Privacy products ask for trust. STACK examines what that trust is built on.
VPNs, privacy tools, and security products make unusually difficult promises.
They ask you to trust that they collect less data, protect more of it, secure their infrastructure properly, respond well when things go wrong, and operate the way their marketing says they do.
Most of that is hard for an ordinary user to verify.
That is where STACK comes in.
STACK is an independent research publication focused on the systems behind privacy and security products. We look beyond feature lists, star ratings, and marketing claims to examine the evidence underneath them.
Our goal is simple:
Help people make better privacy and security decisions by showing what the evidence actually supports, and what it doesn’t.
What STACK investigates
We approach products from several different directions because no single test can tell you whether a service deserves your trust.
Our research includes questions such as:
- Who owns and controls the company?
- What information does the service collect?
- How is user data linked to accounts, payments, or devices?
- What does the technical architecture expose or protect?
- What security controls are actually documented?
- What have independent audits and assessments examined?
- What happens when systems fail?
- Which features are genuinely available, and on which platforms?
- What does the product cost now, and what changes later?
- Which users are likely to benefit from it?
- Where are the important trade-offs?
- What remains unverified?
That research feeds several types of investigations, including:
- Who Owns X
- Is X Private?
- Is X Safe?
- X Features
- Is X Worth It?
- X Alternatives
- X vs Y
- X Review
Each asks a different question.
We do not assume that evidence supporting one automatically answers another.
A security audit does not necessarily prove a privacy claim. Corporate ownership does not automatically establish operational control. A feature appearing on one platform does not mean it works identically everywhere.
Those distinctions matter.
Research first, recommendation second
STACK does not begin an investigation by deciding which product should win.
We begin with the evidence.
That means separating:
- documented facts;
- company statements;
- independent verification;
- historical evidence;
- conflicting evidence;
- unresolved questions.
Only after that record is built and challenged do we interpret what it means for the reader.
- Sometimes the evidence supports a clear answer.
- Sometimes the answer is conditional.
- Sometimes the most important finding is that a claim cannot currently be verified.
We would rather preserve that uncertainty than manufacture certainty for the sake of a cleaner verdict.
We look below the feature list
Features matter.
But privacy and security products are ultimately systems.
A VPN can have hundreds of servers and dozens of settings while still leaving important questions unanswered about ownership, logging, infrastructure, access controls, incident response, payment data, or verification.
That is why STACK looks at what we call trust architecture: the combination of technical, operational, organizational, and evidential structures that determine what a user is actually being asked to trust.
That can include:
Privacy architecture
What information exists, where it exists, how long it persists, and how easily it can be connected back to a person.
Security architecture
How systems are designed to resist compromise, contain failures, protect credentials, and reduce the damage when something goes wrong.
Operational architecture
How infrastructure is administered, how privileged access is controlled, how third parties are involved, and how the service operates outside ideal conditions.
Ownership and governance
Who owns the business, who controls it, which legal entities operate the service, and how clearly those relationships can be established.
Verification
Whether important claims are supported by audits, technical documentation, corporate records, independent assessments, or other evidence, and exactly what those sources do and do not prove.
Provider claims are not the same as independent evidence
Companies are legitimate sources of information about their own products.
But a company stating that something is true is not the same as that claim being independently verified.
STACK keeps those categories separate. The same principle applies to audits.
An audit can be valuable evidence, but its meaning depends on:
- what was examined;
- which systems or versions were in scope;
- when the work occurred;
- what was excluded;
- what evidence the auditor had access to;
- what findings were made;
- whether remediation was independently confirmed.
We do not treat the existence of an audit badge as proof of everything a company says.
We do not hide the difficult parts
Research rarely produces a perfectly clean record.
- Sources disagree.
- ]Documentation becomes outdated.
- Companies change ownership.
- Product features move between plans.
- Audits cover only part of a system.
- Independent tests produce conflicting results.
- Public evidence sometimes stops before the question is fully answered.
When that happens, STACK keeps the uncertainty visible.
You may see conclusions such as:
- independently verified;
- provider-stated;
- supported but bounded;
- conflicting;
- historically established;
- unresolved.
Those distinctions are deliberate. They are part of the answer.
Search does not decide the conclusion
STACK publishes for people who are actively trying to make a decision, so search intent matters.
But it affects how an investigation is organized, not what the evidence is allowed to say. We do not choose a verdict because it creates a cleaner headline. We do not require every comparison to produce one universal winner.
And we do not turn incomplete evidence into certainty simply because a reader searched for a yes-or-no answer.
Commercial relationships do not control the research
STACK may earn revenue from some products or services discussed on the site.
That does not determine:
- which companies we investigate;
- which evidence we include;
- which problems we surface;
- which product wins a comparison;
- whether we recommend a service;
- whether we publish a negative finding.
Some companies covered by STACK may have no commercial relationship with us at all.
You can read more in our Affiliate / Commercial Disclosure.
Corrections and changing evidence
Privacy and security products change.
Prices change. Features disappear. Ownership structures change. New audits are published. Incidents happen. Documentation is revised.
We therefore distinguish between:
- corrections, where something we published was wrong;
- updates, where the underlying reality changed after publication;
- clarifications, where wording needs to be made more precise.
Material changes are reflected in our coverage rather than silently ignored.
Read more in Corrections & Updates.
Why STACK exists
The internet does not need another page telling you that a VPN has “military-grade encryption,” thousands of servers, and a 30-day money-back guarantee.
- Those facts may be relevant.
- They are rarely the whole decision.
The harder questions are underneath them:
- Who are you trusting?
- What information exists?
- What happens when something fails?
- Who can access the system?
- What has actually been verified?
- What remains uncertain?
And do the product’s real strengths and limitations fit what you are trying to do?
That is the layer STACK is built to investigate.
Privacy is the promise. Trust architecture is the test.