Skip to content
Independently verified · Quarterly re-audit
EU VETTED

F-Secure VPN

VERIFIED
VPN · Finland
Founded 1988 · f-secure.com/en/vpn ↗

Finnish publicly listed VPN (F-Secure Corporation, Helsinki; Nasdaq Helsinki: FSECURE), formerly FREEDOME VPN, ISO 27001-certified company-wide but with no independently audited no-logs claim.

In short

F-Secure VPN, in the VPN category, is a European service with Finland as its hosting location and at most minor, transient US exposure under the CLOUD Act.

Assessment notes

F-Secure VPN (formerly branded FREEDOME VPN) is operated by F-Secure Corporation (Business ID 3269349-7), a Finnish publicly listed company headquartered in Helsinki and traded on Nasdaq Helsinki (FSECURE) since the 1 July 2022 partial demerger that split F-Secure's consumer-security business from the corporate-security business now called WithSecure; co-founder Risto Siilasmaa remains the largest shareholder at roughly 40%, with no foreign or US parent identified, and the company holds a company-wide ISO/IEC 27001:2022 certification (KPMG IT Certification, certificate FI241106-169). On the axis that matters most for a VPN listing, independently audited no-logs evidence, F-Secure has none: its own VPN privacy notice discloses that it retains VPN service-provisioning logs (source IP address, random device ID, GeoIP country, access timestamp) for one year and VPN service-log events for three months, and this retained connection metadata is exactly what let Finland's National Bureau of Investigation obtain and hand over FREEDOME VPN logs to German prosecutors in a January 2019 criminal case; the seizure was later ruled unlawful by the Helsinki Court of Appeal and the data ordered destroyed, but the episode proves connection-identifying logs existed to seize in the first place. No Cure53/Deloitte/PwC-style independent no-logs audit has ever been published for F-Secure VPN. cloud_act_exposure is set to minor rather than none because F-Secure's own privacy notice states it engages an unnamed third-party infrastructure provider to help operate the newer WireGuard/Hydra VPN version, whose corporate jurisdiction is not disclosed; there is no evidence of a US parent or that F-Secure Corporation itself is US-incorporated, so exposure is not rated material. Finland is a member of the 14 Eyes intelligence-sharing alliance, a jurisdictional caveat that applies on top of the no-logs gap regardless of F-Secure's otherwise clean Nordic ownership. No public DPA was found. Net: solid EU/Nordic public-company ownership and a real company-wide ISO 27001 certification, offset by the weakest no-logs evidence base and the only confirmed real-world logs-were-seized precedent of any VPN in this directory.

CLOUD ACT
OWNERSHIP
SUB-PROCS
0 none disclosed
Verified signals
Jurisdiction
  • EU / adequacy hosting
  • EU / adequacy operator
  • No US CLOUD Act exposure
Transparency
  • Public DPA
  • Sub-processors disclosed
  • Open-source clients
  • Third-party certification
JUMP TO
OVERVIEW

About F-Secure VPN

F-Secure VPN, formerly branded FREEDOME VPN, is operated by F-Secure Corporation, a Finnish company headquartered at Tammasaarenkatu 7, Helsinki (Business ID 3269349-7). F-Secure traces back to Data Fellows, founded on 16 May 1988 by Petri Allas and Risto Siilasmaa. The company as it exists today is the product of a 1 July 2022 partial demerger: WithSecure Corporation (the pre-2022 combined entity) split its consumer-security business into a newly listed F-Secure Corporation on Nasdaq Helsinki (ticker FSECURE), while the corporate/enterprise-security business kept the WithSecure name. Co-founder Risto Siilasmaa remains F-Secure's largest shareholder, reported at roughly 40% of shares outstanding, with no foreign or US corporate parent identified in the ownership chain. F-Secure holds a company-wide ISO/IEC 27001:2022 certification (KPMG IT Certification Ltd, certificate FI241106-169) covering its Helsinki, Oulu, Bratislava, Kuala Lumpur, Bengaluru and Hilversum offices.

The product itself is a consumer VPN sold standalone or bundled inside F-Secure Total. It offers virtual server locations in "over 20 countries" per F-Secure's own marketing copy, which does not give an exact server or country count, so both are recorded as null here rather than guessed. Plans cap at 5 simultaneous devices. Two VPN protocol generations are in circulation: the older version runs OpenVPN and IPSec/IKEv2, and the newer version (rolled out via app updates) runs WireGuard, the proprietary Hydra protocol, and IPSec. Kill switch is available on Windows, macOS and Android (not documented for iOS). Port forwarding is not offered or mentioned anywhere in F-Secure's own documentation.

The no-logs picture is the reason this listing scores low despite clean ownership. F-Secure's own VPN privacy notice states plainly that it does not log which destination addresses a customer connects to, but it separately discloses that it does retain VPN service-provisioning logs, source public IP address, a randomly generated device ID, GeoIP-derived country, and access timestamps, for one year, plus VPN service-log events for provisioned devices for three months, and temporary abuse-detection logs for 90 days. This is exactly the kind of connection metadata that, in January 2019, Finland's National Bureau of Investigation formally requested from F-Secure in connection with a serious-crime investigation led by German prosecutors; F-Secure handed the logs over, then went to court arguing the seizure was overbroad and coercive. In May 2019 a Finnish district court agreed, and after the NBI's appeal, the Helsinki Court of Appeal ruled the seizure of the FREEDOME VPN logs unlawful and ordered the data destroyed. The logs at issue reportedly contained customer IP addresses, device IDs, and VPN session start/end times, not visited-site records, so the "no logging of destination traffic" claim survives narrowly, but the case is direct, real-world proof that F-Secure's VPN retains and can be compelled to hand over identifying connection metadata. No independent third-party audit (Cure53, Deloitte, PwC or otherwise) of any F-Secure no-logs claim was found on F-Secure's own site or in its press materials, which puts F-Secure behind every audited competitor in this directory (Mullvad, IVPN, ProtonVPN, NordVPN, Surfshark, CyberGhost, Opera VPN) on the one axis this category is built around.

F-Secure's own VPN privacy notice additionally discloses that the newer WireGuard/Hydra VPN version is provided with the help of an unnamed third-party infrastructure provider that also processes customer data; its identity and jurisdiction are not published. Separately, an F-Secure staff reply in the company's own community forum states that F-Secure uses roughly 10-20 different third-party hosting providers worldwide for its physical servers, legally owned by F-Secure with exclusive physical access, but does not name them. Neither disclosure confirms a US-owned sub-processor, so cloud_act_exposure is recorded as minor rather than material, but the lack of a named, auditable sub-processor list is itself a transparency gap. Finland is a member of the 14 Eyes intelligence-sharing alliance, the same jurisdictional caveat this directory applies to Sweden (Mullvad, OVPN) and Norway (Opera VPN); it does not by itself lower the ownership signal, but it is a fact EU/EEA buyers evaluating jurisdictional exposure should weigh alongside the no-logs gap above.

Pricing is subscription-only with no persistent free tier: a 5-day free trial is offered, and F-Secure's own site advertises annual plans at EUR 49.99/year for 1 device (the true entry price, equivalent to about EUR 4.17/month, billed annually), EUR 69.99/year for 3 devices, and EUR 79.99/year for 5 devices, alongside pricier 2-year commitments. A 30-day money-back guarantee applies. F-Secure runs its own affiliate programme (hosted via Cleverbridge/Partnerize) covering F-Secure Total, Internet Security, Scam Protection and VPN, advertising "up to 30% commission" with no minimum payout on F-Secure's own affiliate page; third-party affiliate aggregators report figures up to 40% and a 60-day cookie, neither of which is confirmed on F-Secure's own site, so those numbers are not used here. Best fit: mainstream buyers who already want an antivirus/identity-protection bundle from a recognisable, publicly listed Nordic vendor and are not specifically shopping for an independently audited no-logs guarantee. EU/EEA buyers whose priority is a proven, audited no-logs architecture should prefer Mullvad, OVPN, ProtonVPN or IVPN, all elsewhere in this directory.

SUB-PROCESSORS

Sub-processor map · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
CERTIFICATIONS

Frameworks & certifications

ISO/IEC 27001
ACTIVE
FEATURES

Capability matrix

Simultaneous devices 5 devices
Protocols WireGuard IKEv2 ui.features.token_hydra
Kill switch Yes
Audited no-logs No
Port forwarding No
Platforms iOS macOS Windows Android
INTEGRATION & ACCESS
REST API No
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
from €4/mo
billed annually
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement. This is recorded as no public DPA (see How we assess).
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    www.f-secure.com/en…
    Open ↗
  • Terms of Service
    www.f-secure.com/en…
    Open ↗
ALTERNATIVES

Alternatives in this category

AirVPN
Italy · Founded 2010
EU-SOVEREIGN

Italian hacktivist-founded VPN (Perugia, 2010), no-logs, port forwarding, but no longer serves Italian residents (Piracy Shield).

Public DPA Sub-processors Open source
FROM
€7/mo
CLOUD ACT
NONE
AzireVPN
Sweden · Founded 2012
EU-HOSTED

Swedish privacy VPN (Stockholm, est. 2012): Blind Operator, RAM-only, audited no-logs; acquired by Malwarebytes (US) 7 Nov 2024.

Public DPA Sub-processors Open source
FROM
CLOUD ACT
MATERIAL
CyberGhost
Romania · Founded 2011
EU-BASED

Romanian-operated VPN (CyberGhost S.R.L., 2011) under Kape Technologies (UK; ex-Crossrider) → Unikmind/Teddy Sagi (IM) since 2023; listed as a warning.

Public DPA Sub-processors Open source
FROM
€2/mo
CLOUD ACT
MINOR