# URnetwork vs Surfshark

Surfshark is the value pick of the mainstream VPNs; URnetwork splits the path
so the exit never learns who you are and the operator cannot read the sealed
session.

**Choose Surfshark** if you want unlimited devices on one plan, steady
datacenter speed, and deep multi-year discounts. **Choose URnetwork** if you
want residential exits, city selection, and a split path. Both run
post-quantum encryption by default and ship a kill switch on every platform.
Surfshark is the cheaper way to cover a household. URnetwork splits visibility
between its operator and a member-run provider.

[Surfshark](https://surfshark.com) is run by Surfshark B.V. in Amsterdam. It
has shared a holding company with NordVPN since February 2022; the merger
announcement said the brands would "operate as autonomous companies relying on
separate infrastructures". Its signature is unlimited simultaneous devices on
one subscription, served by a rented, RAM-only datacenter fleet.

URnetwork uses member-run exits. The provider does not receive your source IP
on the relayed path. Native apps seal traffic to the provider by default.
[How URnetwork works](/docs/overview) explains the full design. The
[threat model](/docs/threat-model) holds the complete record of what is stored
and enforced.

## Six differences that affect the choice

| | Surfshark | URnetwork |
|---|---|---|
| Trust model | One company end to end, both hops of Dynamic MultiHop included | Two relay parties; the exit never sees your IP, and the operator cannot read the sealed session |
| Exit address | Rented datacenter ranges, publicly listed, widely blocked by streaming and retail sites | Residential addresses; ordinary traffic to the sites you visit |
| Coverage and targeting | 4,500+ marketed servers in 100+ countries, mixing physical and virtual locations with no published breakdown | Member devices in 90+ countries; browse countries, search for a city |
| Devices and data | Unlimited simultaneous devices, unmetered | Data metered, devices not; one allowance shared by everything you sign in |
| Consistency | The same datacenter hardware every session | Member uplinks; speed moves with the provider |
| Price and tiers | About $15.45/month, or $2.49–4.49/month on 24–27-month promos that renew higher; no free tier | $5/month or $40/year, with a free daily allowance |

Caveats below the table:

- Post-quantum encryption is parity, on by default on both sides. Surfshark
  states it ships on WireGuard, by its own account as of early 2026.
  URnetwork's X25519MLKEM768 client-to-provider session is default in the
  native apps, skipping any provider it cannot seal to rather than
  downgrading. The browser extension has no sealed session; there, the
  operator's data path logs nothing, pinned by a test in the open code.
- Dynamic MultiHop chains two servers you choose, and IP Rotator changes the
  exit address without dropping the tunnel. Both change what websites see.
  Both hops of MultiHop belong to Surfshark, and every rotated address is one
  Surfshark terminates.
- Both cover Android, iOS, macOS, Windows, and Linux, each with an explicit
  kill switch. Surfshark adds TV apps; both ship browser extensions, and
  URnetwork pairs its extension with its web app.
- Surfshark requires an email address to open an account. URnetwork's Instant
  Account takes one tap and no email. Current URnetwork numbers are at
  [ur.io/products](https://ur.io/products).

## Surfshark's assessments and what they cover

Surfshark's third-party record is real and specific. Deloitte completed
no-logs assurance engagements in 2023 and June 2025: interviews and
configuration review against the stated policy, with the full report readable
only behind a customer login. SecuRing completed a security test of the
infrastructure in December 2025, finding two medium-severity issues and no
critical ones, since fixed, plus a separate assessment of the apps and browser
plugin. Cure53 tested the extensions in 2018 and the infrastructure in 2021
and 2026.

Read the scopes. The security tests probe whether servers can be broken into;
only the Deloitte engagements concern logging at all. An assurance engagement
attests that the policy was implemented as described while the examiners
looked. Between snapshots you are back to the policy. One more scope fact:
Surfshark B.V. and NordVPN have shared a holding company since February 2022,
and an assurance report on one entity says nothing about the other. That is a
scope fact, not an accusation.

Surfshark's own texts mark the boundary. The homepage says the VPN "doesn't
monitor, track, or store what you do online". The privacy policy says its
servers "temporarily keep" your user ID and/or IP address with connection
timestamps, deleted within 15 minutes of session end. The company's own post
introducing Nexus, the network layer behind IP Rotator, adds: "All we can see
inside the network are traffic patterns." Marketing and policy can both be
true because "no-logs" is a choice about records, not a limit on visibility.

No involuntary test is on the record: no raid, no court production. Two
California class actions allege deceptive auto-renewal enrollment over
2022–2024 charges; those are allegations, not findings, unresolved as of
early 2026. No public breach of Surfshark infrastructure is on record.

![How you verify a privacy claim — point-in-time audits vs court and raid evidence vs open continuous verification](/docs-assets/infographic-verification.svg)

*A no-logs assurance is the first kind of evidence. URnetwork's is the third
kind: open code anyone can check on any day, with no independent examination
of the protocol or the operator's server code yet.*

## Rented fleet, virtual locations, residential variance

Surfshark's fleet is rented datacenter capacity, RAM-only since 2020.
RAM-only means nothing persists across a reboot; a running server still holds
and processes the sessions it terminates. The marketed map is 4,500+ servers
in 100+ countries, and Surfshark's own support pages say it mixes physical
and virtual presence: an IP registered to one country, served from hardware
in another, its own example a "German" location routed through France. No
public list says which locations are virtual or how many. In 2022 Surfshark
removed its physical India servers rather than comply with CERT-In's logging
mandate, and replaced them with virtual Indian locations served from abroad.
Outside measurement puts Surfshark ahead of its large peers on this point:
IPinfo's December 2025 study measured 41% of its advertised locations virtual or
unmeasurable, the lowest share of any big brand tested.

![Advertised locations vs measured reality — share of advertised locations measured virtual or unmeasurable per provider (IPinfo, December 2025)](/docs-assets/infographic-virtual-locations.svg)

*Surfshark measured 41%, the lowest of the big brands tested. Mullvad, IVPN
and Windscribe measured 0%. URnetwork appears as a mechanism rather than a
percentage, because a provider is the presence.*

Datacenter ranges are published, so streaming and retail sites can block them
wholesale; rotation changes the address without leaving Surfshark's ranges.
URnetwork's exits are residential addresses, and their traffic is ordinary to
the sites that receive it. Coverage is counted differently too. A URnetwork
location exists only while a member's device is online in it, and the network
geolocates the connection it observes rather than letting a provider declare
a city. A provider egressing through its own VPN or a hosting range is
detected and demoted, not excluded. Nobody has run IPinfo's study on
URnetwork.

Consistency runs Surfshark's way. Its servers behave the same every session.
URnetwork's speed moves with each member's uplink; URnetwork puts its average
streaming speed at 40 Mbps+.

## Payments and identity

Surfshark accounts start with an email address; as of early 2026 it accepts
cryptocurrency alongside cards. Its Alternative ID feature generates a
persona and a masked email alias. That shields you from websites, spam, and
breach fallout; the alias-to-inbox mapping lives with Surfshark.

URnetwork's Instant Account is created in one tap with no email. A recovery
seed phrase, issued once and stored only as hashes, restores the account
after a reinstall. The phrase is a URnetwork credential. URnetwork never asks
for a crypto wallet's seed phrase or private key. Sign-in by Solana or
Bittensor wallet signature is an alternative, and Pro can be paid in on-chain
USDC. USDC is pseudonymous; its anonymity depends on your wallet's history.

## Where Surfshark wins

- Unlimited devices on one subscription. One plan covers the whole household.
- Consistency. The same hardware every session, where URnetwork's throughput
  moves with the providers in your window.
- Multi-hop as a menu. Dynamic MultiHop picks the entry and exit countries;
  IP Rotator changes the exit address mid-session. URnetwork's separation is
  fixed in the architecture, not user-arranged.
- Fresh third-party attestations. Deloitte's no-logs assurance and SecuRing's
  security testing, both 2025. URnetwork's two 2025 assessments cover its web
  app, API, and Android app, not the protocol or the server.
- Multi-year price. The 24–27-month promos are among the cheapest paid plans
  anywhere.

## Where URnetwork wins

- The split. The exit never learns who you are, and the operator cannot read
  the sealed session. No single party holds identity and destinations
  together.
- The exit address. Residential IPs work where Surfshark's published ranges
  are blocked outright.
- Aim. Search a city by name wherever members are online; Surfshark offers
  countries, with cities in some.
- One-tap anonymity. An Instant Account with no email, restored on a new
  device by its recovery phrase; Surfshark requires an email.
- Month-to-month price and a free tier. $5 against about $15.45, plus a free
  daily allowance; Surfshark has no free tier.
- Whole-stack source. Client and server code are public; Surfshark's are
  closed.
- The supply side. Members can share their connection as participants in the
  [UR protocol](https://ur.xyz). Surfshark has no equivalent role.

## Limits and evidence

URnetwork's main limits:

- No independent audit covers the protocol, the connect engine, or the
  operator's server code. Two 2025 third-party assessments cover other
  surfaces: a penetration test of the web application and API (April–May
  2025), and the Leviathan MASA AL2 assessment of the Android app, which
  passed. Leviathan writes that its assessment "should not be read as a
  holistic security evaluation or comprehensive penetration test." Neither
  examined logging, retention, or the data path. A penetration test also says
  nothing about what gets written down, the same scope note SecuRing's
  testing carries for Surfshark.
- The split assumes the operator and the providers in your window are
  independent. Nothing in the system attests that independence, and no outside
  party has measured the fleet. See the [threat model](/docs/threat-model),
  §6.1.
- The WireGuard-compatible fallback endpoint assigns one stable tunnel
  address, so several providers could recognize the same client across
  sessions. The native tunnel is the recommended path.
- Coverage counts are self-published. IPinfo measured Surfshark from outside;
  nobody has run that study on URnetwork.

Surfshark's limit is structural. Every server, both MultiHop hops included,
terminates your tunnel for one company, so one position can see your real IP
and your destinations together. Its own policy keeps a live session record
for up to 15 minutes after each session, and its own Nexus post says the
network sees traffic patterns. The assurance engagements attest the policy;
no involuntary test has checked it.

Trying URnetwork costs nothing: the Instant Account takes one tap and no
email, so you can test it against your own sites before paying for either
product. More questions are answered in the [FAQ](/docs/faq).
