Choosing a VPN is a strange purchase. You’re picking the one company that will sit between you and the entire internet, based mostly on their own promises about how little they’ll look.
Every provider says “no logs”. Every provider says “military-grade encryption”. The words are free. What’s not free is the structure behind them, and structure is what you can actually check.
Short answer. Ask five questions: who pays for the servers, what exactly is logged, who independently verified it, who legally operates it, and does the marketing oversell? Structure beats promises every time.
The five questions
1. Who pays for the servers?
The foundational question. A subscription business answers to subscribers. A free product with no paid plan answers to whoever’s actually paying, and that arrangement rarely favors you. The honest free option exists: free tiers of paid VPNs, where Windscribe and Proton VPN are the familiar examples, with real limits and the same privacy policy as paying users.
2. What exactly do they log?
Read the privacy policy for nouns, not adjectives. “We value your privacy” means nothing. “We do not store connection timestamps, IP addresses, or browsing activity” means something. Watch for the quiet exceptions: “except as required for service improvement” is a door wide enough to drive a data warehouse through.
3. Who checked, besides them?
Independent audits turn promises into evidence. The good sign is a named audit firm, a published report, a recent date, and audits repeated over time rather than one from five years ago. No audit doesn’t prove dishonesty, but between two providers, the audited one wins.
4. Who are they, legally?
A named company, a jurisdiction, identifiable people. You’re routing your entire digital life through them; “we’re a passionate team” with no address is not enough. Jurisdiction also decides which governments can compel what, which matters more to some readers than others, but anonymity of the operator is a red flag for everyone.
5. How do they talk?
The meta-signal. A provider that says “we protect your connection, here’s what that does and doesn’t mean” is describing a real product. A provider promising total invisibility is describing a myth, and if they oversell the product, ask what else they oversell. Honest marketing correlates with honest engineering more than any spec sheet.
What you’re actually buying
Keep the scope in view while comparing: a VPN covers your connection, nothing more. The best provider on earth won’t clean your inbox, secure your passwords, or stop what targets your address instead of your IP. Buy the pipe from someone trustworthy, and staff the other layers separately.
Frequently asked questions
Are VPN review sites reliable?
Many earn affiliate commissions from the VPNs they rank, so treat rankings as a starting list, not a verdict. The five structural questions work regardless of who’s ranking.
Is a cheaper VPN worse?
Not inherently. Price doesn’t map to trustworthiness; structure does. A modest subscription with audits and a named company beats an expensive one with neither.
Does server count matter?
Less than the marketing suggests. Thousands of servers matter for speed and region choice, not for privacy. A no-log policy on ten servers protects you more than logging on ten thousand.
Should I pick based on jurisdiction?
It’s one factor of five. A provider with clean logging practices has little to hand over regardless of who asks. Structure first, geography second.
Bottom line
You can’t verify encryption from your couch, but you can verify structure: the business model, the policy’s nouns, the audits, the company, the tone. Five questions, ten minutes, and the field narrows itself. Then enjoy the one thing a good VPN really sells: a pipe you don’t have to think about.