# Mesh VPNs and private networks privacy ratings

Software that joins devices into an encrypted private network, with a coordination server that is hosted by the vendor or self-hosted.

**Our picks:** [Tailscale](https://privacyratings.com/mesh-vpns/tailscale/): A WireGuard mesh for Windows, macOS, Linux, Android and iOS, with NAT traversal and DERP relays when a direct connection fails. Keys are created on each device, so the coordination server and relays never see traffic. The clients are open source under BSD-3-Clause, ACLs and SSO come built in, and the open-source Headscale server can replace the hosted coordination server for full self-hosting. [Headscale](https://privacyratings.com/mesh-vpns/headscale/): The open-source, self-hosted replacement for Tailscale's coordination server. The official Tailscale clients connect to it unchanged, so the whole network runs on your own server with no account at Tailscale.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [Tailscale](https://privacyratings.com/mesh-vpns/tailscale/) (our pick) | D (50/100) | Canada (Five Eyes) | Mesh VPN built on WireGuard that connects devices into a private network using a hosted coordination server for key exchange and access control, with open-source clients. |
| [Headscale](https://privacyratings.com/mesh-vpns/headscale/) (our pick) | B (82/100) | Unknown | Self-hosted, open-source implementation of the Tailscale coordination server, letting official Tailscale clients join a private network without using Tailscale's hosted service. |
| [innernet](https://privacyratings.com/mesh-vpns/innernet/) | B (88/100) | Japan | Open-source private network system built on WireGuard, with a self-hosted server that manages peers, CIDR-based groups and access rules. |
| [tinc](https://privacyratings.com/mesh-vpns/tinc/) | B (88/100) | Unknown | Long-running open-source VPN daemon that builds an encrypted mesh between nodes, sending traffic directly to its destination where possible, with no central server. |
| [Defguard](https://privacyratings.com/mesh-vpns/defguard/) | B (82/100) | Poland | Self-hosted WireGuard VPN platform with multi-factor authentication on every connection, identity management and access rules, from a company in Poland. |
| [ionscale](https://privacyratings.com/mesh-vpns/ionscale/) | B (76/100) | Unknown | Open-source, self-hosted Tailscale control server with support for multiple tailnets, OIDC login, ACLs and DNS, used with the official Tailscale clients. |
| [Nebula](https://privacyratings.com/mesh-vpns/nebula/) | C (71/100) | Unknown | Overlay networking tool originally built at Slack that connects hosts over mutually authenticated, encrypted tunnels using its own certificate authority and firewall rules, with self-hosted lighthouse nodes for discovery. |
| [NetBird](https://privacyratings.com/mesh-vpns/netbird/) | C (71/100) | Germany (Fourteen Eyes) | WireGuard-based mesh VPN and zero-trust access platform with open-source clients and a management server that can be self-hosted or used as NetBird's hosted service. |
| [Firezone](https://privacyratings.com/mesh-vpns/firezone/) | D (59/100) | United States (Five Eyes) | Zero-trust remote access platform built on WireGuard, with clients, gateways and a control plane for group-based access policies. Mostly offered as a hosted service; self-hosting the control plane is not officially supported. |
| [OpenZiti](https://privacyratings.com/mesh-vpns/openziti/) | D (59/100) | United States (Five Eyes) | Open-source zero-trust networking platform from NetFoundry that connects apps and devices through an overlay of self-hosted routers and a controller, with tunneler apps and SDKs. |
| [Netmaker](https://privacyratings.com/mesh-vpns/netmaker/) | D (50/100) | United States (Five Eyes) | WireGuard-based platform for building mesh and site-to-site networks, with an open-source server that can be self-hosted and a hosted cloud version. |
| [Husarnet](https://privacyratings.com/mesh-vpns/husarnet/) | D (44/100) | Poland | Peer-to-peer VPN from a company in Poland, built for robotics and IoT, that gives each device an IPv6 address derived from its public key, with a hosted dashboard and relay servers. |
| [ZeroTier](https://privacyratings.com/mesh-vpns/zerotier/) | F (38/100) | United States (Five Eyes) | Peer-to-peer virtual network platform that joins devices into encrypted virtual Ethernet networks, managed through ZeroTier's hosted controller or a self-hosted one. |
| [NordVPN Meshnet](https://privacyratings.com/mesh-vpns/nordvpn-meshnet/) | F (29/100) | Panama | Free mesh networking feature of the NordVPN apps that links devices directly over NordLynx, a WireGuard-based protocol. Meshnet is free to use. |
| [Twingate](https://privacyratings.com/mesh-vpns/twingate/) | F (24/100) | United States (Five Eyes) | Hosted zero-trust remote access service that connects devices to private resources through connectors on the customer's network, managed from Twingate's cloud controller. |
| [Cloudflare Mesh](https://privacyratings.com/mesh-vpns/cloudflare-mesh/) | F (18/100) | United States (Five Eyes) | Private networking in Cloudflare One that gives devices and servers running the WARP client or connector private addresses, with all traffic passing through Cloudflare's network. |
| [LogMeIn Hamachi](https://privacyratings.com/mesh-vpns/hamachi/) | F (18/100) | United States (Five Eyes) | Hosted VPN service from LogMeIn that joins computers into virtual LAN networks, with a free plan for up to five computers per network. |
| [Yggdrasil](https://privacyratings.com/anonymity-networks/yggdrasil/) (rated under Anonymity networks) | B (80/100) | Unknown | Experimental decentralized mesh network that gives each node an IPv6 address and routes end-to-end encrypted traffic between peers; the project states it does not aim to provide anonymity. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?
- **Keys stay on devices** (weight 3): Is traffic encrypted between devices with private keys created on each device, so the coordination server and relays cannot read it?
- **Self-hosted coordination server** (weight 2): Can the coordination or control server be self-hosted with open-source software?
- **No connection logs by default** (weight 2): Are connection logs and client diagnostic logs kept off the vendor's servers unless a user or admin turns them on?

Source: https://privacyratings.com/mesh-vpns/
