# Nebula privacy rating

Overlay networking tool originally built at Slack that connects hosts over mutually authenticated, encrypted tunnels using its own certificate authority and firewall rules, with self-hosted lighthouse nodes for discovery.

## Summary

Nebula scores 71 out of 100 (grade C) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no ads or data sales, keys stay on devices, self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry and independent audit.

- Website: https://github.com/slackhq/nebula
- Source code: https://github.com/slackhq/nebula
- License: MIT
- Platforms: Windows, macOS, Linux, Android, iOS
- Category: [Mesh VPNs and private networks](https://privacyratings.com/mesh-vpns/)
- Grade: C (71/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | MIT. | https://github.com/slackhq/nebula/blob/master/LICENSE |
| No trackers or telemetry | No | No telemetry in the source code, but the official documentation site loads Google Analytics. | https://nebula.defined.net/docs/ |
| No ads or data sales | Yes | Free open-source software maintained by Defined Networking, which sells a managed version, with no ads. | https://github.com/slackhq/nebula |
| Independent audit | No | No independent audit is published. |  |
| Keys stay on devices | Yes | Each host can create its own key pair, and only the public key is sent to the certificate authority for signing. Lighthouses only help hosts find each other. | https://nebula.defined.net/docs/guides/sign-certificates-with-public-keys/ |
| Self-hosted coordination server | Yes | The certificate authority and lighthouses are self-hosted and open source. A managed version is sold separately. | https://nebula.defined.net/docs/guides/quick-start/ |
| No connection logs by default | Yes | Logs are written locally. The open-source version has no vendor service to send them to. | https://nebula.defined.net/docs/config/logging/ |

Source: https://privacyratings.com/mesh-vpns/nebula/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/mesh-vpns/nebula.md
