Mesh VPNs and private networks
NordVPN Meshnet privacy rating
Free mesh networking feature of the NordVPN apps that links devices directly over NordLynx, a WireGuard-based protocol. Meshnet is free to use.
Summary
NordVPN Meshnet scores 29 out of 100 (grade F) on the mesh VPNs and private networks criteria. It meets 1 of 7 criteria: no ads or data sales. It partly meets open source and keys stay on devices. It does not meet no trackers or telemetry and self-hosted coordination server. Still needing evidence: independent audit and no connection logs by default. It is based in Panama: Not in the Five, Nine or Fourteen Eyes.
Score 29 out of 100. How scoring works
Criteria
-
Partial
Open source Weight 3 of 3
Is all the source code needed to run the product public?
The libtelio networking library and the Linux app are GPL-3.0. The other apps and the coordination servers are closed source.
-
No
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The Android app includes AppsFlyer, Google Firebase Analytics and Crashlytics.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Free to use and funded by NordVPN subscriptions, with no ads in the apps.
-
Unknown
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
Needs evidence. Add it
-
Partial
Keys stay on devices Weight 3 of 3
Is traffic encrypted between devices with private keys created on each device, so the coordination server and relays cannot read it?
Connections are described as end-to-end encrypted, but where keys are created and what relays can see is not documented.
-
No
Self-hosted coordination server Weight 2 of 3
Can the coordination or control server be self-hosted with open-source software?
Only NordVPN's hosted service can be used.
-
Unknown
No connection logs by default Weight 2 of 3
Are connection logs and client diagnostic logs kept off the vendor's servers unless a user or admin turns them on?
Needs evidence. Add it