Mesh VPNs and private networks
tinc privacy rating
Long-running open-source VPN daemon that builds an encrypted mesh between nodes, sending traffic directly to its destination where possible, with no central server.
Summary
tinc scores 88 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, keys stay on devices, self-hosted coordination server and no connection logs by default. It does not meet independent audit.
Score 88 out of 100. How scoring works
Criteria
-
Yes
Open source Weight 3 of 3
Is all the source code needed to run the product public?
GPL-2.0 or later.
-
Yes
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The website loads no trackers, and there is no hosted service.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Free volunteer project with no ads or data sales.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
Yes
Keys stay on devices Weight 3 of 3
Is traffic encrypted between devices with private keys created on each device, so the coordination server and relays cannot read it?
Each node creates its own key pair. Nodes exchange public keys directly, with no coordination server.
-
Yes
Self-hosted coordination server Weight 2 of 3
Can the coordination or control server be self-hosted with open-source software?
There is no central server. Every node is configured and run by its owner.
-
Yes
No connection logs by default Weight 2 of 3
Are connection logs and client diagnostic logs kept off the vendor's servers unless a user or admin turns them on?
There is no vendor service. Logs stay on each node.