← Back to Blog

    Who Owns Your VPN? The 2026 Ownership Map

    The VPN market looks like dozens of rivals, but several major brands sit inside the same corporate groups. This assessment joins ownership evidence to the CLOUD Act, UK investigatory powers, EU e-evidence and the harder question: which entity can actually be ordered to produce which data?

    VPN AnalysisPublished · Updated · 20 min read· By TheVPNMatrix.com

    Evidence-based review per our 28-criteria methodology · affiliate disclosure

    Many consumer VPN storefronts connected to only three parent companies, with one parent also controlling review rankings
    Apparent competition can collapse into shared ownership. The conflict is sharper when the owner also controls the review surface.

    Quick answer

    The VPN market looks more diverse at brand level than it is at ownership level. One company, Kape Technologies, owns ExpressVPN, Private Internet Access, CyberGhost and Zenmate, and two of the review sites that rank them. NordVPN and Surfshark, routinely pitted against each other, belong to the same wider group. Ziff Davis owns IPVanish and media brands that review VPNs. Knowing who sits behind the logo will not tell you a VPN is bad. It tells you whose interests it ultimately answers to, which is the thing you are really trusting when you hand over every packet you send.

    The legal answer is narrower than “where is the VPN based?” The relevant state may reach the contracting operator, controller, parent or processor when that entity is covered by domestic or cross-border process and possesses or controls responsive data. The US CLOUD Act, UK Investigatory Powers Act and incoming EU e-Evidence rules all make corporate and data-control boundaries more important, not less. None proves that a VPN keeps browsing logs; that remains an architecture and evidence question.

    The market in one table

    Map the brands to their owners and the long "best VPN" list collapses into a short one.

    OwnerVPN brandsAlso ownsBased
    Kape Technologies (formerly Crossrider)ExpressVPN, Private Internet Access, CyberGhost, ZenmatevpnMentor, Wizcase (review sites)Private since May 2023; headquartered in London
    Cyberspace B.V. (Nord Security + Surfshark)NordVPN, SurfsharkIncogni; formerly AtlasVPNNetherlands / Lithuania
    Ziff Davis (ex-J2 Global)IPVanish, StrongVPN, Encrypt.mePCMag, IGN, Mashable (review media)United States
    McAfeeTunnelBearMcAfee Safe ConnectUnited States
    Point Wild (ex-Aura/Pango)Hotspot ShieldNoneUnited States
    Adguard Software LimitedAdGuard VPNAdGuard Ad Blocker, AdGuard DNSCyprus operator/controller; ultimate control unresolved
    Independently controlled in current evidenceProton VPN, Mullvad, IVPN, Windscribe, AirVPNMozilla VPN runs on MullvadSwitzerland, Sweden, others

    A VPN operator is technically able to observe sensitive connection metadata and, depending on implementation, traffic leaving its servers. One important fact about it is therefore not the logo or the launch-week discount, but who controls it, where they sit, and what else they answer to. Two brands in one group share corporate incentives, but their contracting entities, jurisdictions, infrastructure and data practices may still differ. The map must record those layers rather than infer one from another.

    How we built this map

    The table is a current research view, not a claim that every company in a corporate group shares one database or one legal entity. We match each brand to five separate layers: the consumer-facing name, the company named in the current terms or privacy policy, the immediate owner, the ultimate controlling group where that is disclosed, and the jurisdiction that can issue an order to the service actually handling the account. Those layers often point to different countries. A London headquarters, a Dutch holding company and a British Virgin Islands contracting entity are not interchangeable facts.

    We prefer current company filings, annual reports, acquisition announcements, terms, privacy policies and official ownership disclosures. Provider histories and press pages are useful but interested evidence. Trade reporting fills gaps only where the transaction record is inaccessible. Search snippets, copied ownership charts and an unexplained "based in" badge are discovery aids, not proof. Where the operating entity or ultimate controller remains unclear, the correct label is unresolved rather than independent.

    That last rule matters because absence of a visible parent is not evidence that no parent exists. Private companies can disclose little, brands can contract through regional subsidiaries, and acquisitions can move products without immediately rewriting every policy page. The map therefore records an as-of date and treats ownership confidence as a field that can change, not as permanent biography.

    Kape Technologies, four VPNs and two review sites

    Kape owns four consumer VPN brands. It bought CyberGhost in March 2017 for about $10 million, Zenmate soon after for around $5 million, Private Internet Access in 2019 for $127 million, and ExpressVPN in 2021 for $936 million (ProPrivacy; CyberInsider). One company now sits behind four of the brands that compete for the same buyer.

    Kape's own current company history confirms the CyberGhost, Private Internet Access, Webselenese and ExpressVPN acquisitions, and records that it delisted from the London Stock Exchange in May 2023 (Kape Technologies). That change matters because the group is no longer subject to the same public-market reporting visibility. It does not prove weaker privacy. It raises the importance of product-level audits and disclosures because fewer facts now arrive through public filings.

    The acquisitions are ordinary. The history is not. When Kape bought CyberGhost in 2017 it was still called Crossrider, a firm whose platform was used to bundle adware into software downloads. It rebranded to Kape Technologies in 2018 and dropped the ad-tech business (Wikipedia). People and companies can change, and the past does not automatically poison the present. It does set the bar for scrutiny. Routing your traffic through a company that built its first fortune on adware is a choice worth making with open eyes, rather than because an advert sounded sure of itself.

    The reviewer owns the reviewed

    In May 2021 Kape also bought Webselenese, the company behind vpnMentor and Wizcase, two of the most-read VPN review sites on the internet, with around 6.1 million monthly visitors between them (CyberInsider). So one company owns four VPNs and two of the sites that review VPNs. You can guess how it went. By late 2021, Kape's own brands held the top three places in vpnMentor's "best VPN" ranking, while rivals like NordVPN and Surfshark slid down it. Both sites still describe themselves as independent, and neither puts the word "Kape" anywhere a reader would easily see it.

    Kape is not alone in the shape of this. Ziff Davis owns IPVanish, StrongVPN and Encrypt.me, bought from StackPath in April 2019, and Ziff Davis also owns PCMag, IGN and Mashable, titles that review VPNs (TechRadar; MarketScreener). To its credit, PCMag leaves its parent's VPNs out of its main "best VPN" roundup, which is more daylight than Kape's sites offer. The structure is still the point. When one owner sits on both sides of the recommendation, a glowing review is an advert wearing a press badge, and the only defence a reader has is knowing the ownership before they read the verdict.

    This is, plainly, why this site publishes its formula and its ownership data instead of asking you to trust a number. A ranking you cannot audit is an opinion with confidence.

    NordVPN and Surfshark share a corporate group

    In February 2022, Nord Security and Surfshark, both Lithuanian, merged under a Netherlands-registered holding company, Cyberspace B.V. (Infosecurity Magazine; PR Newswire). Surfshark says the companies retained separate brands, apps, product development and infrastructure, and they are still compared against each other as rivals across the market. The defensible conclusion is that they share a corporate group, not that the two services are operationally identical. Nord's earlier acquisition of AtlasVPN had already folded a third brand into the same group before AtlasVPN was shut down in 2024 and its users were moved to NordVPN.

    None of this makes NordVPN or Surfshark a bad product. Both are audited, both perform well, and we rank them on that evidence. It does mean an article presenting them as two independent contenders is staging a match between two teams owned by the same club.

    Who is still independent

    The genuinely independent VPNs are a shorter list than the market implies, and it holds most of the names built by people who cared more about the privacy than the marketing. Proton VPN is operated by Proton AG in Switzerland, whose controlling shareholder is now the non-profit Proton Foundation (Proton). Mullvad is owned by Amagicom AB in Sweden, and runs the servers behind Mozilla VPN, so even Mozilla's option is Mullvad underneath. IVPN, Windscribe and AirVPN remain independently held. Riseup VPN is run by a non-profit activist collective and owned by no one as a business.

    AdGuard shows why operator is not the same as owner

    AdGuard VPN is a useful boundary case. Its current privacy policy identifies ADGUARD SOFTWARE LIMITED, registered in Limassol, Cyprus, as the data controller. Its about page says the same company develops AdGuard VPN, AdGuard Ad Blocker and AdGuard DNS, and that three founders head the business. Those are strong first-party facts about the operator, controller and product family. They do not name the founders, show shareholdings, or establish an ultimate beneficial owner (privacy policy; about page).

    The accurate label is therefore private operator identified; ultimate control unresolved in the current public primary record. Calling it independent simply because no parent is displayed would reverse the burden of proof. This distinction also affects how to read the AdGuard VPN review: the named Cyprus controller, the open-source TrustTunnel code, the Android app assessment and the unaudited no-logs claim are four separate evidence questions.

    Independence guarantees nothing on its own. A small independent with no audit is not safer than an audited brand under a large owner. What independence removes is a whole class of conflict, the pressure from a parent's other businesses and its shareholders, and that absence has value.

    What the CLOUD Act and similar laws actually do

    As of 26 July 2026, the main cross-border mechanisms do not create one global surveillance jurisdiction. They create several routes by which a properly authorised demand may reach a provider or records outside the issuing country. The scope and safeguards differ.

    PowerWhat it can doWhat it does not proveOwnership question
    US Stored Communications Act and CLOUD ActFor a covered electronic-communications or remote-computing provider subject to US process, 18 U.S.C. section 2713 reaches records in its possession, custody or control even when stored outside the US. Section 2703 sets different processes for content and non-content records.It does not put every foreign VPN under US law because it has US users or servers, and it does not itself require a provider to invent a permanent browsing log.Is a US group entity the operator, a covered provider, or in practical control of the requested records?
    US-UK CLOUD Act agreementSince October 2022, designated US and UK authorities can transmit qualifying orders directly to covered providers in the other country for serious-crime investigations, subject to the agreement's targeting and review conditions.It is not a bulk-data pipeline and does not make every subsidiary of a US or UK parent interchangeable.Is the recipient a covered provider in the US or UK, and is the target/order eligible under the agreement?
    UK Investigatory Powers ActDifferent parts govern communications-data acquisition, interception, equipment interference, technical-capability notices and targeted retention notices. Section 87 retention is notice-based and time-limited; the 2024 amendments strengthened overseas enforcement of retention notices.It does not show that every UK-linked VPN has received a notice or retains every user's traffic.Which company is a telecommunications operator for the relevant power, and what UK nexus and practical ability does it have?
    EU e-Evidence RegulationFrom 18 August 2026, Regulation (EU) 2023/1543 will create European Production and Preservation Orders addressed through designated establishments or representatives of providers offering covered services in the EU.It is not yet applicable on this article's as-of date, does not erase judicial safeguards, and does not turn GDPR into a ban on criminal-process disclosure.Which group entity or representative receives orders for EU users, including where the provider is established outside the EU?
    EU retention and access lawCJEU case law rejects general and indiscriminate traffic/location retention for ordinary crime while permitting defined categories such as targeted or expedited retention and strictly limited IP-address or civil-identity retention under safeguards.An EU address does not prove zero retention, and GDPR does not prevent a lawful, necessary disclosure.Which national law implements the permitted power, does it cover this service, and which data categories remain separate?
    Treaty and mutual-assistance routesMutual legal assistance and, where in force between the relevant states, the Budapest Convention's Second Additional Protocol provide routes for preservation, subscriber information and other electronic-evidence cooperation.They do not make every foreign request self-executing; domestic implementation, treaty participation and the requested data type still matter.Can authorities reach the operator or a processor through cooperation even without direct jurisdiction over the parent?

    A preservation demand is also not the same as a general retention mandate. US law, for example, can require specified records already in a provider's possession to be preserved temporarily while legal process is obtained. Canada likewise has preservation demands and production orders for computer and transmission data. Those tools can be significant, but they should not be paraphrased as a universal duty for every VPN to generate future browsing histories.

    Does ownership actually matter?

    Yes, though not the way a scare headline wants. Ownership is not destiny. A VPN owned by a public company can still run an audited no-logs policy, sit in a sound jurisdiction, and behave well, and several do. What ownership changes is incentives, and incentives are exactly what you are betting on when you trust a no-logs promise you cannot personally check.

    A public company answers to shareholders, which is a steady pressure to monetise that an independent does not carry in the same form. An owner of several VPN brands has reasons to share infrastructure and data handling across them. An owner of both the VPNs and the sites reviewing them has an obvious reason to flatter its own. None of these is proof of anything. Each is a reason to weight the facts you can verify, an external audit, the jurisdiction, the published evidence, above the ones you cannot, the brand and the advert. That is the whole skill.

    Ownership changes the questions, not the verdict

    A parent company can influence budget, retention policy, legal strategy, advertising, cross-selling and the choice of infrastructure suppliers. It may also leave the VPN operator, code, servers and privacy programme substantially separate. The first case creates a direct operational dependency; the second creates a governance risk. Treating both as the same would be as misleading as ignoring the parent altogether.

    This is why ownership sits beside, rather than above, the rest of our evidence matrix. The useful questions are concrete. Which entity invoices the subscriber? Which entity is the data controller? Who receives legal demands? Does the audit cover only the application or the production server estate? Are sister brands included in the same audit scope? Can account identifiers, support records or advertising audiences move across the group? Has the company published a transparency report since the acquisition? A logo cannot answer any of those questions. A current contract, audit and filing sometimes can.

    What to do with this

    Before you trust a VPN, find out who owns it, where they are, and what else they own. Then weight the audit and the jurisdiction over the logo. Our comparison tool carries the ownership data for every provider we grade next to the audit status and the score, so you see the company behind the brand in the same place you see the evidence, and the ranking is computed from that evidence rather than from who owns whom or who pays us.

    The industry would much rather you shopped by brand. Shop by owner, audit and jurisdiction instead, and most of the marketing stops working on you. That is the entire point of a map.

    A five-minute ownership check before you subscribe

    1. Read the current terms and privacy policy. Record the legal entity, address and governing law rather than the country displayed in an advert.
    2. Trace the parent and sister brands. Check the owner's site, filings and acquisition history, then note whether it also owns review or advertising businesses.
    3. Trace possession and control. Ask which operator, parent, processor or regional representative can access account, support, payment and connection records.
    4. Separate retention from preservation. Check what the provider routinely creates, what a targeted order could preserve, and whether local law could impose prospective retention on this type of operator.
    5. Open the latest audit. Confirm its date, scope, auditor, findings and remediation. An app audit does not prove server-side non-retention.
    6. Check the transparency record. Look for legal requests, incidents, ownership changes and whether the provider explains what it could and could not supply.
    7. Match the evidence to your threat model. A traveller avoiding hotel Wi-Fi, a torrent user, a journalist and an employee accessing a corporate network do not need the same owner, jurisdiction or operational proof.

    Our recommendation is not to reject every consolidated provider. It is to refuse the fiction that brand competition equals independent ownership, and to require stronger operational evidence when the same group controls several products or both the product and the recommendation surface. Use the legal tracker to inspect the country layer and read our country-by-country legal enforcement assessment, then return to the entity and data-flow evidence before drawing a provider conclusion. This article is general research, not legal advice.

    Compare providers after checking the owner

    If the evidence fits your threat model, our current partner options include Proton VPN, NordVPN and Surfshark. This is not a claim that any one jurisdiction makes them immune from legal process; compare their entity, audit and retained-data evidence before buying.

    Affiliate disclosure: We may earn a commission from those three links at no extra cost to you. Commission does not change ownership findings, Matrix scores or inclusion. We also cover non-partners where the evidence warrants it. Read our full disclosure and editorial policy.

    Open the evidence-led VPN comparison

    Frequently asked questions

    Who owns ExpressVPN?

    Kape Technologies, which also owns Private Internet Access, CyberGhost and Zenmate. Kape was formerly Crossrider, a company associated with adware, before it rebranded in 2018. It bought ExpressVPN in 2021 for $936 million.

    Is Surfshark owned by NordVPN?

    No. Surfshark is not owned by the NordVPN product. Surfshark says it and Nord Security merged under one holding company in 2022 while retaining separate brands and operations.

    Which company owns the most VPNs?

    Kape Technologies owns the most major consumer brands, with ExpressVPN, Private Internet Access, CyberGhost and Zenmate, and it also owns the review sites vpnMentor and Wizcase.

    Do any VPN review sites get owned by the VPNs they review?

    Yes. Kape owns vpnMentor and Wizcase while owning four VPNs, and Ziff Davis owns IPVanish alongside PCMag, IGN and Mashable. Always check who owns a review site before trusting its ranking.

    Which VPNs are still independent?

    Proton VPN (Proton AG, Switzerland) and Mullvad (Amagicom AB, Sweden) have unusually clear control records. IVPN, Windscribe and AirVPN are privately held, but 'independent' should be used only when the current operator and ultimate controller are supported by evidence. Mozilla VPN runs on Mullvad's servers.

    Who owns AdGuard VPN?

    AdGuard VPN's current privacy policy names ADGUARD SOFTWARE LIMITED in Cyprus as the data controller, and its about page says that company develops AdGuard VPN. The same page says three founders head the business, but it does not name them or disclose an ultimate beneficial owner. We therefore verify the operator and controller, not a fully resolved ownership chain.

    Does it matter who owns my VPN?

    It changes incentives, governance and sometimes which entity has possession, custody or control of responsive records. Ownership alone does not make a VPN unsafe, and a parent's country does not automatically govern every subsidiary. Weight the named operator, data controller, data actually retained, audit scope and applicable legal process over the brand.

    Does the US CLOUD Act apply to every VPN with US customers or servers?

    No. The CLOUD Act does not put every foreign VPN under US law merely because it has US customers or rents a US server. The key US rule applies to a covered electronic-communications or remote-computing provider that is subject to US process and has possession, custody or control of the requested records, wherever those records are stored. Provider status, corporate control and the data held all matter.

    Can a VPN avoid legal demands by being based in Switzerland, Panama or the British Virgin Islands?

    No jurisdiction makes a provider immune from lawful process. Domestic orders, mutual legal assistance, treaty mechanisms, direct cross-border evidence regimes and orders to another group entity may still matter. A well-designed no-logs service can reduce what exists to disclose, but the provider must prove the design, scope and operation rather than relying on a country badge.

    References

    1. [1]AdGuard VPN (2026) 'About us', AdGuard VPN. Available at: https://adguard-vpn.com/en/about-us.html (Accessed: 26 July 2026).
    2. [2]AdGuard VPN (2024) 'Privacy policy', AdGuard VPN. Available at: https://adguard-vpn.com/en/privacy.html (Accessed: 26 July 2026).
    3. [3]Council of Europe (2026) 'Second Additional Protocol to the Convention on Cybercrime', Council of Europe. Available at: https://www.coe.int/en/web/cybercrime/second-additional-protocol (Accessed: 26 July 2026).
    4. [4]Court of Justice of the European Union (2024) 'Case C-470/21: retention and access to IP-address and identity data', EUR-Lex. Available at: https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:62021CJ0470 (Accessed: 26 July 2026).
    5. [5]CyberInsider (2024) 'Kape Technologies owns ExpressVPN, CyberGhost, PIA and Zenmate, plus review sites', CyberInsider. Available at: https://cyberinsider.com/kape-technologies-owns-expressvpn-cyberghost-pia-zenmate-vpn-review-sites/ (Accessed: 16 June 2026).
    6. [6]CyberInsider (2024) 'The VPN review websites owned by VPNs (vpnMentor, Wizcase)', CyberInsider. Available at: https://cyberinsider.com/vpn-review-websites-owned-by-vpns/ (Accessed: 16 June 2026).
    7. [7]European Parliament and Council (2023) 'Regulation (EU) 2023/1543 on European Production and Preservation Orders for electronic evidence', Official Journal of the European Union. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R1543 (Accessed: 26 July 2026).
    8. [8]Government of Canada (2026) 'Criminal Code: preservation demands and production orders', Justice Laws Website. Available at: https://laws-lois.justice.gc.ca/eng/acts/C-46/ (Accessed: 26 July 2026).
    9. [9]Infosecurity Magazine (2022) 'Nord Security and Surfshark merge', Infosecurity Magazine. Available at: https://www.infosecurity-magazine.com/news/nord-security-and-surfshark-merge/ (Accessed: 16 June 2026).
    10. [10]Kape Technologies (2026) 'About Kape Technologies and company journey', Kape Technologies. Available at: https://www.kape.com/about-us/ (Accessed: 15 July 2026).
    11. [11]Kape Technologies (2026) 'Annual Report 2025', Kape Technologies. Available at: https://www.kapekh.org/files/report_file/423-en.pdf (Accessed: 24 July 2026).
    12. [12]MarketScreener (2019) 'J2 Global acquired IPVanish, StrongVPN and Encrypt.me from StackPath', MarketScreener. Available at: https://www.marketscreener.com/quote/stock/ZIFF-DAVIS-INC-9623089/news/J2-Global-Inc-acquired-IPVanish-StrongVPN-Encrypt-me-from-StackPath-LLC-34322612/ (Accessed: 16 June 2026).
    13. [13]Point Wild (2026) 'Our Story', Point Wild. Available at: https://www.pointwild.com/our-story/ (Accessed: 24 July 2026).
    14. [14]PR Newswire (2022) 'Nord Security and Surfshark join forces to strengthen positions in the cybersecurity industry', PR Newswire. Available at: https://www.prnewswire.com/news-releases/nord-security-and-surfshark-join-forces-to-strengthen-positions-in-the-cybersecurity-industry-301473286.html (Accessed: 16 June 2026).
    15. [15]ProPrivacy (2021) 'Kape Technologies acquires ExpressVPN for $936M', ProPrivacy. Available at: https://proprivacy.com/privacy-news/kape-technologies-aquires-expressvpn (Accessed: 16 June 2026).
    16. [16]Proton (2026) 'The Proton Foundation', Proton. Available at: https://proton.me/foundation (Accessed: 15 July 2026).
    17. [17]Surfshark (2026) 'About Surfshark', Surfshark. Available at: https://surfshark.com/about-us (Accessed: 24 July 2026).
    18. [18]TechRadar (2019) 'IGN owner J2 Global snaps up major VPN brands', TechRadar. Available at: https://www.techradar.com/news/ign-owner-j2-global-snaps-up-major-vpn-brands (Accessed: 16 June 2026).
    19. [19]UK Parliament (2024) 'Investigatory Powers (Amendment) Act 2024', legislation.gov.uk. Available at: https://www.legislation.gov.uk/ukpga/2024/9/contents (Accessed: 26 July 2026).
    20. [20]United States Department of Justice (2025) 'Cloud Act Agreement between the Governments of the U.S. and United Kingdom', Department of Justice. Available at: https://www.justice.gov/criminal/criminal-oia/cloud-act-agreement-between-governments-us-united-kingdom-great-britain-and-northern (Accessed: 26 July 2026).
    21. [21]United States House of Representatives (2026) '18 U.S.C. section 2713: Required preservation and disclosure of communications and records', United States Code. Available at: https://uscode.house.gov/view.xhtml?edition=prelim&req=granuleid%3AUSC-prelim-title18-section2713 (Accessed: 26 July 2026).
    22. [22]United States House of Representatives (2026) '18 U.S.C. section 2703: Required disclosure of customer communications or records', United States Code. Available at: https://uscode.house.gov/view.xhtml?edition=prelim&req=granuleid%3AUSC-prelim-title18-section2703 (Accessed: 26 July 2026).
    23. [23]Wikipedia (2026) 'Kape Technologies', Wikipedia. Available at: https://en.wikipedia.org/wiki/Kape_Technologies (Accessed: 16 June 2026).
    24. [24]Ziff Davis (2026) 'Annual Report 2025', US Securities and Exchange Commission. Available at: https://www.sec.gov/Archives/edgar/data/1084048/000108404826000021/annualreport2025.htm (Accessed: 24 July 2026).

    NordVPN

    Top-rated VPN with excellent features

    Get Deal

    Cookie Preferences

    We use essential storage and anonymous aggregate site metrics. Optional event analytics only run if you opt in.

    Learn more
    Questions or concerns?

    Contact us via X, Substack, or see our Cookie Policy for full details.