0kyc.io
Independent · continuously verified

No-KYC VPNs

Privacy VPNs judged on what actually protects you: an independently audited no-logs policy, the jurisdiction they answer to, and whether you can sign up and pay anonymously. Marketing claims don't move the grade — audits and structure do.

46
services tracked
24
independently verified
46
live right now
1 hour
since last check
Green = we confirmed it. Amber = we couldn't yet. A service marked unverified isn't necessarily bad — it just hasn't passed our checks, and we won't dress that up as a fact. That distinction is the whole point.
9 services · 7 verified this page / 2 unverified
IVPN logo
IVPN vpn
Anonymous account, no email required · Monero and cash accepted, Cure53-audited, open-source · Gibraltar jurisdiction, refuses all requests originating outside it
A
4.5/5
live
verified no-KYC open source no-JS
based in Gibraltar from $6/mo no-logs audited
Details
ProtonVPN logo
ProtonVPN vpn
Swiss-based, fully open-source · 5 consecutive Securitum audits · 458 Swiss court orders received since 2017, all 458 denied for lack of logs
B
4.2/5
live
verified open source
based in Switzerland from $3.42/mo no-logs audited
Details
Mullvad logo
Mullvad vpn
No email, cash or Monero accepted · numbered account, audited, RAM-only servers · Swedish jurisdiction, data never leaves the EEA
B
4.2/5
live
verified no-KYC open source no-JS tor
based in Sweden from $5.71/mo no-logs audited
Details
NymVPN logo
NymVPN vpn
Decentralized mixnet plus dVPN in one app · zk-nym credentials unlink payment from usage even when you pay by card, Cure53-audited, Swiss company · but no WireGuard config export, no split tunnelling, and users report unstable connections
B
3.9/5
live
verified no-KYC open source
based in Switzerland from $12/mo no-logs audited
Details
Xeovo logo
Xeovo vpn
Finnish self-funded VPN and stealth proxy provider · optional email, cash and Monero accepted, onion site, DPI-resistant protocols for censored countries · no logs of IPs, traffic, timestamps or DNS — but closed source and never independently audited
B
3.6/5
live
verified no-KYC no-JS tor
based in Finland from $4/mo
Details
AirVPN logo
AirVPN vpn
Run by hacktivists since 2010 · Monero direct, no email required, Tor onion, port forwarding · EU jurisdiction, refuses extra-EU legal competence — but no independent audit
B
3.6/5
live
verified no-KYC tor
based in Italy from $7.99/mo
Details
IPVanish logo
IPVanish vpn
Unlimited devices, audited no-logs (Leviathan 2022, Schellman 2025) — but US jurisdiction, subscription IP retained, and a 2016 case where connection logs were handed to Homeland Security
C
3.5/5
live
verified shares data
based in United States from $2.19/mo no-logs audited
Details
Cryptostorm logo
Token-based VPN with no accounts, no email and no KYC · nodes only ever see a SHA-512 hash, and the privacy policy publishes the actual auth database schema and node log config · Tor and I2P sites, Monero accepted, DMCA notices ignored
C
3.2/5
live
unverified no-KYC open source no-JS tor i2p
based in United States from $6/mo
Details
PureVPN logo
PureVPN vpn
BVI-registered, 6,500+ servers, KPMG-audited no-logs — but caught logging a user for the FBI in 2017 despite "zero-log" claims, and now runs an opt-in partner network built to keep operational records
E
2.5/5
live
unverified shares data incident
based in British Virgin Islands from $2.15/mo
Details

A no-logs claim is worth exactly what verifies it

Every VPN advertises no logs. The phrase is unregulated and costs nothing to print. What separates a meaningful claim from a slogan is external verification: an independent audit by a named firm with a published report, or a court case where the provider was compelled to hand over data and had none to give.

Both kinds of evidence exist and are checkable. Where neither does, a no-logs claim is a promise from a company you cannot inspect — which may well be honest, but is not the same thing as verified. That distinction drives the grade here more than speed, server count or price.

Jurisdiction is structural, not cosmetic

A provider based in a country with data-retention mandates or intelligence-sharing agreements operates under legal obligations that its privacy policy cannot override. This does not make such a provider dishonest; it means the protection you get depends on law as much as intent, and law changes without asking you.

This is why a jurisdiction ceiling applies in our scoring: a VPN in a Five Eyes country cannot reach the top grades regardless of how good its audit is, because the structural exposure remains. Some readers will judge that too harsh, and the methodology page shows the exact weighting so you can discount it if you disagree.

Signing up without identifying yourself

Anonymous use has two halves and providers often solve only one. A service can accept Monero and still require an email address, or accept a cash payment and tie the account to a persistent identifier. Look for account creation that needs no email, payment in a currency that does not carry your name, and no requirement to install a client that phones home with device identifiers.

Also worth checking: whether the provider actually accepts connections over Tor, and whether it runs RAM-only infrastructure. Neither is decisive on its own, but together they indicate a provider that designed for the threat model it markets to.

What a VPN does not do

A VPN moves the point at which your traffic becomes visible from your ISP to your provider. It does not make you anonymous to sites you log into, does not defeat browser fingerprinting, and does not protect against an adversary who can watch both ends of the connection. Treating it as blanket anonymity leads people to take risks the tool was never going to cover.