Industry Analysis

Who Really Owns Your VPN? Founders, Ownership & Controversies (2026)

The VPN market quietly consolidated into a handful of parent companies. Here is who controls what — with the acquisition dates, the prices, and the difference between a proven scandal and an internet rumor.

By the VPN Insider editorial desk · Independent analysis · Every nontrivial claim below is sourced; see references. Last verified June 2026.

"No-logs," "privacy-first," "founded by activists" — the marketing is nearly identical across the category. The ownership is not. Over the last decade a few holding companies have rolled up the most-advertised brands, and a parent company's incentives, home jurisdiction, and track record tell you more about a VPN than any landing page.

This is a map of who owns whom as of 2026: the founders, the roots, the ownership timeline with dates, and the controversies. We separate the three things most write-ups blur together — proven events with public records behind them, whispers that remain unproven allegations, and clean records where the dirt simply isn't there. Where a widely repeated "fact" is wrong, we say so.

A structural quirk runs through the whole industry: providers routinely place the service entity in a privacy-friendly jurisdiction (Panama, the British Virgin Islands, Switzerland) while the parent or operations sit somewhere else entirely. A Panama mailing address does not move the engineering team out of a surveillance-alliance country. Read jurisdiction claims as marketing until you've checked the corporate registry.

Ownership at a glance

The four roll-ups below — Kape, Nord Security, Ziff Davis, and the Aura/Point Wild lineage — control a large share of the brands you see advertised. The independents sit at the bottom.

Parent / ownerBrandsService jurisdictionRecord
Kape Technologies (Isle of Man; private, Teddy Sagi)ExpressVPN, CyberGhost, Private Internet Access, ZenMateBVI / Romania / USproven issues
Nord Security (Amsterdam, NL)NordVPN, SurfsharkPanama / Netherlands1 breach
Ziff Davis (US, public)IPVanish, StrongVPNUnited Statespast logging
Point Wild / ex-Aura (US)Hotspot Shield, Betternet, UltraVPNUnited StatesFTC complaint
McAfee (US)TunnelBearCanadamostly clean
Certida LLC (Texas, US)VyprVPN (ex-Golden Frog)US (was Switzerland)jurisdiction shift
Proton AG (Geneva, CH)Proton VPNSwitzerlandstrong
Mullvad / Amagicom AB (Sweden)MullvadSwedenclean
Windscribe (Toronto, CA)WindscribeCanadaindependent

Kape Technologies — the roll-up that started as adware

Owner: Teddy Sagi (via Unikmind Holdings) · Registered: Isle of Man · HQ: London · Status: private since 2023

No story captures the industry's reinvention better than Kape. The company was founded in 2011 as Crossrider, a browser-extension and ad-monetization platform whose toolkit was widely abused to push adware — Malwarebytes still ships a detection family called Adware.CrossRider.1 Crossrider shut down that platform in 2016, rebranded to Kape Technologies in 2018, and pivoted into consumer privacy by acquiring VPNs.2 The irony — an ex-adware company selling privacy — is the single most-cited fact about Kape, and it is accurate.

In 2023, Israeli billionaire Teddy Sagi, already the majority holder, took Kape private through Unikmind Holdings, raising his offer to 290 pence (US$3.60) per share and valuing Kape's equity at roughly US$1.58 billion on completion in May 2023. Kape delisted from London's AIM market and is now wholly Sagi-owned.34

The acquisition timeline

Controversies

proven Beyond the Crossrider adware lineage, Kape's most significant conflict of interest is editorial: in 2021 it acquired Webselenese, the company behind the "independent" review sites vpnMentor and WizCase, for about US$149 million. A holding company that owns three major VPNs and the review sites that rank them is a textbook conflict — and post-acquisition, those sites' rankings favored Kape-owned brands.11

Separately, ExpressVPN's then-CIO Daniel Gericke was one of three former U.S. operatives named in a September 2021 U.S. Department of Justice deferred-prosecution agreement over Project Raven, a UAE surveillance operation; Gericke's share of the settlement was US$335,000. It was a settlement, not a conviction, and ExpressVPN publicly stood by him — but a VPN's security chief paying to settle a foreign-spying case is a legitimate trust question.12

whisper Speculation about Israeli-intelligence ties — driven by Sagi's nationality and an unrelated decades-old conviction — recurs online but rests on no evidence. We flag it as rumor, not finding. On the upside, the Kape brands now commission independent no-logs audits and publish them.

Analyst's read

Kape's brands are technically capable, and the audits are real. The hard part is structural: the same owner controls the products and once controlled the "independent" sites reviewing them. If you buy a Kape VPN, do it on the product's audited merits — never on a top-10 list, because some of those lists were in-house.

Nord Security — the Lithuanian powerhouse

Parent: Nord Security (Amsterdam, NL) · Roots: Tesonet, Vilnius, Lithuania

NordVPN traces to childhood friends Tomas Okmanas (Tom Okman) and Eimantas Sabaliauskas, working out of the Lithuanian tech incubator Tesonet (co-founded 2008). The company dates to 2012 and the NordVPN product launched in 2013 — a small but worth-correcting nuance to the usual "founded 2012" shorthand.1314 The service is operated under Panama jurisdiction, while parent Nord Security is headquartered in Amsterdam.15

Surfshark, founded in 2018 by Vytautas Kaziukonis, began under British Virgin Islands jurisdiction but relocated its HQ to the Netherlands in 2021 — so the commonly cited "BVI" label is now outdated.16 In a deal announced in 2021 and finalized in 2022, Nord Security and Surfshark merged under one holding company while continuing to run as separate brands with separate infrastructure.17

Controversies

proven In 2018, a single NordVPN server in a Finland data center was accessed via an insecure remote-management tool the data center had added without Nord's knowledge. No user logs or credentials were exposed, but the bigger problem was disclosure: Nord learned of it in 2019 and only went public in October 2019 after it surfaced on social media. An expired TLS key was taken; the delayed disclosure, more than the breach itself, drew the criticism.18

whisper Nord's close ties to Tesonet — which also runs data-harvesting and residential-proxy businesses — fuel recurring "they share your data" allegations. These remain circumstantial and unproven; Nord denies them and its independent audits support the no-logs claim. Worth noting precisely: Nord's no-logs assurance audits were done by PwC in 2018 and 2020, then by Deloitte from 2022 onward — repeated independent verification is a genuine point in its favor.19

Analyst's read

The 2018 breach was real but limited; the repeated, switching-auditor transparency since is more reassuring than a single audit would be. The Tesonet questions are about trust in the corporate family, not a documented leak. Reasonable mainstream choices — just know you're buying into a large commercial group, not a scrappy independent.

Ziff Davis — IPVanish and the logging that shouldn't have existed

Parent: Ziff Davis (US, public) · Jurisdiction: United States (Five Eyes)

IPVanish launched in 2012 under Mudhook Media, a subsidiary of Highwinds Network Group. Highwinds (with IPVanish) was bought by StackPath in February 2017, and in 2019 IPVanish moved to J2 Global — since renamed Ziff Davis — under its NetProtect unit.20

proven The defining controversy predates current ownership. In 2016, under Highwinds, IPVanish handed detailed connection logs — source IPs and session times — to Homeland Security Investigations in a criminal case, despite marketing a "zero-logs" policy. The episode (publicly reported in 2018) is one of the clearest cautionary tales in the category: a no-logs promise is only as good as the corporate will and jurisdiction behind it. IPVanish has since changed ownership and submitted to independent auditing.21

Analyst's read

Different owners, U.S. jurisdiction, an audited policy today — but the 2016 incident is exactly why we weight verifiable audits and jurisdiction over slogans. If your threat model includes U.S. legal process, a Five-Eyes-based VPN with a logging history is not where to start.

Hotspot Shield — from AnchorFree to Aura to Point Wild

Owner: Point Wild (US) · Lineage: AnchorFree → Pango → Aura → Point Wild

Hotspot Shield is the flagship of AnchorFree, founded in 2005 by David Gorodyansky and Eugene Malobrodsky; the VPN launched in 2008.22 The ownership chain since is one of the messiest in the industry: AnchorFree rebranded to Pango; Pango was acquired by Aura (founder/CEO Hari Ravichandran) in July 2020; in 2024 Aura split and spun Pango back out; and in December 2024 Pango merged with TotalAV's parent and rebranded as Point Wild, which now owns Hotspot Shield alongside Betternet, UltraVPN and others.23

proven In August 2017, the Center for Democracy & Technology filed an FTC complaint against Hotspot Shield's free tier, alleging undisclosed data sharing, interception and redirection of user traffic to advertising partners, and ad injection — practices flatly at odds with a privacy product.24

Analyst's read

A documented FTC complaint over traffic interception, plus an ownership trail so convoluted it's hard to say who's accountable today, makes this lineage the hardest to recommend for anyone who actually needs privacy. The free tier especially monetizes the thing you're trying to protect.

McAfee — TunnelBear's friendly face

Owner: McAfee (US) · Operated from: Toronto, Canada

TunnelBear was founded in 2011 by Daniel Kaldor and Ryan Dochuk in Toronto, and acquired by McAfee in March 2018.25 It was an early adopter of annual independent security audits, and its record is largely free of major scandal — complaints tend to be about performance and feature limits rather than trust.

Analyst's read

Clean record and audit-forward, but U.S.-owned and operated from Canada — two Five Eyes countries. Fine for casual privacy and unblocking; not the pick if jurisdiction is central to your threat model.

VyprVPN — the jurisdiction that moved the wrong way

Owner: Certida LLC (Texas, US) · Was: Golden Frog (Switzerland)

VyprVPN was built by Golden Frog, founded in December 2009 by internet veterans Ron and Carolyn Yokubaitis, with its privacy jurisdiction in Switzerland (not the Netherlands, a detail frequently mis-stated). In 2023 it was acquired by Certida LLC of Texas, shifting the operation to U.S. jurisdiction.26

proven Historically, VyprVPN retained connection metadata for up to ~30 days. It addressed this in 2018 with one of the industry's first public no-logs audits, by Leviathan Security Group, which found issues that were then fixed.27 whisper The live concern is structural: a 2023 move from Switzerland to Texas trades one of the world's stronger privacy jurisdictions for a Five Eyes member — the opposite of the direction privacy buyers want.

Analyst's read

An audited history and a real fix to its logging, but the jurisdiction shift to the U.S. is a meaningful downgrade for anyone choosing a VPN on privacy grounds. Re-evaluate it as a U.S. service now, not the Swiss one it used to be.

The independents — Proton, Mullvad, Windscribe

Three notable providers have no roll-up parent, and it shows in how they behave under pressure.

Proton VPN strong

Parent: Proton AG, controlled by the non-profit Proton Foundation · HQ: Geneva, Switzerland

Proton grew out of CERN: the company was founded in 2014 (the ProtonMail era) by Andy Yen, Jason Stockman and Wei Sun, and Proton VPN launched in May 2017. Since June 2024, Proton AG has been controlled by the non-profit Proton Foundation, a structure explicitly designed to keep the mission insulated from acquirers.2829

proven, with a key distinction The 2021 "Proton logged a user" story is real but is routinely misattributed. It involved ProtonMail, not Proton VPN: compelled by a legally binding Swiss order (routed via Europol from French police), ProtonMail logged the IP address of a French climate activist. Email contents stayed encrypted, and Proton has noted it doesn't log IPs by default. It's a useful reminder that no provider is above its home country's law — but it was an email-service order, not a VPN logging failure.30

Mullvad cleanest record in the category

Operator: Mullvad VPN AB / Amagicom AB · HQ: Gothenburg, Sweden · founder-owned

Launched in 2009 by Fredrik Strömberg and Daniel Berntsson, Mullvad is wholly owned through Amagicom AB with no outside investors, and is famous for anonymous accounts — a random account number, no email required.31 proven (in its favor) In April 2023, Swedish police arrived at Mullvad's office with a search warrant intending to seize customer data and left empty-handed because none existed — about the strongest real-world validation of a no-logs claim available.32

Windscribe independent

Owner: founders & employees · HQ: Toronto, Canada

Founded in 2016 by Yegor Sak, Alex Paguis and Mark Ulicki, Windscribe is fully owned by its founders and staff.33 proven In June 2021, Ukrainian authorities seized two Windscribe servers; the company candidly disclosed that those two servers were not properly encrypted and stored an OpenVPN certificate and key on disk, then re-architected to keep keys in memory only. The honesty of the post-mortem earned more trust than the incident cost — though it's a reminder that Canada is a Five Eyes country.34

Analyst's read

If transparency under pressure is your bar, the independents clear it most convincingly. Mullvad and Proton VPN are the reference points for privacy-first buyers; Windscribe earns credit for candor despite a Five-Eyes home.

Four patterns worth internalizing

1. Consolidation concentrates incentive. Kape, Nord Security, Ziff Davis and the Aura/Point Wild lineage control a large share of the advertised market. When one owner runs multiple "competing" brands — and, in Kape's case, once ran the review sites too — the comparison you're reading may be a sale, not an analysis.

2. Acquisitions move jurisdictions and policies. The dates matter: PIA (Dec 2019), ExpressVPN (Sep 2021) and VyprVPN (2023) each changed the calculus of the product overnight. VyprVPN's Switzerland-to-Texas move is the clearest example of a deal making a service less private.

3. Jurisdiction is marketed, not always real. A Panama or BVI service entity is a legal address; the engineers, executives and infrastructure may sit in a surveillance-alliance country. Check the parent, not just the privacy-policy boilerplate.

4. The recurring failure modes are mundane. Subscription dark patterns, audits that quietly go stale, and "no-logs" claims that were never tested account for most real-world harm — more than exotic intelligence conspiracies. The independents (Mullvad, Proton, Windscribe) tend to score highest precisely because their behavior under legal pressure is documented.

The bottom line

No provider is perfect, and the right VPN depends on your threat model, not a leaderboard. But a few durable conclusions hold up against the records: for maximum privacy, favor proven, independently owned no-logs services whose claims have survived a real-world test — Mullvad's empty-handed police raid and Proton's non-profit structure are the gold standard. For mainstream use, the large commercial brands are capable, but buy them on their current, dated audits and jurisdiction — not on slogans, and never on a "top 10" list whose owner you haven't checked. And treat any acquisition as a reset: when a VPN changes hands, its old promises don't automatically carry over. Verify the latest audit, transparency report and company registry before you trust — or pay for — any of them.

References

Sources accessed and verified June 2026. VPN ownership, audits and policies change frequently — confirm current details against company registries and the latest transparency reports before relying on them.

  1. Malwarebytes Labs, "Adware.CrossRider" detection reference. malwarebytes.com
  2. CyberInsider, "Kape Technologies and its Crossrider/adware past." cyberinsider.com
  3. Perivan / regulatory notice, "Unikmind Holdings closes acceptances for Kape Technologies — equity valued at $1.58 billion" (2023). perivan.com
  4. Bloomberg, "Billionaire Sagi Raises Offer for UK Software Company Kape," April 20, 2023. bloomberg.com
  5. CyberGhost VPN, "About / company history"; corroborated by TechCrunch coverage of the Kape acquisition. cyberghostvpn.com
  6. PR Newswire, "ZenMate Acquired by Kape Technologies" (Oct 2018). prnewswire.com
  7. Kape Technologies RNS, "Completion of Private Internet Access acquisition" (Dec 16, 2019). investegate.info
  8. Wikipedia, "Private Internet Access." en.wikipedia.org
  9. Business Wire, "ExpressVPN to Join Kape Technologies," Sept 13, 2021. businesswire.com
  10. The Register, "ExpressVPN bought by Kape Technologies," Sept 14, 2021. theregister.com
  11. CyberInsider, "VPN review websites owned by VPN companies" (Kape / Webselenese / vpnMentor / WizCase). cyberinsider.com
  12. Cybernews, "ExpressVPN CIO Daniel Gericke fined $335,000 for cyber-espionage (Project Raven)," 2021. cybernews.com
  13. Wikipedia, "NordVPN." en.wikipedia.org
  14. Wikipedia, "Tesonet." en.wikipedia.org
  15. NordVPN Support, "Where is NordVPN based?" support.nordvpn.com
  16. Wikipedia, "Surfshark"; Surfshark "About us" (HQ relocation to the Netherlands, 2021). en.wikipedia.org
  17. NordVPN Blog, "Nord Security and Surfshark merger agreement" (finalized 2022). nordvpn.com
  18. NordVPN Blog, "Official response to the data-center breach"; Engadget, "NordVPN confirms data-center breach," Oct 2019. nordvpn.com · engadget.com
  19. NordVPN Blog, "Independent no-logs audits" (PwC 2018, 2020; Deloitte 2022–). nordvpn.com
  20. Wikipedia, "IPVanish" (Highwinds/Mudhook → StackPath 2017 → J2 Global/Ziff Davis 2019). en.wikipedia.org
  21. TorrentFreak, "No-logging VPN IPVanish led Homeland Security to a Comcast user" (2018, on 2016 events). torrentfreak.com
  22. Wikipedia, "AnchorFree" (founders Gorodyansky & Malobrodsky, 2005; Hotspot Shield 2008). en.wikipedia.org
  23. PR Newswire, "Pango Group merges with Total Security; combined company rebranded Point Wild" (Dec 2024); PR Newswire, "Aura acquires Pango" (2020). prnewswire.com
  24. Center for Democracy & Technology, "CDT's complaint to the FTC on Hotspot Shield VPN," Aug 7, 2017. cdt.org
  25. Wikipedia, "TunnelBear"; VentureBeat, "McAfee acquires VPN company TunnelBear," Mar 2018. venturebeat.com
  26. Golden Frog / VyprVPN "About" (founders Ron & Carolyn Yokubaitis, Dec 2009, Switzerland; acquired by Certida LLC, Texas, 2023). goldenfrog.com
  27. Business Wire, "VyprVPN Publishes World's First Public No-Log Audit" (Leviathan Security, 2018). businesswire.com
  28. Wikipedia, "Proton VPN" (founders met at CERN; VPN launched May 2017). en.wikipedia.org
  29. Proton, "Proton transitions to a non-profit Foundation structure," June 2024; TechCrunch coverage. proton.me
  30. TechCrunch, "ProtonMail logged IP address of French activist after order by Swiss authorities," Sept 2021. techcrunch.com
  31. Mullvad, "About" (Strömberg & Berntsson, Amagicom AB, founder-owned). mullvad.net
  32. Mullvad Blog, "Mullvad VPN was subject to a search warrant. Customer data not compromised," April 2023. mullvad.net
  33. Windscribe Knowledge Base, "Who owns Windscribe?" windscribe.com
  34. Windscribe Blog, "Ukrainian server seizure — a commentary and state of the industry," 2021. windscribe.com
Independent · affiliate-funded · rankings not for sale. We may earn a commission if you subscribe through our links, but commission never touches our scores, this analysis, or which companies we scrutinize. This article reports proven, sourced events and clearly labels unproven allegations as such. It is informational, not legal advice. See how we review.

VPNInsider.org · Industry Analysis · updated monthly · June 2026.