noKYCme

Case file · VPN

ExpressVPN

Slick, audited, Bitcoin-friendly — but email-gated and Kape-owned.

KYC-on-trigger · Level 2
Based
British Virgin Islands
Price
From ~$5–13 / month
Reviewed
2026-07-21
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

6.9/10 · KYC-on-trigger (email identity)

Best-in-class engineering: RAM-only TrustedServer, an industry-leading 27 independent audits, an open-sourced Lightway core, and a 2017 Turkey server seizure that found no logs. But sign-up needs an email, anonymous payment is Bitcoin-only (no Monero), and two real trust questions stand out: Kape/Crossrider ownership and the CIO's Project Raven surveillance past. Capable and well-audited, not anonymous-by-design.

What the internet says

3 recurring praises · 3 recurring gripes

Most praised: widely praised for speed, apps, and the audited ram-only trustedserver design. Most cited downside: the project raven cio history is a recurring, serious trust objection.

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Specs & jurisdiction.

Jurisdiction
British Virgin Islands
Intel-sharing
Outside 14 Eyes
Logging
No logs (audited)
Anon. payment
Bitcoin — email required; no Monero
Protocols
Lightway, OpenVPN, WireGuard
Network
~105 countries
Devices
8
Kill switch
Yes
RAM-only
Yes — TrustedServer
Open source
Partial (Lightway core, GPLv2)
Audited
Yes — 27 audits (Cure53/KPMG/PwC/F-Secure)
Free tier
No

The full read

Our analysis, in plain words.

ExpressVPN has the strongest engineering of the mainstream tier. Its TrustedServer infrastructure runs entirely in RAM, loading a read-only image at every boot and wiping all data on reboot, and it has been independently audited more than almost any competitor (27 audits by Cure53, KPMG, PwC, F-Secure and Praetorian, including repeated no-logs audits and PwC/Cure53 audits of TrustedServer). Its Lightway protocol core is open-sourced under GPLv2 and separately audited. In 2017 Turkish investigators seized one of its servers during the Andrei Karlov assassination probe and recovered no logs, a real-world validation of the no-logs claim.

It is level 2, not no-KYC: account creation requires an email and payment information. Anonymous payment is possible via Bitcoin but not Monero, so the privacy ceiling sits a little below the crypto-flexible competitors, and the email handle keeps it off the no-KYC floor.

The reason ExpressVPN scores lowest on trust among the mainstream three is not the technology but two documented, VPN-relevant concerns. It is owned by Kape Technologies (formerly Crossrider, a firm with an adware history), the same owner as PIA. More seriously and uniquely, its CIO Daniel Gericke was personally fined $335,000 under a US DOJ deferred-prosecution agreement for previously building zero-click surveillance for the UAE (Project Raven) that targeted activists and journalists. For a service whose entire value is protecting people from surveillance, a security chief with that history is exactly what the trust axis is meant to penalise.


The score, broken down

How the 6.9 is built.

Privacy 3.1Trust 2.2Reliability 1.7 Headroom 3.1

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

62/100

62 × 50% = 3.1 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

72/100

72 × 30% = 2.2 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

84/100

84 × 20% = 1.7 of 10

Weighted total 6.9 / 10 · no reliability rule triggered, so the score stands. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +4Accepts Bitcoin (no Monero)
  • +4BVI jurisdiction, outside 5/9/14 Eyes (no data-retention law)
  • +4Audited no-logging policy (KPMG)

Trust

  • +5RAM-only "TrustedServer" (audited by PwC and Cure53)
  • +527 independent audits (Cure53, KPMG, PwC, F-Secure, Praetorian)
  • +4Lightway protocol core open-sourced (GPLv2) and audited

The fine print, read for you

The clause they bury.

Verbatim — the catch
“Personal Data, such as an email address and payment information [that] you submit to us when you create or update your Account.”

What it meansSign-up requires an email (and payment info), which is what keeps ExpressVPN at level 2, not no-KYC. The bigger caveats are trust, not the clause: Kape/Crossrider ownership and the CIO's Project Raven past mean you are trusting the operator and its people, not just the (genuinely strong, RAM-only, heavily audited) architecture.

Read the source →
KYC trigger threshold

A valid email plus payment information is required to create an account. Bitcoin payment (no Monero) can reduce billing linkage, but the email handle keeps this at level 2. No government ID is required.

Policy review — point by point

  • Email + payment required at sign-up

    The privacy policy lists an email address and payment information among the personal data collected to create an account, the basis for the level-2 rating.

  • Audited RAM-only no-logs posture

    The no-logs policy and RAM-only TrustedServer are independently audited (KPMG no-logs; PwC and Cure53 on TrustedServer).

  • No government-ID requirement

    No government ID is required to sign up or pay; Bitcoin is accepted.

Jurisdiction analysis

British Virgin Islands, outside the 5/9/14 Eyes alliances and with no mandatory data-retention law, a genuinely strong jurisdiction. For ExpressVPN the trust risk lives in ownership and personnel (Kape, Project Raven), not jurisdiction, and the RAM-only architecture means a seized server holds nothing, as the 2017 Turkey seizure demonstrated.


We keep watching

Incident & policy timeline.

  1. Dec 2017

    Turkey server seizure found no logs

    Turkish investigators seized an ExpressVPN server during the Andrei Karlov assassination probe and recovered no logs, a real-world validation of the no-logs claim (comparable to PIA's court tests and Mullvad's raid).

    source ↗
  2. Sep 2021

    CIO fined for Project Raven; Kape acquisition

    ExpressVPN CIO Daniel Gericke was personally fined $335,000 under a US DOJ deferred-prosecution deal for earlier building zero-click surveillance for the UAE (Project Raven) that targeted activists and journalists. In the same month Kape Technologies (formerly Crossrider, an adware-linked firm) acquired ExpressVPN for ~$936M. Both are standing, VPN-relevant trust concerns.

    source ↗
  3. 2024

    Windows split-tunneling DNS leak

    For roughly 21 months (Windows app versions ~12.23.1-12.72.0), a bug in the split-tunneling feature sent DNS requests to ISPs outside the encrypted tunnel, affecting about 1% of Windows users. ExpressVPN disclosed it and pulled the feature. Self-reported and patched, but a long exposure window.

    source ↗
  4. Jun 2025

    RDP real-IP leak (patched)

    Leftover debug code in some Windows builds (12.97-12.101.0.2-beta) routed Remote Desktop traffic (TCP port 3389) outside the tunnel, exposing users' real IP addresses. Found via ExpressVPN's bug-bounty programme and patched on 18 June 2025.

    source ↗

The verdict

Where it stands.

Strengths

  • RAM-only TrustedServer (audited)
  • 27 independent audits
  • Open-sourced Lightway core
  • 2017 Turkey seizure found no logs
  • BVI jurisdiction

Trade-offs

  • Email required, not identity-free
  • Bitcoin-only anonymous payment (no Monero)
  • Kape/Crossrider ownership
  • CIO's documented Project Raven surveillance history
Visit ExpressVPN No affiliate relationship. We link to the official site directly.

Across the internet

What reviewers report.

Consistently praised

  • Widely praised for speed, apps, and the audited RAM-only TrustedServer design
  • The 23-audit record and open-sourced Lightway are cited as real transparency
  • The 2017 Turkey seizure is cited as proof the no-logs claim holds

Recurring complaints

  • The Project Raven CIO history is a recurring, serious trust objection
  • Kape ownership (ex-Crossrider adware) distrusted
  • Email required; higher price; Bitcoin-only anonymous payment

Sentiment is strongly positive on engineering and audits, and strongly negative on the Project Raven and Kape trust questions. No corroborated data-betrayal or freeze pattern exists; the 2017 seizure is consistent with the no-logs claim.


Keep exploring

Related lists & categories.


Ask the bureau

ExpressVPN, common questions.

Is ExpressVPN no-KYC?

No. It is heavily audited with strong RAM-only TrustedServer tech and accepts Bitcoin, but account creation requires an email and it carries documented ownership and personnel trust questions, so it is not identity-free. We rate it KYC-on-trigger (level 2).

Has ExpressVPN's no-logs claim been tested?

Yes. In 2017 Turkish investigators seized one of its servers and found no logs, and its no-logs policy and RAM-only infrastructure have been independently audited many times (27 audits by firms including KPMG, PwC and Cure53).

Why is ExpressVPN's trust score the lowest of the mainstream VPNs?

Not because of the tech, which is excellent, but because its CIO was fined for building surveillance tools for the UAE (Project Raven) and it is owned by Kape (formerly the adware-linked Crossrider). Those are real, VPN-relevant trust concerns.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.