{
  "slug": "defguard",
  "category": "mesh-vpns",
  "name": "Defguard",
  "description": "Self-hosted WireGuard VPN platform with multi-factor authentication on every connection, identity management and access rules, from a company in Poland.",
  "website": "https://defguard.net",
  "source": "https://github.com/DefGuard/defguard",
  "license": null,
  "platforms": [
    "windows",
    "macos",
    "linux",
    "android",
    "ios"
  ],
  "jurisdiction": {
    "code": "PL",
    "name": "Poland",
    "eyes": null,
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "B",
  "score": 82,
  "coverage": 100,
  "summary": "Defguard scores 82 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 6 of 7 criteria: open source, no ads or data sales, independent audit, keys stay on devices, self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry. It is based in Poland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
  "url": "https://privacyratings.com/mesh-vpns/defguard/",
  "markdown": "https://privacyratings.com/mesh-vpns/defguard/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/DefGuard/defguard/blob/main/LICENSE.md",
      "note": "All code is public. The core is AGPL-3.0, and enterprise features in the same repository use the source-available Defguard Enterprise License."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://defguard.net",
      "note": "The website loads Google Tag Manager."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://defguard.net/pricing/",
      "note": "Funded by paid enterprise licenses, with no ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://defguard.net/pentesting/",
      "note": "Findings from periodic penetration tests by ISEC are published in full, with links to the fixes."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "device_keys": {
      "title": "Keys stay on devices",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://docs.defguard.net/features/network-devices",
      "note": "The server does not store WireGuard private keys. Traffic ends at gateways on your own infrastructure."
    },
    "self_hosted_control": {
      "title": "Self-hosted coordination server",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://github.com/DefGuard/defguard",
      "note": "The core server is open source and self-hosted only."
    },
    "no_connection_logs": {
      "title": "No connection logs by default",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://defguard.net",
      "note": "Defguard is self-hosted only, so connection logs stay on your own servers."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T07:02:25.283Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}