Why People Say to Avoid NordVPN
We put NordVPN first on most of our lists, and we earn a commission when you buy through us. That is exactly why this page exists: if the criticism is fair, you should read it here rather than find it later.
We may earn a commission when you buy through our links, at no extra cost to you. How we fund this site
The short answer
Nothing we found makes NordVPN unsafe to use. Two things are worth knowing before you buy: there is no port forwarding, and the renewal price is well above the advertised one. If your threat model involves a government rather than an advertiser, the closed-source apps and the European staff base are reasons to look at Mullvad or Proton VPN instead.
Every criticism, weighed
Each point below links to where it comes from. We include the ones that do not hold up, because you will meet them anyway.
No port forwarding
FairThe claim
NordVPN does not offer port forwarding on any server, which slows down torrenting on poorly seeded files and blocks remote access to a home network.
Our read
True, and it matters if you seed. NordVPN presents it as a deliberate security decision — open ports are an attack surface — which is a defensible position, but it does not change the outcome for you. Proton VPN and Private Internet Access do offer it.
The renewal price is much higher than the first term
FairThe claim
The advertised price applies to the first subscription period only. After that it renews at a considerably higher rate, and complaints about automatic renewal are common.
Our read
This is normal across the industry, but that does not make it harmless: the price you compare on any review site — ours included — is the introductory one. Check what the second term costs before you commit, and set a reminder before it renews.
Panama on paper, Europe in practice
True, with contextThe claim
NordVPN markets its Panama incorporation as being outside intelligence-sharing alliances, while the team largely works from Lithuania and the Netherlands — the latter a 9 Eyes member.
Our read
Both halves are true, and PCWorld calls the concern fair. Whether it matters depends on your threat model: incorporation determines which courts can compel data, staff location does not. If your threat model includes a state actor, this is a reason to look at Mullvad or Proton instead.
The 2018 server breach was disclosed late
True, with contextThe claim
An unauthorised party reached a single rented server in Finland in March 2018. NordVPN did not disclose it publicly until late 2019.
Our read
The breach itself was limited — one rented server, no user credentials taken, and it led to the move to RAM-only servers. The delay is the real problem: a company whose product is trust took over a year to tell its users. That is a fact about its behaviour, not about its encryption.
The apps are not open source
True, with contextThe claim
Privacy-focused communities do not recommend NordVPN because its clients are proprietary, so the code cannot be independently inspected.
Our read
Correct as a fact. Whether it disqualifies NordVPN depends on what you want: audits by a third party are a weaker guarantee than open code, but they are not nothing. Mullvad and Proton VPN publish their clients; if that is your bar, they are the shortlist.
The Tesonet and Oxylabs connection
Not supportedThe claim
NordVPN's founders are also listed as founders of Tesonet, which owns the web-scraping company Oxylabs. The claim is that user traffic feeds a data-harvesting business.
Our read
The shared founders are real; the data-sharing is not. PCWorld examined the claim and found that no link has been demonstrated. We list it because you will run into it, not because it holds up.
What is genuinely good
A page that only lists complaints is not an assessment. These are the reasons NordVPN still leads most of our lists.
Repeatedly audited
The no-logs policy has been checked by external firms more than once, most recently by Deloitte. That is a stronger position than most providers can show.
RAM-only servers
Servers run from memory, so a seized machine holds nothing after a reboot. This came out of the 2018 incident — a criticism that led to a real change.
It is genuinely fast
The NordLynx protocol is consistently near the top in independent speed testing, which is why it still leads most of our own lists.
If one of these is a dealbreaker
ProtonVPN
Open-source apps, Swiss jurisdiction, and port forwarding. The usual choice when the closed-source objection matters to you.
Mullvad VPN
No account, no email, flat pricing with no renewal jump, and open-source clients. The strictest option on this list.
Frequently asked questions
Frequently Asked Questions
Sources
Every point above links to where it came from. Read on 25 July 2026.