URnetwork vs Private Internet Access
Private Internet Access holds the strongest court-tested no-logs record of any VPN; URnetwork splits the path so the exit never learns who you are and the operator cannot read the sealed session.
Choose PIA if you value a court-tested no-logs record, torrenting with port forwarding, and the cheapest multi-year price. Choose URnetwork if you want residential exits, city selection, and a split path. Both publish open-source client apps. PIA has the stronger tested record. URnetwork splits visibility between its operator and a member-run provider.
Private Internet Access (PIA) was founded in 2010 by Andrew Lee and is one of the oldest names in consumer VPNs. It is a US company, based in Denver, owned since November 2019 by Kape Technologies, which also owns ExpressVPN and CyberGhost. Every one of its client apps is open source.
URnetwork uses member-run exits. The provider does not receive your source IP on the relayed path. Native apps seal traffic to the provider by default. How URnetwork works explains the full design. The threat model holds the complete record of what is stored and enforced.
Six differences that affect the choice
| PIA | URnetwork | |
|---|---|---|
| Trust model | One company; the server sees your IP and your destinations together, every session | Two relay parties; the exit never sees your IP, and the operator cannot read the sealed session |
| Exit address | Datacenter ranges, publicly listed, widely blocked by streaming and retail sites | Residential addresses; ordinary traffic to the sites you visit |
| Coverage and targeting | Marketed as 91 countries and all 50 US states; PIA's own API flags 78 of 189 regions geo-located (Aug 2026) | Member devices in 90+ countries; browse countries, search for a city |
| Tested record | Subpoenaed in 2016 and 2018 with no logs to produce; three Deloitte reviews; quarterly transparency reports | Open client and server code; no independent audit of the protocol or server code, and no court test |
| Torrenting | Port forwarding and a long torrent-friendly history | The provider-side security layer drops BitTorrent-class traffic |
| Price and tiers | About $12/month, or near $2/month on multi-year promos that typically renew higher; no free tier | $5/month or $40/year, with a free daily allowance |
Caveats below the table:
- URnetwork runs post-quantum encryption by default: the X25519MLKEM768 client-to-provider session is default in the native apps, skipping any provider it cannot seal to rather than downgrading. No post-quantum option was found at PIA as of early 2026, on WireGuard or OpenVPN as shipped. The browser extension has no sealed session; there, the operator's data path logs nothing, pinned by a test in the open code.
- Both cover Android, iOS, macOS, Windows, and Linux, each with a kill switch. URnetwork adds a browser extension paired with its web app, with the extension's kill switch on by default.
- PIA ships MACE, a DNS-level ad and tracker blocker, and a dedicated IP option. URnetwork's apps ship a "Block ads and trackers" toggle of their own, so the contrast is which filter you prefer, not who has one.
- A PIA account starts with an email address; cryptocurrency is accepted as of early 2026. URnetwork's Instant Account takes one tap and no email. Current URnetwork numbers are at ur.io/products.
The court record
Twice, under legal pressure, PIA had nothing to hand over. A 2016 FBI subpoena in the McWaters case produced no user activity logs; per the criminal complaint, all PIA could say was that the connections came from a cluster of east-coast IPs. In the 2018 Colby trial, its general counsel testified that the company held no name or address records and no trace of the defendant's sign-up emails. These were adversarial tests with legal stakes, not commissioned audits, and they are the strongest form of no-logs evidence any VPN in this doc set can show. On tested record, PIA is ahead of URnetwork, which has faced no court test.
Dates and entities keep the record accurate. Both tests were passed by London Trust Media, the company that ran PIA before Kape Technologies bought it in November 2019 for roughly $95 million; PIA's marketing carries the result forward undated, as "our log-less service has even been proven in court." The post-acquisition evidence is different in kind: three Deloitte Audit Romania reviews (2022, 2024, 2025), point-in-time ISAE 3000 examinations of server configurations and management systems with the reports behind a customer login, plus quarterly transparency reports that still record zero logs produced, 19 legal requests in Q2 2026 among them. No logging incident has surfaced under Kape. Ownership is context here too: Kape, renamed from Crossrider in 2018 after its browser-extension platform became known for ad-injection abuse, also bought the review sites vpnMentor and WizCase in 2021, and they rank Kape's three VPN brands at or near the top over a disclosure that rankings "may take into consideration" the common ownership.
What the record proves is that on those dates, that company wrote nothing down. The design still lets the server see identity and destinations together every day, and RAM-only "NextGen" hardware wipes at reboot while a running server observes everything it terminates. That is the structural difference the rest of this page turns on.
Geo-located servers and the map
PIA's coverage claim and its own disclosure sit on the same page. The server list advertises 91 countries and all 50 US states; further down, it explains that some locations are virtual, its own example being "our India servers are geo-located in Singapore and the UK." The public server API carries a per-region geo flag, and as of August 2026 it marked 78 of 189 regions as geo-located: an IP registered to the named place, hardware somewhere else. That includes 37 of the 55 US regions, so the all-fifty-states map is mostly state-registered IPs served from roughly a dozen physical states, and 41 of the 91 countries have no physical PIA server at all. Hong Kong, where PIA shut its servers down in 2020 over the security law, is still on the menu as a geo-located exit. Publishing the flag is more disclosure than most rivals offer, and outside measurement lands nearby: IPinfo's December 2025 study measured 52% of PIA's advertised locations virtual or unmeasurable.
URnetwork's map is presence-backed. A location is listed only while a member's device is online in it, and the network geolocates the connection it observes rather than letting a provider declare a city. A provider egressing through its own VPN or a hosting range is detected and demoted, not excluded. Nobody has run IPinfo's study on URnetwork. Datacenter ranges are published, so streaming and retail sites can block them wholesale; URnetwork's exits are residential addresses, and their traffic is ordinary to the sites that receive it. Consistency runs PIA's way: tuned rack servers return the same number every session, while URnetwork's speed moves with each member's uplink. URnetwork puts its average streaming speed at 40 Mbps+.
Payments and identity
A PIA account starts with an email address, and cryptocurrency payment, accepted as of early 2026, loosens the payment-to-identity link without removing the email.
URnetwork's Instant Account is created in one tap with no email. A recovery seed phrase, issued once and stored only as hashes, restores the account after a reinstall. The phrase is a URnetwork credential. URnetwork never asks for a crypto wallet's seed phrase or private key. Sign-in by Solana or Bittensor wallet signature is an alternative, and Pro can be paid in on-chain USDC. USDC is pseudonymous; its anonymity depends on your wallet's history.
Where PIA wins
- The evidence file. Court-tested in 2016 and 2018, audited three times since 2022, and transparency-reported quarterly. No VPN in this doc set shows stronger no-logs evidence.
- Torrenting. Port forwarding and a long history of supporting it; URnetwork's provider-side security layer drops BitTorrent-class traffic to protect the members whose connections carry the exit.
- Consistency. Datacenter speed that reads the same every session.
- Multi-year price. Promotional rates near $2/month are among the cheapest paid plans anywhere.
- Desktop maturity. Long-shipping, refined apps.
Where URnetwork wins
- The split. The exit never learns who you are, and the operator cannot read the sealed session. No single party holds identity and destinations together; PIA's server holds both and chooses not to record.
- The exit address. Residential IPs work where PIA's published ranges are blocked outright.
- Aim. Search a city by name wherever members are online; PIA offers countries and US states, much of the map geo-located by its own flag.
- Whole-stack source. PIA opens its clients; URnetwork opens the server side as well.
- One-tap anonymity. An Instant Account with no email, restored on a new device by its recovery phrase; PIA starts with an email.
- Month-to-month price and a free tier. $5 against about $12, plus a free daily allowance; PIA has none.
- Post-quantum encryption, on by default; none found at PIA.
- The supply side. Members can share their connection as participants in the UR protocol. PIA has no equivalent role.
Limits and evidence
URnetwork's main limits:
- No independent audit covers the protocol, the connect engine, or the operator's server code, and no court has tested its storage claims. Two 2025 third-party assessments cover other surfaces: a penetration test of the web application and API (April–May 2025), and the Leviathan MASA AL2 assessment of the Android app, which passed. Leviathan writes that its assessment "should not be read as a holistic security evaluation or comprehensive penetration test." Neither examined logging, retention, or the data path.
- The split assumes the egress fleet is what it is designed to be: many separately operated providers rather than one custodian. The fleet is member-operated by design, but how independent it actually is has never been measured, and nothing stops the operator running providers of its own. See the threat model, §6.1.
- The WireGuard-compatible fallback endpoint assigns one stable tunnel address, so several providers could recognize the same client across sessions. The native tunnel is the recommended path.
- Coverage counts are self-published. IPinfo measured PIA from outside; nobody has run that study on URnetwork.
PIA's limit is structural. Its server terminates your tunnel, so one position can see your real IP and your destinations together, and everything past that is a choice about records. The court record proves the choice was made, on those dates, by that owner; the current owner has audits and transparency reports, not a court test. RAM-only hardware bounds persistence, not visibility.
Trying URnetwork costs nothing: the Instant Account takes one tap and no email, so you can test it against your own sites before paying for either product. More questions are answered in the FAQ.