
Quick answer
The VPN market looks more diverse at brand level than it is at ownership level. One company, Kape Technologies, owns ExpressVPN, Private Internet Access, CyberGhost and Zenmate, and two of the review sites that rank them. NordVPN and Surfshark, routinely pitted against each other, belong to the same wider group. Ziff Davis owns IPVanish and media brands that review VPNs. Knowing who sits behind the logo will not tell you a VPN is bad. It tells you whose interests it ultimately answers to, which is the thing you are really trusting when you hand over every packet you send.
The legal answer is narrower than “where is the VPN based?” The relevant state may reach the contracting operator, controller, parent or processor when that entity is covered by domestic or cross-border process and possesses or controls responsive data. The US CLOUD Act, UK Investigatory Powers Act and incoming EU e-Evidence rules all make corporate and data-control boundaries more important, not less. None proves that a VPN keeps browsing logs; that remains an architecture and evidence question.
The market in one table
Map the brands to their owners and the long "best VPN" list collapses into a short one.
| Owner | VPN brands | Also owns | Based |
|---|---|---|---|
| Kape Technologies (formerly Crossrider) | ExpressVPN, Private Internet Access, CyberGhost, Zenmate | vpnMentor, Wizcase (review sites) | Private since May 2023; headquartered in London |
| Cyberspace B.V. (Nord Security + Surfshark) | NordVPN, Surfshark | Incogni; formerly AtlasVPN | Netherlands / Lithuania |
| Ziff Davis (ex-J2 Global) | IPVanish, StrongVPN, Encrypt.me | PCMag, IGN, Mashable (review media) | United States |
| McAfee | TunnelBear | McAfee Safe Connect | United States |
| Point Wild (ex-Aura/Pango) | Hotspot Shield | None | United States |
| Adguard Software Limited | AdGuard VPN | AdGuard Ad Blocker, AdGuard DNS | Cyprus operator/controller; ultimate control unresolved |
| Independently controlled in current evidence | Proton VPN, Mullvad, IVPN, Windscribe, AirVPN | Mozilla VPN runs on Mullvad | Switzerland, Sweden, others |
A VPN operator is technically able to observe sensitive connection metadata and, depending on implementation, traffic leaving its servers. One important fact about it is therefore not the logo or the launch-week discount, but who controls it, where they sit, and what else they answer to. Two brands in one group share corporate incentives, but their contracting entities, jurisdictions, infrastructure and data practices may still differ. The map must record those layers rather than infer one from another.
How we built this map
The table is a current research view, not a claim that every company in a corporate group shares one database or one legal entity. We match each brand to five separate layers: the consumer-facing name, the company named in the current terms or privacy policy, the immediate owner, the ultimate controlling group where that is disclosed, and the jurisdiction that can issue an order to the service actually handling the account. Those layers often point to different countries. A London headquarters, a Dutch holding company and a British Virgin Islands contracting entity are not interchangeable facts.
We prefer current company filings, annual reports, acquisition announcements, terms, privacy policies and official ownership disclosures. Provider histories and press pages are useful but interested evidence. Trade reporting fills gaps only where the transaction record is inaccessible. Search snippets, copied ownership charts and an unexplained "based in" badge are discovery aids, not proof. Where the operating entity or ultimate controller remains unclear, the correct label is unresolved rather than independent.
That last rule matters because absence of a visible parent is not evidence that no parent exists. Private companies can disclose little, brands can contract through regional subsidiaries, and acquisitions can move products without immediately rewriting every policy page. The map therefore records an as-of date and treats ownership confidence as a field that can change, not as permanent biography.
Kape Technologies, four VPNs and two review sites
Kape owns four consumer VPN brands. It bought CyberGhost in March 2017 for about $10 million, Zenmate soon after for around $5 million, Private Internet Access in 2019 for $127 million, and ExpressVPN in 2021 for $936 million (ProPrivacy; CyberInsider). One company now sits behind four of the brands that compete for the same buyer.
Kape's own current company history confirms the CyberGhost, Private Internet Access, Webselenese and ExpressVPN acquisitions, and records that it delisted from the London Stock Exchange in May 2023 (Kape Technologies). That change matters because the group is no longer subject to the same public-market reporting visibility. It does not prove weaker privacy. It raises the importance of product-level audits and disclosures because fewer facts now arrive through public filings.
The acquisitions are ordinary. The history is not. When Kape bought CyberGhost in 2017 it was still called Crossrider, a firm whose platform was used to bundle adware into software downloads. It rebranded to Kape Technologies in 2018 and dropped the ad-tech business (Wikipedia). People and companies can change, and the past does not automatically poison the present. It does set the bar for scrutiny. Routing your traffic through a company that built its first fortune on adware is a choice worth making with open eyes, rather than because an advert sounded sure of itself.
The reviewer owns the reviewed
In May 2021 Kape also bought Webselenese, the company behind vpnMentor and Wizcase, two of the most-read VPN review sites on the internet, with around 6.1 million monthly visitors between them (CyberInsider). So one company owns four VPNs and two of the sites that review VPNs. You can guess how it went. By late 2021, Kape's own brands held the top three places in vpnMentor's "best VPN" ranking, while rivals like NordVPN and Surfshark slid down it. Both sites still describe themselves as independent, and neither puts the word "Kape" anywhere a reader would easily see it.
Kape is not alone in the shape of this. Ziff Davis owns IPVanish, StrongVPN and Encrypt.me, bought from StackPath in April 2019, and Ziff Davis also owns PCMag, IGN and Mashable, titles that review VPNs (TechRadar; MarketScreener). To its credit, PCMag leaves its parent's VPNs out of its main "best VPN" roundup, which is more daylight than Kape's sites offer. The structure is still the point. When one owner sits on both sides of the recommendation, a glowing review is an advert wearing a press badge, and the only defence a reader has is knowing the ownership before they read the verdict.
This is, plainly, why this site publishes its formula and its ownership data instead of asking you to trust a number. A ranking you cannot audit is an opinion with confidence.
Who is still independent
The genuinely independent VPNs are a shorter list than the market implies, and it holds most of the names built by people who cared more about the privacy than the marketing. Proton VPN is operated by Proton AG in Switzerland, whose controlling shareholder is now the non-profit Proton Foundation (Proton). Mullvad is owned by Amagicom AB in Sweden, and runs the servers behind Mozilla VPN, so even Mozilla's option is Mullvad underneath. IVPN, Windscribe and AirVPN remain independently held. Riseup VPN is run by a non-profit activist collective and owned by no one as a business.
AdGuard shows why operator is not the same as owner
AdGuard VPN is a useful boundary case. Its current privacy policy identifies ADGUARD SOFTWARE LIMITED, registered in Limassol, Cyprus, as the data controller. Its about page says the same company develops AdGuard VPN, AdGuard Ad Blocker and AdGuard DNS, and that three founders head the business. Those are strong first-party facts about the operator, controller and product family. They do not name the founders, show shareholdings, or establish an ultimate beneficial owner (privacy policy; about page).
The accurate label is therefore private operator identified; ultimate control unresolved in the current public primary record. Calling it independent simply because no parent is displayed would reverse the burden of proof. This distinction also affects how to read the AdGuard VPN review: the named Cyprus controller, the open-source TrustTunnel code, the Android app assessment and the unaudited no-logs claim are four separate evidence questions.
Independence guarantees nothing on its own. A small independent with no audit is not safer than an audited brand under a large owner. What independence removes is a whole class of conflict, the pressure from a parent's other businesses and its shareholders, and that absence has value.
Why the owner's country is not the whole legal answer
A VPN's advertised jurisdiction is only one possible point of legal contact. A demand may be directed to the company that contracts with the user, the data controller named in the privacy policy, a parent that controls the records, an infrastructure or payment provider, or a designated legal representative. The decisive questions are which entity is covered by the power, which entity possesses or controls the requested data, and what data the service created in the first place.
This is where our ownership evidence tracker and legal tracker map meet. The ownership tracker answers who operates, controls and sits beside the brand. The legal tracker asks what retention, preservation, disclosure and interception powers exist in the relevant country. Neither can answer the reader's risk question alone. A map of laws without the correct entity can attach the right rule to the wrong company; an ownership chart without legal process can mistake corporate geography for legal immunity.
The six-layer legal-reach test
- Contracting operator: the entity named in the terms and usually the first recipient of an account-related demand.
- Data controller: the entity deciding why and how personal data is processed. It may differ from the operator or payment company.
- Parent and control: the company that can direct policy or has possession, custody or control of group records. Ownership alone does not prove record-level control.
- Infrastructure and processors: hosting, analytics, support, app-store and payment providers may hold their own subscriber or operational records under other laws.
- Service and user nexus: some powers turn on where the provider offers service, where the target is located, or whether an overseas operator has a sufficient domestic connection.
- Data actually held: a disclosure order can reach an existing billing record, support ticket or connection log; it cannot reveal a browsing history that was genuinely never created. Preservation and prospective retention are separate powers.
The strongest case against jurisdiction panic is important. Lawful orders are not proof that a provider is secretly logging everyone, and the major regimes below contain thresholds, scope limits, review mechanisms and routes to challenge at least some orders. A Swiss, Swedish or British Virgin Islands company is not automatically safe; a US or UK company is not automatically unsafe. Architecture, minimisation, audit scope and a provider's record of contesting overbroad demands can matter more than the flag.
What the CLOUD Act and similar laws actually do
As of 26 July 2026, the main cross-border mechanisms do not create one global surveillance jurisdiction. They create several routes by which a properly authorised demand may reach a provider or records outside the issuing country. The scope and safeguards differ.
| Power | What it can do | What it does not prove | Ownership question |
|---|---|---|---|
| US Stored Communications Act and CLOUD Act | For a covered electronic-communications or remote-computing provider subject to US process, 18 U.S.C. section 2713 reaches records in its possession, custody or control even when stored outside the US. Section 2703 sets different processes for content and non-content records. | It does not put every foreign VPN under US law because it has US users or servers, and it does not itself require a provider to invent a permanent browsing log. | Is a US group entity the operator, a covered provider, or in practical control of the requested records? |
| US-UK CLOUD Act agreement | Since October 2022, designated US and UK authorities can transmit qualifying orders directly to covered providers in the other country for serious-crime investigations, subject to the agreement's targeting and review conditions. | It is not a bulk-data pipeline and does not make every subsidiary of a US or UK parent interchangeable. | Is the recipient a covered provider in the US or UK, and is the target/order eligible under the agreement? |
| UK Investigatory Powers Act | Different parts govern communications-data acquisition, interception, equipment interference, technical-capability notices and targeted retention notices. Section 87 retention is notice-based and time-limited; the 2024 amendments strengthened overseas enforcement of retention notices. | It does not show that every UK-linked VPN has received a notice or retains every user's traffic. | Which company is a telecommunications operator for the relevant power, and what UK nexus and practical ability does it have? |
| EU e-Evidence Regulation | From 18 August 2026, Regulation (EU) 2023/1543 will create European Production and Preservation Orders addressed through designated establishments or representatives of providers offering covered services in the EU. | It is not yet applicable on this article's as-of date, does not erase judicial safeguards, and does not turn GDPR into a ban on criminal-process disclosure. | Which group entity or representative receives orders for EU users, including where the provider is established outside the EU? |
| EU retention and access law | CJEU case law rejects general and indiscriminate traffic/location retention for ordinary crime while permitting defined categories such as targeted or expedited retention and strictly limited IP-address or civil-identity retention under safeguards. | An EU address does not prove zero retention, and GDPR does not prevent a lawful, necessary disclosure. | Which national law implements the permitted power, does it cover this service, and which data categories remain separate? |
| Treaty and mutual-assistance routes | Mutual legal assistance and, where in force between the relevant states, the Budapest Convention's Second Additional Protocol provide routes for preservation, subscriber information and other electronic-evidence cooperation. | They do not make every foreign request self-executing; domestic implementation, treaty participation and the requested data type still matter. | Can authorities reach the operator or a processor through cooperation even without direct jurisdiction over the parent? |
A preservation demand is also not the same as a general retention mandate. US law, for example, can require specified records already in a provider's possession to be preserved temporarily while legal process is obtained. Canada likewise has preservation demands and production orders for computer and transmission data. Those tools can be significant, but they should not be paraphrased as a universal duty for every VPN to generate future browsing histories.
Ownership and legal exposure, group by group
This table is an assessment of legal exposure, not a claim that an order has been served. It joins the current ownership record to the legal routes that deserve provider-specific testing. Where the contracting entity, record control or ultimate owner is unresolved, the conclusion stays unresolved.
| Group or provider | Verified ownership and operating layers | Legal-reach assessment | Evidence still required |
|---|---|---|---|
| Kape Technologies ExpressVPN, PIA, CyberGhost, Zenmate | Private UK-headquartered parent; product entities and advertised jurisdictions differ, including US-linked PIA, Romanian CyberGhost and BVI-linked ExpressVPN. | No single flag governs the group. A US operating entity may face US process for records it controls; a UK group entity may face UK powers where the statutory operator and nexus tests are met; EU product entities remain subject to applicable national and EU process. | Publish an entity-by-entity controller/operator chart, record-control boundaries, processor list and legal-request statistics after acquisition. |
| Nord Security / Cyberspace B.V. NordVPN, Surfshark | Dutch holding structure, Lithuanian operational presence and different product-facing jurisdictions; the brands say products and infrastructure remain separate. | The shared parent does not prove a shared database. EU establishment and service offering make the EU's national procedures and incoming e-Evidence regime relevant, while the product contract and actual control of records determine the recipient. | Show which entity contracts with each region, whether group functions can access account or support data, and whether audits test separation between brands. |
| Ziff Davis IPVanish and media brands | US public parent and US VPN business, alongside publications that review security products. | This is the clearest US ownership-and-operation nexus in the major-brand set. US production and preservation powers are directly relevant to data held or controlled by the covered provider; the media conflict is separate from legal exposure. | Current transparency reporting, exact retention inventory and an audit showing whether parent or sister systems can access VPN account and operational records. |
| Point Wild Hotspot Shield and related VPN products | US parent with multiple security and VPN products. | US process is relevant where the operator is a covered provider and controls responsive data. Multiple brands raise a separate question about shared identity, advertising, support and analytics systems. | Product-level controller map, cross-brand data-flow disclosure, current infrastructure audit and legal-request report. |
| McAfee / TunnelBear | US parent; TunnelBear service has a Canadian operating history. | Canadian preservation and production powers may apply to records held by the Canadian operator; US reach depends on the role and control of the US parent rather than the acquisition fact alone. | Current contracting/controller entities, parent-access boundaries and transparency statistics split by receiving jurisdiction. |
| Proton VPN | Swiss operator controlled through the non-profit Proton Foundation. | Swiss status removes neither domestic process nor international cooperation. It does reduce the basis for treating a US or EU parent as the record controller because no such parent is evidenced. | Keep publishing service-specific legal-request outcomes and prove which VPN metadata never exists, separately from other Proton account data. |
| Mullvad | Swedish independent operator; also supplies infrastructure for Mozilla VPN. | Swedish/EU rules and the service's operator classification matter. Mullvad's numbered-account design can reduce subscriber data, but Mozilla's customer relationship creates a different account-data path. | Keep the two services' controllers and records separate in analysis; verify current Swedish classification, retention scope and legal-request outcomes. |
| AdGuard VPN | Cyprus operator and controller verified; ultimate beneficial control remains unresolved. | Cyprus and EU process applies to the named controller, including the EU e-Evidence framework from 18 August 2026 where its service scope is met. An unresolved parent does not remove that known legal contact. | Ultimate-owner filing, regional contracting entities, processor and server-control map, legal-request statistics and a server-side no-logs audit. |
These are exposure routes, not provider verdicts. The evidential burden is practical: a provider should show its legal entities, regional contracts, data-flow diagram, list of processors, retention schedule, access controls, audit scope and aggregate request statistics. A warrant can only disclose what exists, but readers should not have to take the provider's word for what exists.
Does ownership actually matter?
Yes, though not the way a scare headline wants. Ownership is not destiny. A VPN owned by a public company can still run an audited no-logs policy, sit in a sound jurisdiction, and behave well, and several do. What ownership changes is incentives, and incentives are exactly what you are betting on when you trust a no-logs promise you cannot personally check.
A public company answers to shareholders, which is a steady pressure to monetise that an independent does not carry in the same form. An owner of several VPN brands has reasons to share infrastructure and data handling across them. An owner of both the VPNs and the sites reviewing them has an obvious reason to flatter its own. None of these is proof of anything. Each is a reason to weight the facts you can verify, an external audit, the jurisdiction, the published evidence, above the ones you cannot, the brand and the advert. That is the whole skill.
Ownership changes the questions, not the verdict
A parent company can influence budget, retention policy, legal strategy, advertising, cross-selling and the choice of infrastructure suppliers. It may also leave the VPN operator, code, servers and privacy programme substantially separate. The first case creates a direct operational dependency; the second creates a governance risk. Treating both as the same would be as misleading as ignoring the parent altogether.
This is why ownership sits beside, rather than above, the rest of our evidence matrix. The useful questions are concrete. Which entity invoices the subscriber? Which entity is the data controller? Who receives legal demands? Does the audit cover only the application or the production server estate? Are sister brands included in the same audit scope? Can account identifiers, support records or advertising audiences move across the group? Has the company published a transparency report since the acquisition? A logo cannot answer any of those questions. A current contract, audit and filing sometimes can.
What to do with this
Before you trust a VPN, find out who owns it, where they are, and what else they own. Then weight the audit and the jurisdiction over the logo. Our comparison tool carries the ownership data for every provider we grade next to the audit status and the score, so you see the company behind the brand in the same place you see the evidence, and the ranking is computed from that evidence rather than from who owns whom or who pays us.
The industry would much rather you shopped by brand. Shop by owner, audit and jurisdiction instead, and most of the marketing stops working on you. That is the entire point of a map.
A five-minute ownership check before you subscribe
- Read the current terms and privacy policy. Record the legal entity, address and governing law rather than the country displayed in an advert.
- Trace the parent and sister brands. Check the owner's site, filings and acquisition history, then note whether it also owns review or advertising businesses.
- Trace possession and control. Ask which operator, parent, processor or regional representative can access account, support, payment and connection records.
- Separate retention from preservation. Check what the provider routinely creates, what a targeted order could preserve, and whether local law could impose prospective retention on this type of operator.
- Open the latest audit. Confirm its date, scope, auditor, findings and remediation. An app audit does not prove server-side non-retention.
- Check the transparency record. Look for legal requests, incidents, ownership changes and whether the provider explains what it could and could not supply.
- Match the evidence to your threat model. A traveller avoiding hotel Wi-Fi, a torrent user, a journalist and an employee accessing a corporate network do not need the same owner, jurisdiction or operational proof.
Our recommendation is not to reject every consolidated provider. It is to refuse the fiction that brand competition equals independent ownership, and to require stronger operational evidence when the same group controls several products or both the product and the recommendation surface. Use the legal tracker to inspect the country layer and read our country-by-country legal enforcement assessment, then return to the entity and data-flow evidence before drawing a provider conclusion. This article is general research, not legal advice.
Compare providers after checking the owner
If the evidence fits your threat model, our current partner options include Proton VPN, NordVPN and Surfshark. This is not a claim that any one jurisdiction makes them immune from legal process; compare their entity, audit and retained-data evidence before buying.
Affiliate disclosure: We may earn a commission from those three links at no extra cost to you. Commission does not change ownership findings, Matrix scores or inclusion. We also cover non-partners where the evidence warrants it. Read our full disclosure and editorial policy.
Frequently asked questions
Who owns ExpressVPN?
Kape Technologies, which also owns Private Internet Access, CyberGhost and Zenmate. Kape was formerly Crossrider, a company associated with adware, before it rebranded in 2018. It bought ExpressVPN in 2021 for $936 million.
Is Surfshark owned by NordVPN?
No. Surfshark is not owned by the NordVPN product. Surfshark says it and Nord Security merged under one holding company in 2022 while retaining separate brands and operations.
Which company owns the most VPNs?
Kape Technologies owns the most major consumer brands, with ExpressVPN, Private Internet Access, CyberGhost and Zenmate, and it also owns the review sites vpnMentor and Wizcase.
Do any VPN review sites get owned by the VPNs they review?
Yes. Kape owns vpnMentor and Wizcase while owning four VPNs, and Ziff Davis owns IPVanish alongside PCMag, IGN and Mashable. Always check who owns a review site before trusting its ranking.
Which VPNs are still independent?
Proton VPN (Proton AG, Switzerland) and Mullvad (Amagicom AB, Sweden) have unusually clear control records. IVPN, Windscribe and AirVPN are privately held, but 'independent' should be used only when the current operator and ultimate controller are supported by evidence. Mozilla VPN runs on Mullvad's servers.
Who owns AdGuard VPN?
AdGuard VPN's current privacy policy names ADGUARD SOFTWARE LIMITED in Cyprus as the data controller, and its about page says that company develops AdGuard VPN. The same page says three founders head the business, but it does not name them or disclose an ultimate beneficial owner. We therefore verify the operator and controller, not a fully resolved ownership chain.
Does it matter who owns my VPN?
It changes incentives, governance and sometimes which entity has possession, custody or control of responsive records. Ownership alone does not make a VPN unsafe, and a parent's country does not automatically govern every subsidiary. Weight the named operator, data controller, data actually retained, audit scope and applicable legal process over the brand.
Does the US CLOUD Act apply to every VPN with US customers or servers?
No. The CLOUD Act does not put every foreign VPN under US law merely because it has US customers or rents a US server. The key US rule applies to a covered electronic-communications or remote-computing provider that is subject to US process and has possession, custody or control of the requested records, wherever those records are stored. Provider status, corporate control and the data held all matter.
Can a VPN avoid legal demands by being based in Switzerland, Panama or the British Virgin Islands?
No jurisdiction makes a provider immune from lawful process. Domestic orders, mutual legal assistance, treaty mechanisms, direct cross-border evidence regimes and orders to another group entity may still matter. A well-designed no-logs service can reduce what exists to disclose, but the provider must prove the design, scope and operation rather than relying on a country badge.
References
- [1]AdGuard VPN (2026) 'About us', AdGuard VPN. Available at: https://adguard-vpn.com/en/about-us.html (Accessed: 26 July 2026).
- [2]AdGuard VPN (2024) 'Privacy policy', AdGuard VPN. Available at: https://adguard-vpn.com/en/privacy.html (Accessed: 26 July 2026).
- [3]Council of Europe (2026) 'Second Additional Protocol to the Convention on Cybercrime', Council of Europe. Available at: https://www.coe.int/en/web/cybercrime/second-additional-protocol (Accessed: 26 July 2026).
- [4]Court of Justice of the European Union (2024) 'Case C-470/21: retention and access to IP-address and identity data', EUR-Lex. Available at: https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:62021CJ0470 (Accessed: 26 July 2026).
- [5]CyberInsider (2024) 'Kape Technologies owns ExpressVPN, CyberGhost, PIA and Zenmate, plus review sites', CyberInsider. Available at: https://cyberinsider.com/kape-technologies-owns-expressvpn-cyberghost-pia-zenmate-vpn-review-sites/ (Accessed: 16 June 2026).
- [6]CyberInsider (2024) 'The VPN review websites owned by VPNs (vpnMentor, Wizcase)', CyberInsider. Available at: https://cyberinsider.com/vpn-review-websites-owned-by-vpns/ (Accessed: 16 June 2026).
- [7]European Parliament and Council (2023) 'Regulation (EU) 2023/1543 on European Production and Preservation Orders for electronic evidence', Official Journal of the European Union. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R1543 (Accessed: 26 July 2026).
- [8]Government of Canada (2026) 'Criminal Code: preservation demands and production orders', Justice Laws Website. Available at: https://laws-lois.justice.gc.ca/eng/acts/C-46/ (Accessed: 26 July 2026).
- [9]Infosecurity Magazine (2022) 'Nord Security and Surfshark merge', Infosecurity Magazine. Available at: https://www.infosecurity-magazine.com/news/nord-security-and-surfshark-merge/ (Accessed: 16 June 2026).
- [10]Kape Technologies (2026) 'About Kape Technologies and company journey', Kape Technologies. Available at: https://www.kape.com/about-us/ (Accessed: 15 July 2026).
- [11]Kape Technologies (2026) 'Annual Report 2025', Kape Technologies. Available at: https://www.kapekh.org/files/report_file/423-en.pdf (Accessed: 24 July 2026).
- [12]MarketScreener (2019) 'J2 Global acquired IPVanish, StrongVPN and Encrypt.me from StackPath', MarketScreener. Available at: https://www.marketscreener.com/quote/stock/ZIFF-DAVIS-INC-9623089/news/J2-Global-Inc-acquired-IPVanish-StrongVPN-Encrypt-me-from-StackPath-LLC-34322612/ (Accessed: 16 June 2026).
- [13]Point Wild (2026) 'Our Story', Point Wild. Available at: https://www.pointwild.com/our-story/ (Accessed: 24 July 2026).
- [14]PR Newswire (2022) 'Nord Security and Surfshark join forces to strengthen positions in the cybersecurity industry', PR Newswire. Available at: https://www.prnewswire.com/news-releases/nord-security-and-surfshark-join-forces-to-strengthen-positions-in-the-cybersecurity-industry-301473286.html (Accessed: 16 June 2026).
- [15]ProPrivacy (2021) 'Kape Technologies acquires ExpressVPN for $936M', ProPrivacy. Available at: https://proprivacy.com/privacy-news/kape-technologies-aquires-expressvpn (Accessed: 16 June 2026).
- [16]Proton (2026) 'The Proton Foundation', Proton. Available at: https://proton.me/foundation (Accessed: 15 July 2026).
- [17]Surfshark (2026) 'About Surfshark', Surfshark. Available at: https://surfshark.com/about-us (Accessed: 24 July 2026).
- [18]TechRadar (2019) 'IGN owner J2 Global snaps up major VPN brands', TechRadar. Available at: https://www.techradar.com/news/ign-owner-j2-global-snaps-up-major-vpn-brands (Accessed: 16 June 2026).
- [19]UK Parliament (2024) 'Investigatory Powers (Amendment) Act 2024', legislation.gov.uk. Available at: https://www.legislation.gov.uk/ukpga/2024/9/contents (Accessed: 26 July 2026).
- [20]United States Department of Justice (2025) 'Cloud Act Agreement between the Governments of the U.S. and United Kingdom', Department of Justice. Available at: https://www.justice.gov/criminal/criminal-oia/cloud-act-agreement-between-governments-us-united-kingdom-great-britain-and-northern (Accessed: 26 July 2026).
- [21]United States House of Representatives (2026) '18 U.S.C. section 2713: Required preservation and disclosure of communications and records', United States Code. Available at: https://uscode.house.gov/view.xhtml?edition=prelim&req=granuleid%3AUSC-prelim-title18-section2713 (Accessed: 26 July 2026).
- [22]United States House of Representatives (2026) '18 U.S.C. section 2703: Required disclosure of customer communications or records', United States Code. Available at: https://uscode.house.gov/view.xhtml?edition=prelim&req=granuleid%3AUSC-prelim-title18-section2703 (Accessed: 26 July 2026).
- [23]Wikipedia (2026) 'Kape Technologies', Wikipedia. Available at: https://en.wikipedia.org/wiki/Kape_Technologies (Accessed: 16 June 2026).
- [24]Ziff Davis (2026) 'Annual Report 2025', US Securities and Exchange Commission. Available at: https://www.sec.gov/Archives/edgar/data/1084048/000108404826000021/annualreport2025.htm (Accessed: 24 July 2026).
