# URnetwork vs NordVPN

NordVPN is the biggest and most polished name in consumer VPN; URnetwork
splits the path so the exit never learns who you are and the operator
cannot read the sealed session.

**Choose NordVPN** if you want the steadiest speeds, a no-logs policy
examined six times by outside firms, and the deepest extras list. **Choose
URnetwork** if you want a split path, residential exits aimed at a city,
and an email-free account with a free tier. Both ship post-quantum
protection. NordVPN is more proven. URnetwork splits visibility between
its operator and a member-run provider.

[NordVPN](https://nordvpn.com) is run by Nord Security: founded by
Lithuanians, incorporated in the Netherlands, operated mostly from
Lithuania, and owner of Surfshark since 2022, with the VPN itself under a
Panama company, the jurisdiction its marketing cites. The company was
valued around $3 billion in 2023. The product is fast and polished, built
on its own WireGuard-based NordLynx protocol, with a fleet that is
RAM-only since 2020 by the company's account.

URnetwork uses member-run exits. The provider does not receive your source IP
on the relayed path. Native apps seal traffic to the provider by default.
[How URnetwork works](/docs/overview) explains the full design. The
[threat model](/docs/threat-model) holds the complete record of what is stored
and enforced.

## Six differences that affect the choice

| | NordVPN | URnetwork |
|---|---|---|
| Trust model | One company's server sees your IP and your destinations together; an audited policy not to record them | Two relay parties; the exit never sees your IP, and the operator cannot read the sealed session |
| External verification | Six no-logs assurance engagements (PwC 2018, 2020; Deloitte 2022–2025), plus app security tests | Open client and server code; no independent audit of the protocol or server code |
| Consistency | Large datacenter fleet; steady, high speeds | Member uplinks; URnetwork puts its average streaming speed at 40 Mbps+ |
| Extras | Meshnet, Threat Protection, Double VPN, NordWhisper obfuscation | Ad and tracker blocking; per-app split tunneling on Android and Windows |
| Exit and targeting | Datacenter ranges; 79 advertised locations virtual by Nord's own count; country list with city picks in some countries | Residential member addresses; browse countries, search for a city |
| Account and price | Email required; about $13/month at the monthly rate, multi-year promos that renew higher; no free tier | One-tap account with no email; free daily allowance; Pro $5/month or $40/year |

Caveats below the table:

- Post-quantum is parity: Nord rolled post-quantum protection across its apps
  over 2024–25, and URnetwork's X25519MLKEM768 client-to-provider session is
  default in the native apps, skipping any provider it cannot seal to rather
  than downgrading. The browser extension has no sealed session; there, the
  operator's data path logs nothing, pinned by a test in the open code.
- Both cover Android, iOS, macOS, Windows, and Linux with an explicit kill
  switch; URnetwork adds a browser extension paired with its web app.
  Nord's Linux app is GPLv3; its other apps and all server code are
  closed. Current URnetwork prices are at
  [ur.io/products](https://ur.io/products).
- Nord labels virtual servers inside its apps; the advertising keeps the
  round number.
- A shopping note: Nord's partner program pays up to 100% of a new signup,
  so "best VPN" rankings placed beside coupon codes are mostly affiliate
  pages.

## Counting a fleet

Nord's coverage number teaches how VPN location counts work. Until 2024 it
advertised roughly 60 countries, all physical. Virtual locations (an IP
registered to one country, hardware in another) then arrived quickly: one
India entry in January 2024, about fifty more that March, when the
advertised country count jumped to 111 overnight, and roughly thirty more
in December 2025, which Nord's own blog put at 79 virtual locations in
total. Independent measurement agrees from outside: IPinfo's December 2025
study of some 150,000 exit IPs across 20 providers found 53% of NordVPN's
advertised locations virtual or unverifiable. What remains is still a
large real network, observed at about 57 countries and 100 datacenter
cities, more than most rivals run. The India case shows the shape of it:
Nord removed its physical India servers in 2022 rather than comply with
CERT-In's logging mandate, a decision that cost it something real, and the
India entry that returned in 2024 is virtual.

![Advertised locations vs measured reality — share of advertised locations measured virtual or unmeasurable per provider (IPinfo, December 2025)](/docs-assets/infographic-virtual-locations.svg)

*What an advertised map looks like when it is measured rather than
counted. URnetwork appears as a mechanism rather than a bar.*

URnetwork counts the strict way: a location exists only while a member's
device is online in it, and the platform geolocates the connection it
observes rather than accepting a declared city; an address that looks like
hosting, a VPN, or a re-announced range is demoted in ranking, not
excluded. Nobody has run IPinfo's study on URnetwork, so its counts are
self-published too; the mechanism is the checkable part.

## Six examinations, and the 2018 server incident

Nord's audit cadence leads the category: PwC examined its no-logs claim in
2018 and 2020, and Deloitte has done so annually from late 2022 through
December 2025 (announced February 2026), six engagements in total, plus
separate app security tests by firms including VerSprite and Cure53. An
engagement of this kind is commissioned, scoped by agreement, and examines
the service's configuration at a point in time; the detailed findings are
not published, and the report covers the entity operating NordVPN, not the
rest of the holding. No subpoena or raid has tested the policy the way
Mullvad's 2023 raid or PIA's court record did. The policy itself keeps a
little: account email, billing data, and a session-status timestamp held
for roughly 15 minutes to enforce the device limit.

The dated incident is a lesson in disclosure. Between January and March
2018 an attacker held access to one rented server in Finland through the
datacenter's remote-management account; keys were stolen, and no evidence
of actual traffic interception was found. By Nord's own account the
datacenter told it on April 13, 2019. On October 18, 2019 Nord's marketing
tweeted "Ain't no hacker can steal your online life"; researchers,
provoked, published the stolen keys, and Nord confirmed the incident on
October 21, 2019. The response afterward was real: colocated fully-owned
hardware from October 2020, the RAM-only fleet, a bug bounty. Separately,
a November 2019 credential-stuffing wave hit roughly 2,000 accounts
through passwords reused from other sites' breaches, and the UK's
Advertising Standards Authority has upheld complaints against Nord ads
twice: in 2019, for overstating public-wifi risk, and in 2023, for a
"switch off… malware" claim its filtering could not substantiate.

URnetwork has no incidents on record and no equivalent attestations; its
storage design is enforced in open server code instead, with the record in
the [threat model](/docs/threat-model). On the relayed path the provider
never receives your source IP, and the operator relays a sealed session it
cannot read, so no single party holds both your identity and your
activity.

![Who can see what — single-party VPN vs Apple Private Relay's closed two-party split vs URnetwork's split knowledge](/docs-assets/infographic-who-sees-what.svg)

*One column has a single party holding both facts; the other splits them
between parties that each see less.*

## Meshnet and the extras

The extras list is Nord's clearest win. Meshnet links your own devices
into a private encrypted network across the internet; URnetwork has no
equivalent. Threat Protection filters malware, ads, and trackers at Nord's
service, while URnetwork's equivalent is the on-device "Block ads and
trackers" toggle, off by default. NordWhisper (2025) is an obfuscation
protocol for networks that block VPNs; URnetwork's answer is extenders,
entry hops on independent addresses and believable ports. Double VPN
chains two Nord servers, which is cover against a network observer, not
against Nord, because both hops answer to one company. URnetwork's two
relay parties are different parties; the separation is the design, not an
option inside it.

## Where NordVPN wins

- Consistency: a large datacenter fleet delivers the same throughput every
  session. (When ads say "officially the fastest," the source is a 2020
  comparative test Nord commissioned from AV-TEST; independent reviews
  agree it is fast, but the superlative was self-funded.)
- External attestation: six no-logs engagements and repeated app security
  tests. URnetwork's two 2025 assessments reach neither its protocol nor
  its server code.
- Extras: Meshnet, Threat Protection, NordWhisper, and Double VPN have no
  URnetwork equivalents.
- Polish and maturity across every platform, backed by a large company.

## Where URnetwork wins

- The split. The exit never learns who you are, and the operator cannot
  read the sealed session. No single party holds identity and destinations
  together; Nord's server sees both.
- Residential exit addresses that are not in the datacenter ranges
  websites blocklist. Residential is not the same as undetectable, and
  nobody has measured URnetwork's exits from outside.
- Targeting: search for a specific city, not just a country.
- Account anonymity: a one-tap email-free account backed by a recovery
  seed phrase (URnetwork's own credential; it never asks for a crypto
  wallet's seed phrase or key), wallet-signature sign-in, and on-chain
  USDC payment. NordVPN cannot be used without an email.
- Whole-stack source: client and server code public, versus one GPLv3
  Linux app.
- Pricing shape: $5/month or $40/year flat, with a free daily allowance,
  versus a promo ladder and no free tier.
- A supply side: members can share their connection as participants in the
  [UR protocol](https://ur.xyz). Nord has no equivalent role.

## Limits and evidence

URnetwork's main limits:

- No independent audit covers the protocol, the connect engine, or the
  operator's server code. Two 2025 third-party assessments cover other
  surfaces: a penetration test of the web application and API (April–May
  2025), and the Leviathan MASA AL2 assessment of the Android app, which
  passed. Leviathan writes that its assessment "should not be read as a
  holistic security evaluation or comprehensive penetration test." Neither
  examined logging, retention, or the data path.
- The split assumes the operator and the providers in your window are
  independent. Nothing in the system attests that independence, and no
  outside party has measured the fleet. See the
  [threat model](/docs/threat-model), §6.1.
- The WireGuard-compatible fallback endpoint assigns one stable tunnel
  address, so several providers could recognize the same client across
  sessions. The native tunnel is the recommended path.
- Coverage counts are self-published. Nord's fleet has been measured from
  outside, with the 53% result above; URnetwork's has not been measured at
  all.

NordVPN's limit is structural. Its server terminates your tunnel, so one
position can see your real IP and your destinations together, and
everything after that is policy. The examinations test that policy at
points in time, with findings that stay private, and no court or raid has
tested it. Double VPN adds a hop without adding a second party.

Trying URnetwork costs nothing: the Instant Account takes one tap and no
email, so you can measure real speeds from your own home before paying for
either product. More questions are answered in the [FAQ](/docs/faq).
