# Self-hosted network security privacy ratings

Network-wide blocking, VPN and security tools to run at home or on a server.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [WireGuard](https://privacyratings.com/self-hosted-network-security/wireguard/) | A (90/100) | Unknown | VPN protocol and implementation built on modern cryptography such as Curve25519 and ChaCha20-Poly1305, included in the Linux kernel and available as apps for other platforms. |
| [Blocky](https://privacyratings.com/self-hosted-network-security/blocky/) | B (80/100) | Unknown | Self-hosted DNS proxy and ad blocker for local networks, with per-client blocklists, conditional forwarding, caching and support for encrypted upstream DNS such as DoH and DoT. |
| [E2Guardian](https://privacyratings.com/self-hosted-network-security/e2guardian/) | B (80/100) | Unknown | Web content filtering proxy for Linux and BSD that blocks sites by phrase, URL, file type and MIME type, running as an explicit or transparent proxy or an ICAP server. |
| [IPFire](https://privacyratings.com/self-hosted-network-security/ipfire/) | B (80/100) | Germany (Fourteen Eyes) | Linux-based firewall distribution for routers and gateways, with a web interface, intrusion prevention, VPN support and add-on packages. |
| [Pi-hole](https://privacyratings.com/self-hosted-network-security/pi-hole/) | B (80/100) | Unknown | Self-hosted DNS sinkhole that blocks ads, trackers and malware domains for every device on a network, with a web interface for query logs and blocklist management. |
| [PiVPN](https://privacyratings.com/self-hosted-network-security/pivpn/) | B (80/100) | Unknown | Set of shell scripts that install and manage a WireGuard or OpenVPN server on a Raspberry Pi or Debian-based server. The maintainers announced the end of the project and it is maintained only on a best-effort basis. |
| [Technitium DNS Server](https://privacyratings.com/self-hosted-network-security/technitium/) | B (80/100) | Unknown | Self-hosted authoritative and recursive DNS server with a web console, network-wide ad and tracker blocking, and support for DNS-over-TLS, DNS-over-HTTPS and DNS-over-QUIC. |
| [OpenVPN](https://privacyratings.com/self-hosted-network-security/openvpn/) | C (60/100) | United States (Five Eyes) | Open-source VPN daemon that uses TLS for key exchange and runs over UDP or TCP, widely used for self-hosted site-to-site and remote-access VPNs. |
| [Zeek](https://privacyratings.com/self-hosted-network-security/zeek/) | D (50/100) | Unknown | Open-source network security monitor that passively analyzes traffic and writes detailed logs of connections and protocols, used for intrusion detection, incident response and threat hunting. |
| [pfSense](https://privacyratings.com/self-hosted-network-security/pf-sense/) | F (35/100) | United States (Five Eyes) | FreeBSD-based firewall and router distribution from Netgate with a web interface, VPN and package system, available as the open-source Community Edition and the closed pfSense Plus. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?

Source: https://privacyratings.com/self-hosted-network-security/
