Independent data report

VPN Protocol Transparency Report 2026: Only 3 of 20 Had Dedicated Public Assessments

Among the 20 core provider-developed technologies included in the July 13, 2026 VPN Protocol Registry, the public record was much thinner than the number of branded names suggests.

"No public protocol audit located" means no assessment meeting the registry definition was found by the verification date. It does not prove that no private review or other assessment occurred.

By Published August 8, 2026 Registry snapshot v0.1.0

Executive summary

VPN providers often place tunnel protocols, modified protocols, obfuscation transports, and composed stacks in the same app menu or marketing category. They are not equivalent. The registry classifies each technology by the role it plays, then records what public source and assessment evidence could be located.

Of the 20 core records, 3 had a dedicated public protocol assessment. Another 2 had a related public assessment, while 15 had no public protocol audit meeting the registry definition located by July 13, 2026. The denominator excludes four adjacent technologies that the registry classifies separately.

Public source was also uneven. 3 technologies had full public source and 3 had partial public source. Six exposed only the base protocol, not the provider-specific changes, and 8 were closed in this snapshot.

VPN Protocol Registry v0.1.0

What the 20 core records document

Dedicated assessment 3 of 20
Full or partial source 6 of 20
Restricted-network relevance 17 of 20
Post-quantum related 4 of 20
Each bar uses its own definition. Its length shows the share of core records that match, not a safety score. The categories overlap, so do not add them together.

Four findings from the core dataset

Finding 1

3 of 20

Dedicated public protocol assessment located

Finding 2

6 of 20

Full or partial public source located

Finding 3

17 of 20

Documented as relevant to restricted networks

Finding 4

4 of 20

Post-quantum-related status in the registry

1. Dedicated assessments were located for three technologies

The dedicated-assessment group contains Lightway, Mimic, Dausos. The registry uses a narrow rule: the public assessment must focus on the protocol or its implementation. A no-logs engagement, broad app audit, or private report does not qualify.

AmneziaWG and GhostBear had related public assessments. They remain separate because those reports did not amount to a dedicated protocol-design or implementation assessment under the registry method.

2. Six technologies had full or partial public source located

The snapshot records 3 as full source and 3 as partial. Source for a standard base such as WireGuard or OpenVPN does not automatically expose a provider's changes, wrappers, address-management layer, or deployed service. That is why the 6 base-only records are not counted with the public source group.

3. Restricted-network positioning was common

17 of 20 records included restricted networks among their documented purposes, and 13 included censorship circumvention. A design goal is not a result from every country or ISP. Filtering methods, app versions, network paths, and deployments change.

4. Four records had a post-quantum-related status

3 were recorded as production and 1 as optional. The mechanisms do not protect identical parts of the connection, so the count is not a list of four equivalent "quantum-safe VPNs." Each record needs to be read against its mechanism and caveats.

The same marketing category hides four technical roles

The core cohort contains 8 tunnel protocols, 6 provider variants, 3 obfuscation transports, and 3 composed stacks. Treating all 20 as interchangeable "VPN protocols" hides what each name actually changes.

Tunnel protocol

Defines the protected tunnel itself. The registry places Lightway and TrustTunnel in this group.

Provider variant

Modifies or extends a base protocol. NordLynx and AmneziaWG both have WireGuard roots but add different surrounding behavior.

Obfuscation transport

Changes how another tunnel travels or appears. Mullvad QUIC obfuscation belongs here.

Protocol stack

Combines several components under one provider label. Windscribe Stealth is one of the three stacks in the snapshot.

Full evidence table

This table shows all 20 records used in the report. Labels describe the public evidence located for the dated registry release. The table does not order providers or assign a security score.

Scroll horizontally to see every column.

Public source, assessment, classification, rollout, platform, and verification evidence for the 20 core provider-developed technologies in VPN Protocol Registry v0.1.0
Technology Type and base Public source Public assessment Rollout and platforms Verified
TrustTunnel AdGuard VPN Tunnel protocol HTTP tunnel Full public source No public protocol audit located Generally available Windows, macOS, Linux, Android, iOS, Server 2026-07-13
AmneziaWG Amnezia VPN Provider protocol variant WireGuard Full public source Related public assessment Generally available Windows, macOS, Linux, Android, iOS, Router, Server 2026-07-13
OpenWeb Astrill VPN Tunnel protocol Proprietary web-oriented tunnel Closed No public protocol audit located Generally available Windows, macOS, Linux, Android, iOS, Router 2026-07-13
StealthVPN Astrill VPN Provider protocol variant OpenVPN-derived design Closed No public protocol audit located Generally available Windows, macOS, Linux, Android, iOS, Router 2026-07-13
Lightway ExpressVPN Tunnel protocol Lightway protocol; wolfSSL Full public source Dedicated public assessment Generally available Windows, macOS, Linux, Android, iOS, Router 2026-07-13
Mimic Gen Digital Tunnel protocol Proprietary TLS 1.3-based tunnel Closed Dedicated public assessment Generally available Windows, macOS, Android, iOS 2026-07-13
Hydra Hotspot Shield Tunnel protocol Proprietary tunnel Closed No public protocol audit located Generally available Windows, macOS, Android, iOS 2026-07-13
KeepSolid Wise VPN Unlimited Provider protocol variant OpenVPN Base protocol only No public protocol audit located Generally available Unknown 2026-07-13
LWO Mullvad VPN Obfuscation transport WireGuard Partial public source No public protocol audit located Generally available Windows, macOS, Linux, Android, iOS 2026-07-13
QUIC obfuscation Mullvad VPN Obfuscation transport WireGuard; MASQUE CONNECT-UDP (RFC 9298) Partial public source No public protocol audit located Generally available Windows, macOS, Linux, Android, iOS 2026-07-13
NordLynx NordVPN Provider protocol variant WireGuard; NordVPN double NAT address-management layer Base protocol only No public protocol audit located Generally available Windows, macOS, Linux, Android, iOS, Router 2026-07-13
NordWhisper NordVPN Tunnel protocol Proprietary web-tunnel design Closed No public protocol audit located Generally available Windows, Linux, Android 2026-07-13
StealthVPN PrivateVPN Provider protocol stack OpenVPN; Shadowsocks Base protocol only No public protocol audit located Limited rollout Windows 2026-07-13
Stealth Proton VPN Provider protocol variant WireGuard Partial public source No public protocol audit located Generally available Windows, macOS, Android, iOS 2026-07-13
Dausos Surfshark Tunnel protocol Custom Dausos tunnel; TLS 1.3-derived handshake Closed Dedicated public assessment Beta macOS 2026-07-13
GhostBear TunnelBear Obfuscation transport TunnelBear VPN tunnel Closed Related public assessment Limited rollout Windows, macOS, Android 2026-07-13
Chameleon VyprVPN Provider protocol variant OpenVPN Base protocol only No public protocol audit located Generally available Windows, macOS, Android, iOS, Router 2026-07-13
Stealth Windscribe Provider protocol stack OpenVPN; stunnel Base protocol only No public protocol audit located Generally available Windows, macOS, Linux, Android, iOS 2026-07-13
WStunnel Windscribe Provider protocol stack OpenVPN; WebSocket tunnel Base protocol only No public protocol audit located Generally available Windows, macOS, Linux, Android, iOS 2026-07-13
Everest X-VPN Tunnel protocol Proprietary Everest tunnel family Closed No public protocol audit located Generally available Unknown 2026-07-13

The downloadable files add purposes, post-quantum status, and record caveats. The exact tagged registry release contains the complete source register, assessment records, generated dossiers, schemas, and checksums.

Methodology and limitations

The report analyzes the 20 records marked core in the immutable July 13, 2026 VPN Protocol Registry v0.1.0 release. The unit of observation is one provider-developed technology, not one provider and not every VPN protocol in existence. Four adjacent technologies remain in the source dataset but are excluded from every headline count.

Each record was checked against the registry's normalized source register. Fields include classification, technical base, transport, purposes, rollout, platforms, source status, public assessment status, post-quantum status, caveats, and the last verification date. The report calculates its figures from the checked-in snapshot instead of copying totals into the page by hand.

Absence claims are deliberately limited. "No public protocol audit located" records the result of the documented search up to the verification date. It cannot exclude private work, unpublished findings, documents outside the search, or evidence published after the snapshot. Public source does not prove production parity, secure implementation, or sound operation. Assessment status does not establish logging behavior or overall provider trustworthiness.

Read the site-wide research and correction policy for release, evidence, independence, and update rules.

Download, reproduce, and cite the report

Report data

These report-specific files contain the 20-row cohort, definitions, findings, and record caveats.

Reusable graphic

The 1200 by 630 graphic is available as an editable SVG and a publication-ready PNG under CC BY 4.0.

Canonical source files

The exact VPN Protocol Registry v0.1.0 GitHub release is the canonical source for the JSON, CSV, generated dossiers, schemas, source register, citation metadata, and checksums used here. The archived release is available through the preferred dataset DOI, 10.5281/zenodo.21813597.

Suggested citation

Price, Steve. "VPN Protocol Transparency Report 2026." DoVPN, August 8, 2026. https://dovpn.com/research/vpn-protocol-transparency-2026/. Based on VPN Protocol Registry v0.1.0, DOI: 10.5281/zenodo.21813597.

Author identifier: ORCID 0009-0009-6603-6878. Data and graphic license: CC BY 4.0.

Provider responses

Providers were not asked to respond before this first report was published. On-record responses received after publication will be added below with the date received and a link to any supporting public evidence. A response does not silently overwrite the frozen v0.1.0 dataset.

Provider Status Date received Public response or evidence
All providers in the v0.1.0 cohort No pre-publication response requested Not applicable No response recorded

Providers can send a response or evidence link to steve@dovpn.com. Factual corrections follow the policy below.

Corrections and updates

Corrections are logged rather than folded into the report without notice. A page-level wording correction changes the modified date and receives a note here. A correction to a registry record follows the registry release process so the source, reason, and affected version remain visible. Send a record ID, evidence link, and explanation to steve@dovpn.com.

No corrections have been recorded for this report. Readers who need help choosing a setting can use the separate VPN protocol comparison and selector.