OVPN
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Stockholm-operated VPN, US-owned since the 2023 Pango acquisition (operating entity OVPN Inc.); fully owns its hardware, diskless RAM-only, court-proven no-logs, legal-fees insurance.
OVPN offers EU hosting in the United States, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under VPN.
Assessment notes
OVPN began as OVPN Integritet AB, a Swedish company publishing transparency reports continuously since 2014, and the engineering story is still strong: it fully owns its server hardware (no rented servers, no virtual machines), all 96 servers across 32 regions are diskless with the operating system in RAM, the no-logs policy is court-proven (an information-injunction case where OVPN simply had nothing to hand over, with legal-fees insurance to underwrite future cases), it supports modern crypto (AES-256-GCM / Curve25519 / ChaCha20 / WireGuard) with full IPv6, and monthly transparency reports are still being published (latest May 2026). The ownership and jurisdiction story, however, is no longer an EU one. OVPN was acquired on 8 May 2023 by Pango (via Intersections, LLC, the US group behind Hotspot Shield, Betternet and VPN 360), and OVPN's own press page now states plainly: The legal operating entity is OVPN Inc., incorporated in US. The current privacy notice is written around OVPN Inc. and its corporate affiliates and names Zendesk (US) as a support sub-processor. Under this directory's rubric a US-incorporated operating entity puts CLOUD Act exposure at material and removes the EU-ownership signal entirely, regardless of where the hardware sits or where the remote-first team lives (Sweden, Hungary, Romania, Ukraine). Listed as a privacy-engineering option carrying an ownership warning, not as a sovereignty pick. Signal gap unchanged: OVPN publishes no DPA, only a privacy notice, with no processor agreement for EU buyers to self-serve.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned This listing The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: No
-
EU / adequacy operator: No
-
No US CLOUD Act exposure: No
-
Public DPA: No
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About OVPN
OVPN is run from Stockholm and has been publishing transparency reports continuously since 2014, but its ownership has changed since it built that reputation. Its own press page states that "the legal operating entity is OVPN Inc., incorporated in US", following the May 2023 acquisition by Pango, the US group behind Hotspot Shield and Betternet; the Swedish company OVPN Integritet AB remains in the structure. The engineering is still what sets it apart from larger competitors, and it is worth reading separately from the corporate question. OVPN fully owns its server hardware: there are no rented servers and no virtual machines anywhere in the fleet, which removes a class of supply-chain and shared-tenancy risk that almost every other VPN provider accepts. All VPN servers are diskless and run their operating system from RAM, so there is no persistent storage on the hardware that could be seized.
The no-logs claim is unusually well-evidenced. Where most VPN providers point at an annual third-party audit, OVPN has the policy legally tested: in an information-injunction case the company was able to demonstrate it had no data to hand over, and OVPN now carries insurance to cover legal fees for future similar cases, a level of structural commitment to non-retention that mirrors Mullvad's culture in the same Swedish jurisdiction. Encryption is modern across the board: AES-256-GCM with OpenVPN, Curve25519 + ChaCha20 with WireGuard. The fleet covers 32 cities globally with full IPv6 support, multihop, port forwarding (up to 7 ports in the 49152-65535 range), and an optional public IPv4 add-on.
For an EU-sovereignty audit, that is where the listing turns. OVPN was for years a natural pairing with Mullvad in the same Swedish jurisdiction, and the technical posture still holds up. The corporate posture no longer does: with a US-incorporated operating entity and a US parent, the consolidated group falls within CLOUD Act reach regardless of where the servers sit, which is the same test this directory applies to every other vendor. The practical effect is limited by the architecture, since diskless RAM-only servers with a court-tested no-logs record leave little to produce, but exposure is a question of corporate control rather than of how much data happens to exist. Buyers with a written EU-jurisdiction requirement should read this as a US vendor with Swedish engineering.
Pricing is paid-only with a 10-day money-back guarantee: 1-month €12, 1-year €4.99/month, 3-year €4.22/month (the long-commitment best-value tier). UI languages: English, Swedish, German, Norwegian. Best fit: privacy-maximalist EU buyers who want a small, owner-operated, structurally-sound Swedish provider with court-tested no-logs, and who prefer "we own everything and it's all in RAM" over a marketing-heavy mainstream brand.
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of OVPN
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Italy · €7/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
Sweden · €3.75/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
Romania · €2.19/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
€7/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
€3.75/mo |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: No
|
€2.19/mo |