{
  "slug": "surfshark",
  "category": "vpns",
  "name": "Surfshark",
  "description": "Commercial VPN service from Surfshark B.V. in the Netherlands. Apps support WireGuard, OpenVPN and IKEv2.",
  "website": "https://surfshark.com",
  "license": null,
  "platforms": [
    "windows",
    "macos",
    "linux",
    "android",
    "ios"
  ],
  "jurisdiction": {
    "code": "NL",
    "name": "Netherlands",
    "eyes": "Nine Eyes",
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 48,
  "coverage": 100,
  "summary": "Surfshark scores 48 out of 100 (grade D) on the VPN providers criteria. It meets 5 of 12 criteria: no ads or data sales, independent audit, transparency report, TLS configuration and modern protocols. It partly meets audited no-logs policy and anonymous payment. It does not meet open source, no trackers or telemetry, tells users about requests, security headers and open-source apps. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C-.",
  "url": "https://privacyratings.com/vpns/surfshark/",
  "markdown": "https://privacyratings.com/vpns/surfshark/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://surfshark.com/privacy",
      "note": "The privacy policy lists Firebase Analytics and AppsFlyer for app analytics and marketing attribution."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://surfshark.com/privacy",
      "note": "Funded by paid subscriptions. The policy states personal data is not sold, rented or traded."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://surfshark.com/media/SurfShark-InfrastructureTestReport_20251217_Public.pdf",
      "note": "Full SecuRing penetration test report on the server infrastructure is public."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://surfshark.com/transparency-report",
      "note": "Quarterly counts of user data requests by type are published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=surfshark.com&hideResults=on",
      "note": "Grade A"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=surfshark.com",
      "note": "Grade C- (45/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "no_logs_audited": {
      "title": "Audited no-logs policy",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://surfshark.com/blog/deloitte-nologs-policy-verified-again",
      "note": "Deloitte assessed the no-logs policy, but the full report is only available to logged-in users, not publicly."
    },
    "anonymous_payment": {
      "title": "Anonymous payment",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://support.surfshark.com/hc/en-us/articles/360003069034-What-payment-options-do-you-offer",
      "note": "Cryptocurrency is accepted, but an email address is needed for the account."
    },
    "open_source_clients": {
      "title": "Open-source apps",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "The apps are closed source."
    },
    "modern_protocols": {
      "title": "Modern protocols",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://surfshark.com/blog/wireguard-protocol-is-now-live-on-surfshark",
      "note": "WireGuard is supported alongside OpenVPN and IKEv2."
    }
  },
  "tests": {
    "ssllabs": "A",
    "observatory": "C-",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Trustpilot",
        "host": "www.trustpilot.com",
        "effect": "none"
      }
    ],
    "tested_at": "2026-10-01T06:38:26.701Z"
  },
  "last_modified": "2026-10-01T06:56:31Z"
}