
NordVPN is safe to use. It operates from Panama, and Deloitte has audited its no-logs policy six times, most recently in February 2026. Its servers hold nothing on disk, and it leaked nothing in our testing. That is the short version. The longer version matters more, because “safe” covers several separate questions.
Who owns the company. What the audits actually examined. Whether the 2018 server breach still counts against it, and what the apps collect while you use them. We read the current privacy notice line by line to answer the last one.
Who Owns NordVPN and Where It Operates From
NordVPN is legit, and the corporate trail is public. The service is registered in Panama and belongs to Nord Security, a company headquartered in Lithuania that also makes NordPass and NordLocker. Panama matters for one specific reason. It has no mandatory data retention law, and it sits outside the 14 Eyes intelligence-sharing arrangement. A VPN based in the US or UK can be served an order to start logging a named user.
A Panamanian company has no equivalent obligation, the practical difference between a no-logs promise that holds and one that bends. If you want the wider context on how much any of this protects you, we cover it in our guide to whether VPNs are safe.
Encryption and Protocols
Encryption scrambles your traffic. Anything intercepted along the way comes out as noise. NordVPN uses AES-256 on OpenVPN and IKEv2, and ChaCha20-Poly1305 on NordLynx. Both are standards with no known practical break. NordLynx is NordVPN’s own build of WireGuard, and the distinction is a privacy one.

WireGuard has to store a user’s IP address on the server to route traffic. NordLynx puts a double NAT system in front of that, so the connection works without keeping an identifier tied to you. This is the protocol we leave on by default, and it is also the fastest of the three. NordVPN has added post-quantum encryption to NordLynx.

The idea is defence against harvest-now-decrypt-later attacks, where traffic captured today gets stored until quantum hardware can open it. Obfuscated servers and the NordWhisper protocol disguise VPN traffic as ordinary web traffic. That is what makes the service usable on networks that block VPNs outright, including restrictive countries like China.
No-Logs Policy and Who Audited It
A no-logs claim is worth as much as the evidence behind it. NordVPN has commissioned more independent assessments than anyone else. PwC AG in Switzerland examined the policy in 2018 and again in 2020. Deloitte has since audited it six times, the latest of those in February 2026. That February date is the answer to the question behind most searches here.

The record is not a single certificate from years ago that a company keeps pointing at. It is an assessment repeated on a schedule, by a firm with its reputation at stake, and the most recent one is months old rather than years. The auditors confirmed the VPN does not store browsing activity, connection timestamps, or the IP addresses users connect from. One caveat. An audit is a snapshot of practice on the day it happened, not a standing guarantee.

Repeated audits from named firms remain the strongest signal this market offers, and NordVPN has more of them than most. Our no-logs VPN guide explains how the claims compare across providers. The infrastructure supports the policy. NordVPN’s servers are diskless and load from RAM, so a seized or stolen server has nothing persistent to hand over to anyone.
What NordVPN’s Apps Actually Collect
The no-logs policy covers VPN traffic. The apps are a separate matter, and NordVPN’s privacy notice sets out what they gather. The apps collect device-level information tied to a randomly generated identifier on the device. That identifier is not linked to an email address, an account, or online activity, and it cannot be matched across devices. The data covers device country, city, and time zone, operating system details and app version.
It also includes crash logs and yes/no markers for whether an action like a login succeeded. The apps record connection details including the name of your public internet service provider, the protocol in use, and which server the app connected to. NordVPN’s position is that this sits behind the random device identifier and cannot be traced to an individual. The design is reasonable. It is also more than nothing, which is why it belongs on this page.

The second is the 90-day connectivity flag. NordVPN keeps a record of whether an account used the service within the last 90 days, for abuse prevention and chargeback disputes. Session information used to cap concurrent logins is deleted within 15 minutes of a session ending. Analytics and advertising collection are optional and controlled in the app settings.
On Android, granting advertising consent lets NordVPN read a resettable system advertising ID, used only to measure its own campaigns. There is no equivalent collection on iOS. Our advice is to switch both toggles off during setup. Nothing about the VPN stops working without them.
The 2018 Server Breach, and Whether It Still Counts
NordVPN has been breached once. In March 2018, an attacker reached a single server in a Finnish data center through an insecure remote management tool that the data center provider had left enabled. NordVPN says it was not informed the tool existed. What the attacker could reach was limited to that one server. No user credentials or activity logs were exposed, because none were stored there.
An expired TLS certificate key was taken, which could in theory have supported a targeted attack against that single server, and could not decrypt VPN traffic at large. The fair criticism is the disclosure. NordVPN went public in October 2019, roughly a year and a half after the incident, and only once the story had begun circulating independently. That delay is the part that should shape how much you trust it.
What followed is the reason we still recommend the service. NordVPN ended the contract with that provider, audited its entire infrastructure, moved every server to the diskless RAM-only setup, and opened a public bug bounty. There has been no repeat since. The breach is history, and the response to it is the more useful signal.
Leak Tests, Kill Switch, and Threat Protection
A VPN that leaks your DNS requests or real IP address defeats its own purpose, so this is the test that matters most. We put NordVPN through ipleak.net and dnsleaktest.com across multiple servers and protocols. No DNS, WebRTC, or IPv6 leaks appeared. We performed these checks in August 2026. The kill switch is the backstop. If the VPN connection drops, it cuts internet access before your real IP is exposed.

We tested it by killing the connection deliberately, and traffic stopped immediately, the same millisecond. NordVPN offers two versions: an internet kill switch that blocks everything, and an app kill switch that closes only the programs you nominate. Our kill switch guide covers why the distinction matters.

Threat Protection Pro adds a layer above the VPN itself, blocking trackers, malicious domains, and infected downloads. It stays active when the VPN is switched off, which is unusual and genuinely useful.

Is NordVPN Safe for Banking?
Yes, and it helps on public networks. Bank sessions over hotel or cafe Wi-Fi are the exact case a VPN is built for, since the encryption holds even if the network itself is hostile. Banks watch for logins from unexpected locations, and connecting through a server in another country can trigger a fraud hold or an extra verification step.
Connect to a server in your country before opening a banking app, and the issue disappears. We go further into this in our guide to the best VPNs for banking.
How to Tell You Are on the Real NordVPN Site
Fake VPN sites exist, and NordVPN’s popularity makes it a common target for lookalike domains that harvest card details or serve altered installers. The only official domain is nordvpn.com, so inspect the address bar for extra words, hyphens, or a different ending before entering payment details. And download the app from that site or from an official app store, never from a third-party download portal.
Verdict: Is NordVPN Safe?
Yes. The jurisdiction is favorable, the servers keep nothing on disk, and it leaked nothing in our testing. Eight independent audits, six of them by Deloitte and the last in February 2026, put the no-logs policy on firmer ground than any rival can claim. The 2018 breach is a mark on the record, though the technical damage was contained and the response was really substantial.
The caveat is the app telemetry. It is modest, documented, and partly optional. Still, a VPN that records your ISP name and chosen server is not collecting nothing. Switch the analytics and advertising toggles off, and you are close to the strongest position available at this price. Plans start at $3.49 a month on the 2-year term, and every plan has a 30-day money-back guarantee.
For the full breakdown, read our NordVPN review, or compare it against the field on our best VPN list to learn why it’s our overall favorite VPN.
Is NordVPN Safe: Frequently Asked Questions
🛜 Is NordVPN safe to use on public Wi-Fi?
Yes, NordVPN is safe to use on a public Wi-Fi network. Traffic is encrypted before it reaches the network, so an operator or another user on the same hotspot sees only that a VPN connection is open. Enabling auto-connect for untrusted networks in the app settings removes the risk of forgetting.
⚖️ Is NordVPN legal?
Yes, in most countries. A handful of states restrict or ban VPN use, among them China, Russia, and Iran, where penalties attach to the user and not the provider. The legality of VPNs is set out by country in a separate guide.
💵 Does NordVPN sell user data?
No. The privacy notice contains no provision for selling personal data or sharing it with advertisers, and the optional advertising data described in it measures NordVPN's own campaigns only.
🛡️ Can NordVPN see browsing history?
No. Traffic is encrypted through the tunnel, and the servers store nothing on disk, so browsing history is not retained anywhere it could be retrieved or handed over. It's explained in its audited no-log policy.
🧲 Is NordVPN safe for torrenting?
Yes. NordVPN permits traffic on the network, and the kill switch stops an IP appearing in a swarm if the connection drops. Panama's lack of a retention law means no download record exists to request. Further detail sits in the best P2P VPN guide.