, port forwarding, custom DNS, multi-hop, gigabit servers, and detailed real-time server-status pages.
For an EU-sovereignty audit AirVPN is structurally clean (Italian-incorporated, no US ties, no US-VC ownership, no US sub-processors on the customer-data path), and the no-logs claim is backed by an over-a-decade track record without security scandals. The catch, and the reason this listing carries a hard editorial caveat, is that on 19 February 2024 AirVPN terminated service for residents of Italy in direct response to Italy's "Piracy Shield" blocking regime. The Italian government mandates that ISPs, DNS resolvers, and intermediaries block flagged pirate-IP addresses within thirty minutes of alert without prior judicial review; AirVPN deemed the requirements an unacceptable risk for overblocking and human-rights violations, and new users must now declare that they are not Italian residents. So while the corporate posture is Italian and EU-controlled, the customer-availability story is unusual: AirVPN serves EU customers from every member state except Italy.
Pricing is straightforward: a 3-day trial starts at €2; monthly plans around €7; 3-year heavily discounted (~€1.50/month equivalent). Bitcoin and other cryptocurrencies are accepted alongside cards. Best fit: privacy-maximalist users across the EU (excluding Italy), torrent-friendly use cases, and anyone wanting a small, founder-controlled provider with a documented activist posture. The Italian-resident blockade is itself a procurement signal: both as evidence of the vendor's willingness to walk away from a regime it disagrees with, and as a practical exclusion for any Italian buyer.
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of AirVPN
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
missingData Processing Addendum (DPA)— missing
-
missingSub-processors list— missing
-
OpenTerms of Serviceairvpn.org/tos…
Alternatives in this category
-
Sweden · €3.75/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
Romania · €2.19/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: No -
-
Finland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
€3.75/mo |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: No
|
€2.19/mo |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: No
|
€4/mo |