The comparison map
This documentation compares URnetwork against twenty-one other networks, one document per product. This page is the overview: every product in those comparisons, plus URnetwork itself, becomes one dot on a two-axis map, scored from the same evidence the individual pages cite. The horizontal axis is a verifiable anonymization index. It asks what the service can see and how you would know: whether any single party holds both who you are and what you do, whether "no logs" is verifiable rather than promised, whether encryption runs through the service or only to it, and whether the key exchange resists harvest-now-decrypt-later attacks. The vertical axis is a connection quality index. It asks whether the connection is good enough to live on: latency, throughput, egress quality, availability, and the ways in.
Each axis is a weighted sum of 0–10 sub-scores assigned against anchors fixed before any product was scored. The method is on the scoring methodology page and the full anchor ladders are on the scores page, so any coordinate here can be recomputed rather than trusted.
The quadrants
The axes cross at (5.00, 5.00), the fixed center of the 0–10 scale, not an average of the field: a position means the same thing whoever else is on the chart, and adding or removing products moves nobody. One reading rule: anything within a quarter point of a line sits on the line, not confidently on either side of it.
Verifiable Next Generation, top right, means clear of the scale center on both axes: privacy structure that can be checked rather than promised, with a connection above the midpoint. Four products: URnetwork (7.30, 6.20); Obscura (6.60, 5.10), on the quality line itself rather than clear of it; Mullvad (6.00, 6.20); and IVPN (5.70, 5.85). The gap behind the group is real: the next scores on the verifiable axis are Apple Private Relay's 5.10 on the line itself and Windscribe's 4.60, clear water rather than rounding. Mullvad holds the best-verified conduct record in the industry, including the 2023 Swedish police raid that left with nothing and 0% measured location mismatch; if external verification is your bar, its page recommends Mullvad. Obscura's entry hop cannot read traffic for any user on any platform, with no setting at all; the client is source-available rather than open source, the backend is unpublished, and it ships no post-quantum encryption. IVPN is the quadrant's most marginal member, clear of both lines but nearest to them.
Trust-Based Current Generation, top left, is where most of the commercial VPN industry lands: eleven single-company designs where the operator terminates the tunnel and could see everything, with connection quality at or above the midpoint. They all sit left of the vertical line for the same structural reason: encryption to a company that decrypts everything, however well run, is not encryption through it. Conduct varies widely inside it; the per-product pages carry the records: Windscribe (4.60, 6.80) comes closest to the verifiable line, with open-source apps, a 2025 court dismissal, and a 2026 seizure that found servers running in RAM alone; Tailscale (3.70, 7.25) posts the best quality score on the map at its own job, a direct mesh between your machines, and is not an egress-privacy product by default; Hotspot Shield (1.70, 5.50) sits at the far edge, with the free tier's ad partners named in its own policy.
Academic / Research, bottom right, holds the strongest anonymization at real cost to daily use. Tor (9.40, 3.30) is the reference standard and the top score on the anonymization axis by a wide margin; its cost is documented by its own community: relay-chain latency and publicly listed exits that much of the web blocks or challenges. For adversaries up to a state, its page and the experts agree: use Tor. NymVPN (7.50, 4.00) ships the strongest anonymity design in commercial VPN, a live 5-hop mixnet with cover traffic, payment unlinkability, and a published independent audit of the protocol itself, which URnetwork does not have. The default Fast mode is a two-hop tunnel without cover traffic; Nym's own docs state the mixnet's latency price.
Legacy, bottom left, means below the scale center on both axes. The label describes position, not age: Orchid (3.40, 3.90), Mysterium (2.70, 4.90) and Sentinel (2.40, 4.80) are young projects that land here on thin verification, the latter two within noise of the quality line. Only for Hola (0.25, 4.85) does the name carry its full weight: the floor of the anonymization axis, with its own privacy policy stating collection of browsing history with retention up to 12 months, and free users' devices enrolled as capacity for a commercial proxy business.
One product belongs to no quadrant. Apple Private Relay (5.10, 4.95) sits at the axes' crossing, inside noise of both lines. Its two-hop split is enforced by encryption, per Apple's own architecture overview; it is held at the middle of the verifiable axis by its closed implementation, by non-collusion that is a corporate arrangement rather than mathematics, and by the narrowest scope on the map: Safari and DNS on Apple hardware, no location choice. An earlier version of this page placed it in Legacy on a misdescription of its architecture; the disclosed rescore is on the score derivations page.
Where URnetwork sits
URnetwork's dot is at (7.30, 6.20), in the top-right quadrant. No single party holds both who you are and what you do: the provider never learns who you are, and the operator relays bytes it cannot read, both by default at launch. The entire stack is open source, including the operator's server code. Egress is residential and city-targetable, with locations derived from the connection the network observes.
Two caveats frame the whole map. These positions are URnetwork's own scoring of published evidence, not an independent measurement. And nobody has measured URnetwork from outside: IPinfo measured roughly 150,000 exit IPs across 20 commercial providers and found only Mullvad, IVPN and Windscribe with zero location mismatch, while URnetwork's residential, presence-derived locations are a mechanism you can check in code, not a third-party result.
URnetwork was scored on the same rubric as everyone else, and its costs are printed here rather than footnoted:
- No independent audit covers the protocol, the connect engine, or the operator's server code. That holds its verifiability part at 6, below Mullvad's 9 and PIA's 8. Two 2025 third-party assessments cover other surfaces, a web-application and API penetration test and a passed Leviathan MASA AL2 assessment of the Android app that Leviathan itself scopes as not a holistic security evaluation; neither examined logging, retention, or the data path, and neither moved a score.
- Two integrity fixes for the sealed session are still landing before launch. Today a failed handshake leaves traffic flowing unsealed with no visible signal, and the key cross-check that would catch an operator substituting a provider key logs rather than refuses; the threat model documents both. The browser extension has no sealed session at all.
- The latency and speed parts are structural judgments, both scored 5. No outside measurement of URnetwork's latency or throughput exists in either direction; the one number in the corpus is URnetwork's own attributed 40 Mbps+ average streaming speed, which moves with the members carrying you.
- It is not a torrenting product. The engine drops BitTorrent-class traffic at the provider's edge, by design.
What would change this picture
Every ordering claim here sits on two stability tests, a design adopted from independent peer review: sampling the axis weights uniformly with sub-scores frozen, and perturbing every sub-score by ±1 point at the published weights. Design, seeds, exact fractions and a reproduction script are on the sensitivity analysis page. The main results:
- The lead over Mullvad is a weighting judgment, not a settled fact.
URnetwork leads Mullvad on the verifiable axis in about 74% of sampled weightings (exactly 71/96 of the weight space). A reader who weighs audits and court evidence at about half the axis gets Mullvad first, a reasonable reading rather than a mistake. Under ±1 score noise at the published weights, URnetwork leads in 99.9% of draws. Before the disclosed rescore that recorded URnetwork's sealed session as on by default, the same test read 55.55%, a coin flip.
- The Obscura gap is one part wide. URnetwork and Obscura tie 16–16
on the two structure parts and tie at 6 on verifiability; URnetwork's entire 0.70 lead is the post-quantum part, scored 7 against Obscura's 0. The structure tie is earned differently: Obscura's entry-hop blindness is by construction, URnetwork's seal is a shipped default with its integrity fixes still landing. Every weighting that gives post-quantum any weight preserves the order, a statement about the difference's shape rather than its robustness; the informative test is score noise, where URnetwork keeps the lead in 93.9% of draws. What would genuinely close the pair is Obscura shipping post-quantum.
- **NymVPN sits 0.20 ahead on the verifiable axis, and
the pair is unsettled.** URnetwork passes it in 67% of sampled weightings (the order turns entirely on whether the post-quantum weight exceeds an eighth), and under score noise NymVPN keeps its lead in about 69% of draws.
- **The
quality axis is the loose one.** URnetwork's quality rank runs 1st to 15th of 22 across sampled weightings, and 4th to 11th under score noise, against the tied-5th its point score suggests; its verifiable-axis rank stays within 1–4 across the same weight space. An earlier claim that no re-weighting could take URnetwork's quality score below the center was withdrawn as circular (every quality sub-score was assigned at least 5, so the bound followed from the inputs); the withdrawal is recorded on the sensitivity page.
- **The two
lines carry different confidence.** Only Apple Private Relay sits within noise of the vertical line; no other product comes closer than 0.40, so no defensible single-point re-score moves anyone else across it. The horizontal line is the noisy one: Obscura sits a tenth above it, Apple, Mysterium, Hola and Sentinel within a quarter point below, and TunnelBear, IPVanish and Hotspot Shield within half a point above. Read all of those loosely; the corner residents, Tor, NymVPN, URnetwork and Mullvad, do not move.
The scores
The map's dots, one line per product, each linked to its head-to-head page. The rank columns are intervals rather than points, on purpose: the 5th–95th percentile of each product's rank (1 = highest) under the ±1 score-noise test. Ranges under re-weighting are wider still; both sets are on the sensitivity analysis page, and the complete sub-score matrix is on the score derivations page.
| Product | X | Y | X rank | Y rank | Quadrant |
|---|---|---|---|---|---|
| Tor | 9.40 | 3.30 | 1 | 21–22 | Academic / Research |
| NymVPN | 7.50 | 4.00 | 2–3 | 20–21 | Academic / Research |
| URnetwork | 7.30 | 6.20 | 2–4 | 4–11 | Verifiable Next Generation |
| Obscura † | 6.60 | 5.10 | 3–5 | 12–19 | Verifiable Next Generation |
| Mullvad | 6.00 | 6.20 | 4–6 | 4–11 | Verifiable Next Generation |
| IVPN | 5.70 | 5.85 | 5–7 | 6–13 | Verifiable Next Generation |
| Apple Private Relay ‡ | 5.10 | 4.95 | 6–8 | 13–19 | On both lines |
| Windscribe | 4.60 | 6.80 | 7–10 | 1–5 | Trust-Based Current Generation |
| PIA | 4.20 | 5.75 | 8–13 | 7–14 | Trust-Based Current Generation |
| ExpressVPN | 4.20 | 6.10 | 8–13 | 4–11 | Trust-Based Current Generation |
| Proton VPN | 3.90 | 6.70 | 9–15 | 1–6 | Trust-Based Current Generation |
| NordVPN | 3.90 | 6.10 | 9–15 | 4–11 | Trust-Based Current Generation |
| Tailscale | 3.70 | 7.25 | 10–16 | 1–3 | Trust-Based Current Generation |
| Cloudflare WARP | 3.55 | 6.70 | 11–16 | 1–6 | Trust-Based Current Generation |
| Surfshark | 3.50 | 6.00 | 11–17 | 5–12 | Trust-Based Current Generation |
| Orchid | 3.40 | 3.90 | 12–17 | 20–22 | Legacy |
| Mysterium † | 2.70 | 4.90 | 16–20 | 14–19 | Legacy |
| TunnelBear | 2.65 | 5.45 | 16–20 | 9–16 | Trust-Based Current Generation |
| Sentinel † | 2.40 | 4.80 | 17–20 | 15–19 | Legacy |
| IPVanish | 2.35 | 5.45 | 17–21 | 9–16 | Trust-Based Current Generation |
| Hotspot Shield | 1.70 | 5.50 | 20–21 | 9–16 | Trust-Based Current Generation |
| Hola † | 0.25 | 4.85 | 22 | 14–19 | Legacy |
† Within a quarter point of the horizontal line: read Mysterium, Sentinel and Hola as on it from below, Obscura from above.
‡ Within noise of both lines at once: read Apple Private Relay as sitting at the axes' crossing, in no quadrant.
Limits
Two axes cannot hold everything. Price, device limits, torrenting policy, port forwarding, jurisdiction, and ownership are all real reasons to choose a product, and none of them is on this chart. The per-product pages carry them.
No weight or axis was adjusted after scoring began, and no score was chosen to produce a placement. Three changes since scoring are disclosed with full re-derivations on the pages below: Apple Private Relay was rescored after peer review showed the evidence base had misdescribed its architecture — an error that had run in URnetwork's favour, so correcting it cut against us; URnetwork was rescored when its sealed session was ruled on by default at launch, which did move its dot in URnetwork's favour and is flagged as such; and Obscura, the closest architectural competitor, was added on 2026-08-07 with every rank interval recomputed. The standing rule applies to URnetwork itself: if new evidence lands, an independent audit, an outside measurement, a competitor shipping verifiable structural separation, the move is to rescore and republish, in that order.
The depth this page defers lives in three places:
- The scoring methodology: the axis weights, the comparator-selection rule, the change ledger, and how the map is built.
- The score derivations: every product's sub-scores, the anchor ladders they were assigned against, the evidence and reasoning behind each number, and the disclosed rescores.
- The sensitivity analysis: the Monte Carlo design and seeds, the rank intervals under both tests, the withdrawn claim, and the reproduction script.
Every individual comparison linked above states where the other product wins, because all of them win somewhere. More questions are answered in the FAQ.