Mesh VPNs and private networks
NetBird privacy rating
WireGuard-based mesh VPN and zero-trust access platform with open-source clients and a management server that can be self-hosted or used as NetBird's hosted service.
Summary
NetBird scores 71 out of 100 (grade C) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no ads or data sales, keys stay on devices, self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).
Score 71 out of 100. How scoring works
Criteria
-
Yes
Open source Weight 3 of 3
Is all the source code needed to run the product public?
BSD-3-Clause for the clients and AGPL-3.0 for the management, signal and relay servers.
-
No
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The website uses Google Analytics, Microsoft Clarity, Hotjar, HubSpot and Reddit tracking.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by paid cloud plans, with no ads in the product.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
Yes
Keys stay on devices Weight 3 of 3
Is traffic encrypted between devices with private keys created on each device, so the coordination server and relays cannot read it?
The client creates the WireGuard private key, which never leaves the device. The management service only distributes public keys, and relays cannot decrypt traffic.
-
Yes
Self-hosted coordination server Weight 2 of 3
Can the coordination or control server be self-hosted with open-source software?
The management, signal and relay servers are open source under AGPL-3.0 and can be self-hosted.
-
Yes
No connection logs by default Weight 2 of 3
Are connection logs and client diagnostic logs kept off the vendor's servers unless a user or admin turns them on?
Traffic event logging is off by default. Client debug bundles are only uploaded when a user runs the upload command.