Privacy Ratings

Self-hosted network security ratings

Network-wide blocking, VPN and security tools to run at home or on a server.

10 self-hosted network security are rated against 4 public criteria, and 10 have enough evidence for a letter grade. Of the 3 with a known jurisdiction, 2 are based in a Five Eyes country, and 3 in the wider Fourteen Eyes.

Open-source self-hosted network security only · Criteria for this category · Suggest an addition · Markdown

10 shown
Self-hosted network security privacy ratings, sorted by pick and then by grade
Name Grade Score Data Jurisdiction Open sourceNo trackers or telemetryNo ads or data salesIndependent audit
VPN protocol and implementation built on modern cryptography such as Curve25519 and ChaCha20-Poly1305, included in the Linux kernel and available as apps for other platforms.
Grade A 90 100% – YesYesYesPartial
Self-hosted DNS proxy and ad blocker for local networks, with per-client blocklists, conditional forwarding, caching and support for encrypted upstream DNS such as DoH and DoT.
Grade B 80 100% – YesYesYesNo
Web content filtering proxy for Linux and BSD that blocks sites by phrase, URL, file type and MIME type, running as an explicit or transparent proxy or an ICAP server.
Grade B 80 100% – YesYesYesNo
Linux-based firewall distribution for routers and gateways, with a web interface, intrusion prevention, VPN support and add-on packages.
Grade B 80 100% Germany Fourteen Eyes YesYesYesNo
Self-hosted DNS sinkhole that blocks ads, trackers and malware domains for every device on a network, with a web interface for query logs and blocklist management.
Grade B 80 100% – YesYesYesNo
Set of shell scripts that install and manage a WireGuard or OpenVPN server on a Raspberry Pi or Debian-based server. The maintainers announced the end of the project and it is maintained only on a best-effort basis.
Grade B 80 100% – YesYesYesNo
Self-hosted authoritative and recursive DNS server with a web console, network-wide ad and tracker blocking, and support for DNS-over-TLS, DNS-over-HTTPS and DNS-over-QUIC.
Grade B 80 100% – YesYesYesNo
Open-source VPN daemon that uses TLS for key exchange and runs over UDP or TCP, widely used for self-hosted site-to-site and remote-access VPNs.
Grade C 60 100% United States Five Eyes YesNoYesPartial
Open-source network security monitor that passively analyzes traffic and writes detailed logs of connections and protocols, used for intrusion detection, incident response and threat hunting.
Grade D 50 100% – YesNoYesNo
FreeBSD-based firewall and router distribution from Netgate with a web interface, VPN and package system, available as the open-source Community Edition and the closed pfSense Plus.
Grade F 35 100% United States Five Eyes PartialNoYesNo

Questions

What is the most private option among self-hosted network security?

No pick has been made yet. The table above is sorted by score, based on public evidence.

How are self-hosted network security rated?

Each entry answers 4 questions: open source, no trackers or telemetry, no ads or data sales and independent audit. Answers need links to evidence. See the full criteria.

Does jurisdiction matter?

Jurisdiction decides which laws can compel a provider to hand over data. Each entry shows its country and whether it is in the Five, Nine or Fourteen Eyes. The data a provider can hand over depends mostly on what it stores and who holds the keys. Read about jurisdictions and the CLOUD Act.