Case file · VPN
ExpressVPN
Slick, audited, Bitcoin-friendly — but email-gated and Kape-owned.
The systematized overview
The bureau vs the internet.
6.9/10 · KYC-on-trigger (email identity)
Best-in-class engineering: RAM-only TrustedServer, an industry-leading 27 independent audits, an open-sourced Lightway core, and a 2017 Turkey server seizure that found no logs. But sign-up needs an email, anonymous payment is Bitcoin-only (no Monero), and two real trust questions stand out: Kape/Crossrider ownership and the CIO's Project Raven surveillance past. Capable and well-audited, not anonymous-by-design.
3 recurring praises · 3 recurring gripes
Most praised: widely praised for speed, apps, and the audited ram-only trustedserver design. Most cited downside: the project raven cio history is a recurring, serious trust objection.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Specs & jurisdiction.
- Jurisdiction
- British Virgin Islands
- Intel-sharing
- Outside 14 Eyes
- Logging
- No logs (audited)
- Anon. payment
- Bitcoin — email required; no Monero
- Protocols
- Lightway, OpenVPN, WireGuard
- Network
- ~105 countries
- Devices
- 8
- Kill switch
- Yes
- RAM-only
- Yes — TrustedServer
- Open source
- Partial (Lightway core, GPLv2)
- Audited
- Yes — 27 audits (Cure53/KPMG/PwC/F-Secure)
- Free tier
- No
The full read
Our analysis, in plain words.
ExpressVPN has the strongest engineering of the mainstream tier. Its TrustedServer infrastructure runs entirely in RAM, loading a read-only image at every boot and wiping all data on reboot, and it has been independently audited more than almost any competitor (27 audits by Cure53, KPMG, PwC, F-Secure and Praetorian, including repeated no-logs audits and PwC/Cure53 audits of TrustedServer). Its Lightway protocol core is open-sourced under GPLv2 and separately audited. In 2017 Turkish investigators seized one of its servers during the Andrei Karlov assassination probe and recovered no logs, a real-world validation of the no-logs claim.
It is level 2, not no-KYC: account creation requires an email and payment information. Anonymous payment is possible via Bitcoin but not Monero, so the privacy ceiling sits a little below the crypto-flexible competitors, and the email handle keeps it off the no-KYC floor.
The reason ExpressVPN scores lowest on trust among the mainstream three is not the technology but two documented, VPN-relevant concerns. It is owned by Kape Technologies (formerly Crossrider, a firm with an adware history), the same owner as PIA. More seriously and uniquely, its CIO Daniel Gericke was personally fined $335,000 under a US DOJ deferred-prosecution agreement for previously building zero-click surveillance for the UAE (Project Raven) that targeted activists and journalists. For a service whose entire value is protecting people from surveillance, a security chief with that history is exactly what the trust axis is meant to penalise.
The score, broken down
How the 6.9 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
62 × 50% = 3.1 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
72 × 30% = 2.2 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
84 × 20% = 1.7 of 10
Weighted total 6.9 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
The fine print, read for you
The clause they bury.
“Personal Data, such as an email address and payment information [that] you submit to us when you create or update your Account.”
What it meansSign-up requires an email (and payment info), which is what keeps ExpressVPN at level 2, not no-KYC. The bigger caveats are trust, not the clause: Kape/Crossrider ownership and the CIO's Project Raven past mean you are trusting the operator and its people, not just the (genuinely strong, RAM-only, heavily audited) architecture.
Read the source →A valid email plus payment information is required to create an account. Bitcoin payment (no Monero) can reduce billing linkage, but the email handle keeps this at level 2. No government ID is required.
Policy review — point by point
-
Email + payment required at sign-up
The privacy policy lists an email address and payment information among the personal data collected to create an account, the basis for the level-2 rating. ↗
-
Audited RAM-only no-logs posture
The no-logs policy and RAM-only TrustedServer are independently audited (KPMG no-logs; PwC and Cure53 on TrustedServer). ↗
-
No government-ID requirement
No government ID is required to sign up or pay; Bitcoin is accepted. ↗
British Virgin Islands, outside the 5/9/14 Eyes alliances and with no mandatory data-retention law, a genuinely strong jurisdiction. For ExpressVPN the trust risk lives in ownership and personnel (Kape, Project Raven), not jurisdiction, and the RAM-only architecture means a seized server holds nothing, as the 2017 Turkey seizure demonstrated.
We keep watching
Incident & policy timeline.
- Dec 2017
Turkey server seizure found no logs
Turkish investigators seized an ExpressVPN server during the Andrei Karlov assassination probe and recovered no logs, a real-world validation of the no-logs claim (comparable to PIA's court tests and Mullvad's raid).
source ↗ - Sep 2021
CIO fined for Project Raven; Kape acquisition
ExpressVPN CIO Daniel Gericke was personally fined $335,000 under a US DOJ deferred-prosecution deal for earlier building zero-click surveillance for the UAE (Project Raven) that targeted activists and journalists. In the same month Kape Technologies (formerly Crossrider, an adware-linked firm) acquired ExpressVPN for ~$936M. Both are standing, VPN-relevant trust concerns.
source ↗ - 2024
Windows split-tunneling DNS leak
For roughly 21 months (Windows app versions ~12.23.1-12.72.0), a bug in the split-tunneling feature sent DNS requests to ISPs outside the encrypted tunnel, affecting about 1% of Windows users. ExpressVPN disclosed it and pulled the feature. Self-reported and patched, but a long exposure window.
source ↗ - Jun 2025
RDP real-IP leak (patched)
Leftover debug code in some Windows builds (12.97-12.101.0.2-beta) routed Remote Desktop traffic (TCP port 3389) outside the tunnel, exposing users' real IP addresses. Found via ExpressVPN's bug-bounty programme and patched on 18 June 2025.
source ↗
The verdict
Where it stands.
Strengths
- RAM-only TrustedServer (audited)
- 27 independent audits
- Open-sourced Lightway core
- 2017 Turkey seizure found no logs
- BVI jurisdiction
Trade-offs
- Email required, not identity-free
- Bitcoin-only anonymous payment (no Monero)
- Kape/Crossrider ownership
- CIO's documented Project Raven surveillance history
Across the internet
What reviewers report.
Consistently praised
- Widely praised for speed, apps, and the audited RAM-only TrustedServer design
- The 23-audit record and open-sourced Lightway are cited as real transparency
- The 2017 Turkey seizure is cited as proof the no-logs claim holds
Recurring complaints
- The Project Raven CIO history is a recurring, serious trust objection
- Kape ownership (ex-Crossrider adware) distrusted
- Email required; higher price; Bitcoin-only anonymous payment
Sentiment is strongly positive on engineering and audits, and strongly negative on the Project Raven and Kape trust questions. No corroborated data-betrayal or freeze pattern exists; the 2017 seizure is consistent with the no-logs claim.
Keep exploring
Related lists & categories.
Ask the bureau
ExpressVPN, common questions.
Is ExpressVPN no-KYC?
No. It is heavily audited with strong RAM-only TrustedServer tech and accepts Bitcoin, but account creation requires an email and it carries documented ownership and personnel trust questions, so it is not identity-free. We rate it KYC-on-trigger (level 2).
Has ExpressVPN's no-logs claim been tested?
Yes. In 2017 Turkish investigators seized one of its servers and found no logs, and its no-logs policy and RAM-only infrastructure have been independently audited many times (27 audits by firms including KPMG, PwC and Cure53).
Why is ExpressVPN's trust score the lowest of the mainstream VPNs?
Not because of the tech, which is excellent, but because its CIO was fined for building surveillance tools for the UAE (Project Raven) and it is owned by Kape (formerly the adware-linked Crossrider). Those are real, VPN-relevant trust concerns.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.