{
  "report": {
    "id": "vpn-protocol-transparency-2026",
    "title": "VPN Protocol Transparency Report 2026",
    "publishedDate": "2026-08-08",
    "snapshotDate": "2026-07-13",
    "cohort": "20 core provider-developed technologies included in the July 13, 2026 VPN Protocol Registry v0.1.0",
    "sourceRelease": "https://github.com/steveprice-dev/vpn-protocol-registry/releases/tag/v0.1.0",
    "preferredDoi": "10.5281/zenodo.21813597",
    "license": "CC BY 4.0",
    "methodologyUrl": "https://dovpn.com/research/vpn-protocol-transparency-2026/#methodology",
    "reportUrl": "https://dovpn.com/research/vpn-protocol-transparency-2026/"
  },
  "definitions": {
    "cohort": "Records whose scope is core in registry v0.1.0. Adjacent technologies are excluded from every headline denominator.",
    "dedicatedPublicAssessment": "The registry audit_status is published_dedicated. A private engagement, whole-service audit, or related application assessment does not meet this definition.",
    "noPublicProtocolAuditLocated": "No public assessment meeting the registry rule was located by the record verification date. This is not proof that no assessment occurred.",
    "fullOrPartialPublicSource": "The registry source_status is full or partial. Base-protocol-only source does not count as source for the provider-specific technology.",
    "restrictedNetworkRelevance": "The record includes restricted_networks among its documented purposes. This is not evidence that the technology works on every restricted network.",
    "postQuantumRelated": "The registry post-quantum status is production, optional, or claimed. Technologies in this group may protect different parts of a connection."
  },
  "findings": [
    {
      "id": "dedicated-audit",
      "label": "Dedicated public protocol assessment located",
      "count": 3,
      "denominator": 20,
      "percent": 15
    },
    {
      "id": "public-source",
      "label": "Full or partial public source located",
      "count": 6,
      "denominator": 20,
      "percent": 30
    },
    {
      "id": "restricted-networks",
      "label": "Documented as relevant to restricted networks",
      "count": 17,
      "denominator": 20,
      "percent": 85
    },
    {
      "id": "post-quantum",
      "label": "Post-quantum-related status in the registry",
      "count": 4,
      "denominator": 20,
      "percent": 20
    }
  ],
  "records": [
    {
      "id": "adguard-trusttunnel",
      "provider": "AdGuard VPN",
      "technology": "TrustTunnel",
      "classification": "Tunnel protocol",
      "technicalBase": "HTTP tunnel",
      "sourceStatus": "Full public source",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Linux",
        "Android",
        "iOS",
        "Server"
      ],
      "purposes": [
        "Restricted networks",
        "Mobile efficiency",
        "Transport reliability"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The public release date is not the date the underlying design first entered AdGuard VPN.",
        "Transport resemblance is a design goal, not a guarantee of censorship resistance in every network."
      ]
    },
    {
      "id": "amnezia-amneziawg",
      "provider": "Amnezia VPN",
      "technology": "AmneziaWG",
      "classification": "Provider protocol variant",
      "technicalBase": "WireGuard",
      "sourceStatus": "Full public source",
      "assessmentStatus": "Related public assessment",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Linux",
        "Android",
        "iOS",
        "Router",
        "Server"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention",
        "General performance"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "Resistance to detection depends on configuration and censor capability.",
        "The related application audit cannot be treated as validation of the protocol design."
      ]
    },
    {
      "id": "astrill-openweb",
      "provider": "Astrill VPN",
      "technology": "OpenWeb",
      "classification": "Tunnel protocol",
      "technicalBase": "Proprietary web-oriented tunnel",
      "sourceStatus": "Closed",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Linux",
        "Android",
        "iOS",
        "Router"
      ],
      "purposes": [
        "Restricted networks",
        "Long-distance performance",
        "General performance"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "Performance and censorship-resistance statements are provider claims.",
        "The public description is too limited for independent protocol-level analysis."
      ]
    },
    {
      "id": "astrill-stealthvpn",
      "provider": "Astrill VPN",
      "technology": "StealthVPN",
      "classification": "Provider protocol variant",
      "technicalBase": "OpenVPN-derived design",
      "sourceStatus": "Closed",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Linux",
        "Android",
        "iOS",
        "Router"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The precise relationship to OpenVPN cannot be independently confirmed from public code.",
        "Anti-detection effectiveness is not established by a public dedicated audit."
      ]
    },
    {
      "id": "expressvpn-lightway",
      "provider": "ExpressVPN",
      "technology": "Lightway",
      "classification": "Tunnel protocol",
      "technicalBase": "Lightway protocol; wolfSSL",
      "sourceStatus": "Full public source",
      "assessmentStatus": "Dedicated public assessment",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Linux",
        "Android",
        "iOS",
        "Router"
      ],
      "purposes": [
        "General performance",
        "Mobile efficiency",
        "Transport reliability",
        "Post-quantum related"
      ],
      "postQuantumStatus": "In production",
      "lastVerified": "2026-07-13",
      "caveats": [
        "Audit results apply to identified versions and scopes, not automatically to every later release.",
        "Open core code does not make the commercial service's entire infrastructure open source."
      ]
    },
    {
      "id": "gendigital-mimic",
      "provider": "Gen Digital",
      "technology": "Mimic",
      "classification": "Tunnel protocol",
      "technicalBase": "Proprietary TLS 1.3-based tunnel",
      "sourceStatus": "Closed",
      "assessmentStatus": "Dedicated public assessment",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Android",
        "iOS"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention",
        "Post-quantum related"
      ],
      "postQuantumStatus": "In production",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The exact post-quantum construction and full design remain non-public.",
        "Remediation statements for the assessed version do not establish that every legacy client or server was upgraded."
      ]
    },
    {
      "id": "hotspotshield-hydra",
      "provider": "Hotspot Shield",
      "technology": "Hydra",
      "classification": "Tunnel protocol",
      "technicalBase": "Proprietary tunnel",
      "sourceStatus": "Closed",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Android",
        "iOS"
      ],
      "purposes": [
        "General performance",
        "Long-distance performance",
        "Transport reliability"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The detailed protocol design and current cryptographic construction are not publicly reviewable.",
        "Broader company or service audits are not counted as a dedicated Hydra audit."
      ]
    },
    {
      "id": "keepsolid-wise",
      "provider": "VPN Unlimited",
      "technology": "KeepSolid Wise",
      "classification": "Provider protocol variant",
      "technicalBase": "OpenVPN",
      "sourceStatus": "Base protocol only",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Unknown"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The provider-specific layer is not open merely because OpenVPN is open.",
        "Current platform coverage needs a stronger first-party platform matrix in a later review."
      ]
    },
    {
      "id": "mullvad-lwo",
      "provider": "Mullvad VPN",
      "technology": "LWO",
      "classification": "Obfuscation transport",
      "technicalBase": "WireGuard",
      "sourceStatus": "Partial public source",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Linux",
        "Android",
        "iOS"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention",
        "General performance"
      ],
      "postQuantumStatus": "Not applicable",
      "lastVerified": "2026-07-13",
      "caveats": [
        "LWO changes traffic appearance but does not create a new cryptographic VPN protocol.",
        "No public dedicated third-party assessment was located."
      ]
    },
    {
      "id": "mullvad-quic-obfuscation",
      "provider": "Mullvad VPN",
      "technology": "QUIC obfuscation",
      "classification": "Obfuscation transport",
      "technicalBase": "WireGuard; MASQUE CONNECT-UDP (RFC 9298)",
      "sourceStatus": "Partial public source",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Linux",
        "Android",
        "iOS"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention",
        "Transport reliability"
      ],
      "postQuantumStatus": "Not applicable",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The standardized MASQUE base does not make Mullvad's entire integration independently deployable.",
        "It is an obfuscation transport rather than a replacement for WireGuard cryptography."
      ]
    },
    {
      "id": "nordvpn-nordlynx",
      "provider": "NordVPN",
      "technology": "NordLynx",
      "classification": "Provider protocol variant",
      "technicalBase": "WireGuard; NordVPN double NAT address-management layer",
      "sourceStatus": "Base protocol only",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Linux",
        "Android",
        "iOS",
        "Router"
      ],
      "purposes": [
        "General performance",
        "Address privacy",
        "Post-quantum related"
      ],
      "postQuantumStatus": "Optional",
      "lastVerified": "2026-07-13",
      "caveats": [
        "Only the WireGuard base is public; the differentiating double-NAT layer is not.",
        "Post-quantum status records the provider's documented rollout, not an independent protocol assessment."
      ]
    },
    {
      "id": "nordvpn-nordwhisper",
      "provider": "NordVPN",
      "technology": "NordWhisper",
      "classification": "Tunnel protocol",
      "technicalBase": "Proprietary web-tunnel design",
      "sourceStatus": "Closed",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "Linux",
        "Android"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The public technical detail is insufficient for independent implementation or cryptographic review.",
        "The encoded platform list is conservative and reflects explicitly sourced launch coverage."
      ]
    },
    {
      "id": "privatevpn-stealthvpn",
      "provider": "PrivateVPN",
      "technology": "StealthVPN",
      "classification": "Provider protocol stack",
      "technicalBase": "OpenVPN; Shadowsocks",
      "sourceStatus": "Base protocol only",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Limited rollout",
      "platforms": [
        "Windows"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "Only the Windows setup is encoded from the current source.",
        "Open component projects do not make the provider's complete deployment fully open."
      ]
    },
    {
      "id": "proton-stealth",
      "provider": "Proton VPN",
      "technology": "Stealth",
      "classification": "Provider protocol variant",
      "technicalBase": "WireGuard",
      "sourceStatus": "Partial public source",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Android",
        "iOS"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The source-status classification is partial, not full.",
        "No public dedicated protocol audit was found; application-level audits should be described separately."
      ]
    },
    {
      "id": "surfshark-dausos",
      "provider": "Surfshark",
      "technology": "Dausos",
      "classification": "Tunnel protocol",
      "technicalBase": "Custom Dausos tunnel; TLS 1.3-derived handshake",
      "sourceStatus": "Closed",
      "assessmentStatus": "Dedicated public assessment",
      "rollout": "Beta",
      "platforms": [
        "macOS"
      ],
      "purposes": [
        "General performance",
        "Transport reliability",
        "Post-quantum related",
        "Restricted networks"
      ],
      "postQuantumStatus": "In production",
      "lastVerified": "2026-07-13",
      "caveats": [
        "Beta status and platform coverage can change quickly.",
        "The public audit document is only a management summary and omits detailed tickets and the exact severity distribution.",
        "A formal public specification and threat model were not available at verification time."
      ]
    },
    {
      "id": "tunnelbear-ghostbear",
      "provider": "TunnelBear",
      "technology": "GhostBear",
      "classification": "Obfuscation transport",
      "technicalBase": "TunnelBear VPN tunnel",
      "sourceStatus": "Closed",
      "assessmentStatus": "Related public assessment",
      "rollout": "Limited rollout",
      "platforms": [
        "Windows",
        "macOS",
        "Android"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention"
      ],
      "postQuantumStatus": "Not applicable",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The 2024 Cure53 report is related evidence, not a dedicated GhostBear design audit.",
        "Platform support is version-sensitive.",
        "GhostBear is an obfuscation layer rather than a separate cryptographic tunnel."
      ]
    },
    {
      "id": "vyprvpn-chameleon",
      "provider": "VyprVPN",
      "technology": "Chameleon",
      "classification": "Provider protocol variant",
      "technicalBase": "OpenVPN",
      "sourceStatus": "Base protocol only",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Android",
        "iOS",
        "Router"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "Only the OpenVPN base is public.",
        "Provider anti-censorship claims are not a substitute for a public dedicated assessment."
      ]
    },
    {
      "id": "windscribe-stealth",
      "provider": "Windscribe",
      "technology": "Stealth",
      "classification": "Provider protocol stack",
      "technicalBase": "OpenVPN; stunnel",
      "sourceStatus": "Base protocol only",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Linux",
        "Android",
        "iOS"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "Open component projects do not make the full provider deployment fully open.",
        "It is a composed transport stack rather than a new VPN cryptographic protocol."
      ]
    },
    {
      "id": "windscribe-wstunnel",
      "provider": "Windscribe",
      "technology": "WStunnel",
      "classification": "Provider protocol stack",
      "technicalBase": "OpenVPN; WebSocket tunnel",
      "sourceStatus": "Base protocol only",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Windows",
        "macOS",
        "Linux",
        "Android",
        "iOS"
      ],
      "purposes": [
        "Restricted networks",
        "Censorship circumvention"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The support-article date is not treated as the original launch date.",
        "WStunnel is a transport composition, not a separate VPN cryptographic protocol."
      ]
    },
    {
      "id": "xvpn-everest",
      "provider": "X-VPN",
      "technology": "Everest",
      "classification": "Tunnel protocol",
      "technicalBase": "Proprietary Everest tunnel family",
      "sourceStatus": "Closed",
      "assessmentStatus": "No public protocol audit located",
      "rollout": "Generally available",
      "platforms": [
        "Unknown"
      ],
      "purposes": [
        "Restricted networks",
        "General performance",
        "Transport reliability"
      ],
      "postQuantumStatus": "None documented",
      "lastVerified": "2026-07-13",
      "caveats": [
        "The public documentation is sparse and many technical claims remain provider descriptions.",
        "Current platform-specific mode coverage requires further first-party evidence."
      ]
    }
  ]
}
