ExpressVPN Review (2026): How Much Does 28 Audits Really Prove?


ExpressVPN looks like an easy VPN to review. It has current pricing, broad platform coverage, strong performance in specific configurations, and current independent testing behind ordinary use cases like streaming and torrenting. On paper, that covers most of what a review needs to answer.

The harder question starts once you look at what actually stands behind the trust claims that come with those capabilities. ExpressVPN has a substantial independent-assurance record. The provider lists 28 named engagements across its infrastructure, protocol, and apps. It has also disclosed a privacy-relevant Windows routing defect that sat in released software for roughly 21 months before anyone outside the company found it, while that same assurance program was running.

Both facts are true at once, and neither one cancels the other. Working out how they fit together is what actually determines whether ExpressVPN deserves your trust, not just your subscription.

Quick verdict

ExpressVPN is a competent, currently functioning VPN with a genuinely substantial independent assurance record behind it. On Windows, using Lightway Turbo, it’s also a fast one.

It isn’t infallible. A real defect went undetected for close to two years. Several things about the product, including continuous fleet-wide conformity, privileged internal access, exact beneficial ownership, and how cleanly its newer bundled tools are separated from the VPN itself, remain outside what any audit has actually confirmed.

For readers who want mainstream VPN capability, strong Windows performance, and broad platform support, and who are satisfied by a large, repeated, and transparently disclosed assurance record, failure included, the evidence supports choosing ExpressVPN.

For readers who need VPN-tunnel port forwarding, full acceleration outside Windows, complete cross-platform feature parity, or independent proof of continuous system-level controls, it currently falls short. Not because the product is bad, but because that proof doesn’t yet exist in public.

The rest of this review is the evidence behind that split verdict.

VPN metrics at a glance

MetricCurrent finding
Starting priceBasic: $83.72 upfront for 28 months (≈$2.99/mo equivalent)
RenewalBasic $99.95/yr, Advanced $119.95/yr, Pro $199.95/yr
Refund / trial30-day money-back guarantee on direct, first-time purchases; app-store purchases follow separate terms
Devices10 (Basic), 12 (Advanced), 14 (Pro) simultaneous connections
Locations214+ selectable locations across 113 countries (provider-published; some locations are virtually hosted)
PlatformsWindows, macOS, Linux, Android, iOS, Apple TV/tvOS, Android TV/Fire TV, browser extension, router/Aircove
ProtocolsLightway (standard and Windows-only Turbo), WireGuard and OpenVPN where documented
PerformanceProtocol- and platform-specific; strongest on Windows with Lightway Turbo (independent lab testing, not STACK-conducted)
StreamingNetflix, Disney+, BBC iPlayer, and named regional services succeed in current independent testing; Amazon fails; some libraries need a server switch
P2PSupported network-wide in current independent testing; no data cap; no explicit first-party all-server policy located
Split tunnelingApp-based on Windows, macOS, Linux, Android; IP-address exclusion only, staged rollout, on iOS
Dedicated IP29 locations, Lightway-only, fixed for the term; included in Pro, paid add-on on Basic/Advanced
Support24/7 live chat

These numbers orient you. They don’t decide the verdict. That takes the rest of the page.

What you actually get

The VPN itself is built around TrustedServer, ExpressVPN’s RAM-only server architecture, and Lightway, its open-source protocol. That core ships across every major platform, plus router and browser routes.

Around that core, the product has grown into a tiered suite. Basic, Advanced, and Express Pro now sit around a widening set of adjacent tools: Keys, MailGuard, Identity Defender, ExpressAI, and eSIM benefits, each gated by tier, term, and region.

Commercial bundling isn’t the same as technical integration. The evidence doesn’t establish that these adjacent tools share infrastructure with the VPN, and it doesn’t establish that they don’t. That distinction stays open rather than resolved in either direction. What’s clear is that the VPN remains the part of ExpressVPN with a real, documented evidence trail behind it. The public evidence record for those adjacent products is thinner.

Fast, but not evenly

Independent testing gives ExpressVPN a genuinely strong speed result, on one specific configuration.

TechRadar’s current lab testing recorded 1,177 Mbps locally and 1,117 Mbps to the US using Lightway Turbo on Windows. In the same review, ordinary Lightway managed 428 Mbps locally and 265 Mbps to the US: still workable, but a different result entirely. Comparitech’s single home-broadband test found a smaller but still strong Turbo result of 155 Mbps down and 137 Mbps up. WireGuard and OpenVPN, tested in the same TechRadar lab, landed closer to Turbo’s range.

The pattern is clear. ExpressVPN’s headline speed belongs to Windows running Turbo. It doesn’t transfer to macOS, Linux, Android, or iOS, because Turbo is Windows-only. It doesn’t transfer to Windows users who need split tunneling either, since Turbo isn’t compatible with some split-tunneling configurations. No complete cross-platform speed matrix currently exists in the public record.

That asymmetry turns out to matter beyond speed. It’s the first sign of something true across the whole product: capability here isn’t uniform. It depends on which platform you’re actually using.

Capability is not one thing

Split tunneling makes the platform gap concrete.

On Windows, macOS (11 and later), and Linux, split tunneling works by selecting apps. On iOS, it’s a different feature entirely: a staged, IP-address exclusion model, not app-level selection, and its rollout isn’t established as universal yet. A Windows user and an iOS user asking whether ExpressVPN supports split tunneling are really asking two different questions.

The browser extension carries its own split. Remote Control Mode operates the full desktop VPN, while Proxy Mode protects only browser traffic. The two aren’t interchangeable.

Dedicated IP has its own boundary. It’s available in 29 locations, works only over Lightway, and is fixed for the length of your term, useful if your needs sit inside those constraints, less useful if they don’t.

One boundary applies everywhere, on every tier: ExpressVPN doesn’t support port forwarding through the VPN tunnel. Router-local forwarding exists, but it sits outside VPN protection entirely. If you need inbound connectivity through the tunnel itself, this rules ExpressVPN out regardless of which tier you buy.

None of these boundaries automatically make ExpressVPN a poor fit. They do mean that whether a feature is genuinely useful depends on the platform and implementation the reader actually needs, and it’s worth checking against your specific platform before you buy.

What ExpressVPN documents about a feature and how that feature behaves against a real streaming service or a real torrent swarm aren’t the same thing. The split-tunneling and port-forwarding boundaries above come from specifications. The next question is what happens when those documented capabilities actually meet the services people use them for.

Streaming and P2P: what current testing actually shows

Current independent testing, from TechRadar and Comparitech, both in 2026, found ExpressVPN successfully accessing Netflix across several regions, Disney+, BBC iPlayer, and named regional services like ITV, Channel 4, and TVNZ.

It also found real failures. Amazon US/UK failed in TechRadar’s current testing. YouTube’s geo-lock initially failed and only succeeded after switching servers. Comparitech noted that some libraries, including Australia and Japan, sometimes needed several server attempts before Netflix worked.

Both halves of that are real evidence, not just the wins. Current independent testing recorded successful access to several major streaming services. It doesn’t show universal compatibility, and treating occasional retries or Amazon’s failure as noise would misrepresent what was actually found.

P2P evidence is similarly bounded, in a different way. Independent specialist testing reports torrenting availability across all servers, and ExpressVPN’s no-data-cap policy supports sustained network use. No explicit first-party policy guaranteeing P2P support on every server was located, so this rests on independent observation and a supportive, but not identical, first-party signal.

Speed, platform behavior, streaming, P2P: all of it is something you or an independent tester can watch happen. Privacy works differently. Most of what a provider does with your data happens somewhere you can’t watch at all.

Privacy: what “no logs” actually covers

“No logs” is the headline. It’s also only the first layer of what ExpressVPN’s privacy relationship with you actually involves.

The base claim: ExpressVPN says it doesn’t collect browsing activity, traffic destinations, DNS queries, source IP, exact connection times, or your outgoing server IP. That’s provider policy, corroborated by inherited, scope-bounded independent assurance, not something independently verified as a continuous, whole-fleet condition today.

Above that sits usage data ExpressVPN does say it collects: connection date, which location you chose, your originating country and ISP, aggregate data transferred, and your app version. Separately, optional diagnostic telemetry, crash reports and speed-test data, is described as largely opt-in.

The most consequential recent change is marketing-attribution telemetry through AppsFlyer. ExpressVPN now explicitly discloses the fields involved: a country code derived from a hashed IP, OS version, device language, app version, device model, randomized installation and user IDs, and consent-gated advertising IDs. It also describes a mitigation: routing AppsFlyer-bound traffic through dedicated ExpressVPN IPs to obscure which server you’re actually using. That disclosure is a real improvement over the vague “some SDK” framing providers often use. The mitigation itself hasn’t been independently verified.

ExpressVPN’s account and payment relationship includes email and processors such as PayPal, BitPay, Paymentwall, and Stripe. Crypto payment options exist; they don’t, on their own, establish anonymity.

Identity Defender is described in policy as using separately supplied data, never associated with VPN-service data. Whether that separation actually holds at the technical or backend level isn’t independently established either way.

Put together, the no-logs claim rests on policy plus bounded independent assurance. The newer disclosures, AppsFlyer’s mitigation and Identity Defender’s separation, rest on provider assertion alone, for now. To understand what’s actually backing any of this, it helps to look at the infrastructure that’s supposed to make these claims true in practice.

Security architecture: what has actually been tested

Here, ExpressVPN’s evidence record is genuinely substantial.

TrustedServer’s RAM-only, standardized deployment model has been assessed by PwC, Cure53, and KPMG, each within defined scopes. Lightway’s core code is open source, and has undergone repeated Cure53 and Praetorian assessments across specific commits and dates. The browser extension received its own dedicated Cure53 engagement in 2024.

These aren’t single, point-in-time claims. They’re real, scoped, and repeated over time. That should count for something, and it does.

What this record doesn’t establish is continuity. Public evidence remains incomplete on who has administrative access to the live infrastructure, how privileged actions are monitored, how the network is segmented, and, critically, whether the production fleet running right now still matches what was audited at some earlier point.

That gap between an audited architecture and the live system today sounds abstract. It isn’t. There’s a real, documented example of exactly what it means.

The DNS defect: where the assurance program’s limits became visible

CVE-2024-25728 is a Windows split-tunneling DNS-routing defect. Under the “Only allow selected apps to use the VPN” mode, with a smaller edge case affecting under an estimated 0.5% of that subgroup, DNS queries could route to third-party DNS instead of ExpressVPN’s own. Visited domains could be exposed, even while the rest of your traffic stayed encrypted.

The defect existed in released software from 19 May 2022 to 7 February 2024. That’s roughly 21 months.

It was found externally, then investigated and fixed by ExpressVPN. A targeted independent assessment supports the fix within its scope.

Here’s what that timeline means. The assurance program described in the previous section, TrustedServer’s audits and Lightway’s repeated assessments, existed throughout those 21 months. It didn’t catch this. That isn’t proof the audits were worthless; most of them assess different systems entirely, unrelated to this specific defect class. It’s also not something the fix erases. A privacy-relevant defect, in a routing path that matters, going undetected for close to two years by the monitoring environment that existed at the time, is real evidence about how much confidence continuous, in-production assurance deserves. It’s a lower amount than the confidence the scoped, point-in-time engagements themselves have earned.

The audit record is real and substantial. It also didn’t catch this. Both things stay true at once, and from here, it’s worth going back to that 28-engagement figure with a sharper question than most reviews ask.

What “28 audits” actually means

ExpressVPN’s Trust Center lists 28 assurance engagements. That’s a real, publicly documented number.

It is not 28 equivalent whole-system, no-logs audits. The engagements span different products, different systems, different dates, and different assurance types. Each one is bounded by its own scope, its own commit, its own point in time.

That’s a substantial documented record in its own right, and it should be credited as such. But the weight of that evidence stops exactly where the DNS defect showed the boundary sits. Continuous live-fleet conformity, who has privileged access and how it’s controlled, the AppsFlyer implementation, exact processor configuration, and how cleanly the VPN’s backend is separated from products like Identity Defender all fall outside any listed engagement. They remain unresolved, not assumed safe.

One more historical data point belongs here: a Turkish server seizure, in which no sought logs were reportedly recovered. It’s a real, narrow corroboration of the no-logs claim in that one instance. It isn’t permanent or general proof, and shouldn’t be read as more than what it is.

What’s been technically tested, and what falls outside that testing, is now on the table. One remaining question isn’t something any engagement could have answered in the first place: who actually controls the company running all of this.

Ownership: what’s established, what isn’t

ExpressVPN is contracted through Express Technologies Ltd., operating within the Kape group. Kape was taken private through the Unikmind transaction in 2023. That much is well supported.

What isn’t established is detailed beneficial or voting control beyond the Kape/Unikmind structure, and how operationally separate ExpressVPN actually is from other entities under the same ownership umbrella, whether that means shared services, shared infrastructure, or shared staff.

Historical context around Project Raven and Daniel Gericke belongs to ExpressVPN’s corporate history. Nothing in the current evidence supports extending that history into any claim about current technical access, compromise, or misuse, and this review doesn’t make that leap. “Who Owns ExpressVPN” covers the fuller corporate history for readers who want it.

That closes the last open question about what stands behind the product. What’s left is what it costs.

Commercial structure: what you’re actually paying for

With the product and its trust profile established, the pricing structure means something more specific than a number on a checkout page.

Basic starts at $83.72 for 28 months, renewing annually at $99.95. Advanced and Pro carry proportionally higher pricing at both stages. That renewal jump is a real, long-term cost commitment, not just a monthly-equivalent figure designed to look small on a landing page.

The tiers mostly change device allowance (10, 12, or 14 simultaneous connections) and access to the adjacent products and Dedicated IP. They don’t change the underlying VPN protocol or server access. Pro includes Dedicated IP by default; Basic and Advanced can add it separately.

This matters because of everything established above. A higher tier buys more devices and more bundled tools, not a differently verified VPN core. The trust picture built across this review, the strong-but-scoped audit record and the unresolved continuous-assurance questions, applies identically at every tier. Whether the added products (Keys, MailGuard, Identity Defender, ExpressAI, eSIM) are worth paying for depends entirely on whether you’ll actually use them; the evidence doesn’t support treating them as strengthening the VPN itself. What happens to adjacent-product data if you downgrade or cancel remains an open question rather than one it’s safe to assume is handled well.

None of that price means much on its own. What it buys only makes sense against what a specific reader actually needs, which is the last thing left to work out.

Who this fits, and who it doesn’t

Windows users who prioritize speed. Requirement: highest available throughput. Evidence: Turbo produced the highest cited throughput in current independent testing. Boundary: Turbo isn’t compatible with some split-tunneling setups, and it doesn’t exist off Windows. Resulting fit: strong, unless split tunneling or a non-Windows platform is also required.

Multi-platform users who need consistent routing features. Requirement: the same feature set everywhere. Evidence: Windows, macOS, and Linux carry real split tunneling; iOS carries a narrower, staged version. Boundary: TV, router, browser, and Dedicated-IP parity across platforms isn’t fully established. Resulting fit: partial, breaking down if full cross-platform parity, especially on iOS, is a requirement rather than a preference.

Mainstream streaming users. Requirement: access to major streaming services. Evidence: current independent testing recorded successful access to Netflix, Disney+, BBC iPlayer, and named regional services. Boundary: Amazon currently fails, and some libraries need retries. Resulting fit: generally strong, unless Amazon specifically or zero-retry consistency is the requirement.

P2P and torrenting users. Requirement: network-wide torrenting without a data cap. Evidence: supported by current independent testing and a no-cap policy. Boundary: no VPN-tunnel port forwarding on any tier. Resulting fit: strong for outbound P2P use, ruled out if inbound connectivity through the tunnel is required.

Users who need a fixed Dedicated IP. Requirement: a stable, dedicated address. Evidence: supported inside 29 listed locations, over Lightway only. Boundary: no flexibility to change location or protocol mid-term. Resulting fit: strong, inside those constraints.

Users with a high, evidence-first trust threshold. Requirement: proof of continuous fleet conformity, privileged-access control, or independently verified separation between the VPN and its adjacent products. Evidence: not currently available in the public record. Resulting fit: not currently supported. This is the clearest case for looking elsewhere, or at least holding a lower level of confidence than the audit count alone might suggest.

Users who want one provider for VPN plus adjacent privacy tools. Requirement: convenience of a single provider. Evidence: commercially available, and clearly the direction ExpressVPN is heading. Boundary: the evidence doesn’t establish that these tools are deeply integrated or independently effective. Resulting fit: depends entirely on valuing that convenience, not on any demonstrated technical advantage.

Conclusion

ExpressVPN doesn’t earn a single, unconditional verdict, because the evidence itself isn’t unconditional. It’s strong in the areas that have actually been tested, and explicitly open in the areas that haven’t.

For readers whose priorities are mainstream VPN capability, broad platform support, Windows performance, and streaming or P2P access, and whose trust threshold is met by a large, repeated, and transparently disclosed assurance record, failure included, the evidence supports choosing ExpressVPN.

For readers who need VPN-tunnel port forwarding, full non-Windows acceleration, complete cross-platform parity, or independent proof of continuous system-level and cross-product controls, the current public record doesn’t clear that bar. It’s simply where ExpressVPN currently sits.

The STACK View

Two products are hiding inside every VPN review: the thing that was tested, and the thing you’re actually trusting.

ExpressVPN’s testing record is real. Twenty-eight named engagements, repeated assessments of Lightway and TrustedServer, a dedicated audit of the browser extension: that’s a substantial documented assurance record. What it isn’t, and what no amount of additional engagements would automatically become, is proof that the system running today matches what was assessed at any given point in the past. The DNS defect didn’t expose a company that lied about its testing. It exposed the gap that exists between testing something and knowing it stays true afterward.

That distinction changes how ExpressVPN’s assurance record should be read. A large inventory of assessments can materially strengthen confidence without proving that every live system, configuration, and operational control continuously matches what was tested. What that record does not answer is what happens in production after the assessed scope and point in time.

What this review actually asked you to decide isn’t whether ExpressVPN is good. On the evidence, it plainly is, within real boundaries. It asked how much unverified trust you’re willing to extend past the point where the documentation runs out, and that answer is yours to set, not ExpressVPN’s, and not ours.

FAQs

Is ExpressVPN safe to use? Its infrastructure and protocol have undergone substantial, repeated independent assessment. Continuous, live-fleet conformity and privileged-access controls remain outside what any audit has confirmed.

Does ExpressVPN keep logs? ExpressVPN’s no-logs policy covers browsing activity, traffic destinations, and DNS queries, and is corroborated by bounded independent assurance. It does collect some connection and usage data, and marketing-attribution telemetry, both disclosed separately in its privacy policy.

Is ExpressVPN fast? On Windows using Lightway Turbo, current independent testing shows very strong speeds. Off Windows, or without Turbo, results are meaningfully lower and less thoroughly tested.

Does ExpressVPN work with Netflix? Yes, across several regions in current independent testing, along with Disney+ and BBC iPlayer. Amazon currently fails, and some libraries occasionally need a server switch.

Can I use ExpressVPN for torrenting? Current independent testing reports P2P support across all servers, backed by a no-data-cap policy. There’s no explicit first-party policy guaranteeing this on every server.

Does ExpressVPN support port forwarding? No, not through the VPN tunnel, on any tier. Router-local forwarding exists but sits outside VPN protection.

Who owns ExpressVPN? Express Technologies Ltd., within the Kape group, which was taken private via the Unikmind transaction in 2023. See “Who Owns ExpressVPN” for the full ownership history.

Is ExpressVPN worth the price? Higher tiers mainly add device allowance and access to bundled tools; they don’t buy a differently verified VPN core. Whether it’s worth it depends on how many devices you need and whether you’ll actually use the adjacent products.

What happened with the ExpressVPN DNS vulnerability? A Windows split-tunneling defect (CVE-2024-25728) allowed DNS queries to bypass ExpressVPN’s own DNS under specific conditions, for roughly 21 months, before being found and fixed. An independent assessment supports the fix within its scope.