VPN Basics

How to Choose a VPN: What It Actually Does, and the Criteria That Separate Providers

No consumer software category has a wider gap between what the ads promise and what the product does than VPNs. The marketing says "complete anonymity", "military-grade protection", "be invisible online". The reality is narrower, and — once you understand it — much easier to shop for.

The key takeaway up front: a VPN does one thing well: it encrypts your traffic and routes it through the provider's server, hiding your activity from your local network and your IP address from the sites you visit. That's genuinely useful in specific situations. But it means you're transferring trust from your internet provider to the VPN company — so the entire buying decision reduces to five checkable criteria: trust and logging (verified by audits), jurisdiction, technical safeguards, speed, and honest pricing. This guide walks through each; the scored side-by-side comparisons live on top-fully.com.

If you want the general evaluation method first — choosing criteria, weighting them, scoring a shortlist — read our criteria-first comparison framework. This guide applies it to VPNs specifically.

What a VPN actually does

Mechanically, a VPN (virtual private network) creates an encrypted tunnel between your device and a server run by the VPN provider. Your traffic travels through that tunnel, then exits to the wider internet from the provider's server. Two consequences follow:

  1. Your local network can't read your traffic. The coffee-shop Wi-Fi, your hotel, your ISP, a nosy network administrator — they see only encrypted data flowing to a VPN server, not which sites you visit or what you do there.
  2. Websites see the VPN server's IP address, not yours. Your apparent location becomes the server's location, which is what enables region-shifting and blunts IP-based tracking.

That's the whole trick. It's a good trick — but notice what it implies: all your traffic now exits through the VPN provider. Whatever your ISP could have observed, the VPN provider now can. You haven't eliminated a watcher; you've chosen a different one. Which is why criterion 1 below outweighs everything else.

What a VPN doesn't do

Clearing this up first makes you immune to most VPN advertising:

  • It doesn't make you anonymous. Logged into Google, Facebook, or any account? Those services know exactly who you are regardless of your IP. Browser fingerprinting, cookies, and tracking pixels also work through a VPN.
  • It's not an antivirus. A VPN encrypts traffic in transit; it does not stop malware, phishing pages, or a malicious download. (Bundled "threat protection" features are typically DNS-level filters — a nice extra, not a security suite.)
  • It doesn't secure weak accounts. Reused passwords are breached through credential leaks, not through your Wi-Fi. A VPN and a password manager solve different problems; if you're securing your digital life in order, our password manager buyer's guide is the other half.
  • HTTPS already encrypts most content. The padlock on modern sites means the content of your traffic is encrypted to the destination even without a VPN. What the VPN adds on top is hiding which sites you connect to from the local network, and your IP from the destination.

When is a VPN clearly worth it? Regular use of untrusted networks (travel, cafés, airports, hotels), wanting your browsing history invisible to your ISP, accessing region-restricted content you're entitled to, or working from jurisdictions where network surveillance is a practical concern. If none of those describe you, be honest with yourself before subscribing — "vaguely more secure" is not a use case, and a subscription without a job to do fails our framework at step one.

Criterion 1: Trust and logging — audited, not promised (weight this heaviest)

Since the provider can see your traffic metadata, the central question is: do they record it? Every VPN on earth claims a "no-logs policy". The claim is free; what you're shopping for is verification. Three tiers of evidence, weakest to strongest:

  1. A written policy — table stakes, and by itself worth little. Read it anyway: "no activity logs" sometimes coexists with connection logs, timestamps, or bandwidth records tied to your account.
  2. Independent no-logs audits — a third-party firm examines the provider's infrastructure and attests the policy matches reality. Recency and scope matter: an audit of the actual server infrastructure beats an audit of the policy document, and audits should recur, not be a one-time press release.
  3. Real-world tests — the strongest evidence is involuntary: server seizures or legal demands where authorities obtained nothing, because nothing was stored. A provider that has survived that test, and published the details, has proven the claim the hard way.

Also under trust: who owns the provider? The VPN industry has consolidated heavily, and several parent companies own many brands — some with data-business histories. Ownership, company history, and transparency reports (how many legal requests, what was produced) are all fair scoring inputs. A provider that publishes transparency reports on a schedule is behaving like a company that expects scrutiny.

Criterion 2: Jurisdiction — where the company answers subpoenas

A no-logs policy operates inside a legal system. The provider's jurisdiction — where it's incorporated and where its infrastructure sits — determines which governments can compel what:

  • Some countries participate in intelligence-sharing alliances and have data-retention or compelled-assistance laws that can reach service providers.
  • Others have no mandatory data-retention requirements for VPNs, which is why many providers deliberately incorporate there.

Don't over-rotate on this criterion: jurisdiction matters far less when there are genuinely no logs to hand over, which is why it's weighted below audited logging, not above. Treat it as a tiebreaker and a consistency check — a provider that markets privacy while sitting in a retention-heavy jurisdiction without explaining how it squares that has a story that doesn't add up. RAM-only servers (which cannot retain data across a reboot, making seizure of a powered-down server useless) are a meaningful technical complement here and increasingly the mark of a serious provider.

Criterion 3: Technical safeguards — kill switch, leak protection, protocols

These are the features that determine whether the tunnel actually holds under real conditions:

  • Kill switch. If the VPN connection drops — networks hiccup, laptops sleep — a kill switch blocks all traffic until the tunnel is re-established, instead of silently failing open and exposing your real IP. This is non-negotiable if your use case is privacy on untrusted networks; verify it exists on every platform you use, because a desktop kill switch doesn't protect your phone.
  • DNS and IP leak protection. Your device's DNS lookups (the "which site am I visiting" requests) must go through the tunnel too, or the privacy story collapses on a technicality. Good providers run their own DNS and document leak protection; you can verify with free leak-test pages during a trial.
  • Modern protocols. WireGuard (and providers' WireGuard-based implementations) is the current standard for the speed/security balance, with OpenVPN as the battle-tested fallback. A provider still leaning on legacy protocols is signaling underinvestment.
  • Honest extras. Multi-hop, split tunneling, and ad/tracker-blocking DNS are legitimately useful to specific users. Score them only if they serve your job description — features you won't use are decoration, per the framework.

Criterion 4: Speed and server network — trial it, don't trust charts

Every VPN adds some overhead: your traffic takes a detour and gets encrypted along the way. How much overhead varies widely by provider, protocol, server load, and your distance to the server — which is why vendor speed charts and even third-party benchmarks are weak evidence for you. The distribution matters more than the peak: a provider with consistently good speeds on nearby servers beats one with a spectacular benchmark on a server continent away.

Do what our framework prescribes: a scripted trial. Nearly every reputable provider offers a money-back window that functions as one. Script the same tasks you'd actually do — a video call at your usual hours, streaming on the platforms you use, a large download — on the servers you'd actually use (nearest city, plus any region you specifically need). Check the server network for your geography: a provider with three hundred locations you'll never use is worth less than one with fast, uncongested servers where you live and travel.

Criterion 5: Pricing — the intro-price trap, measured in year three

VPN pricing is the most discount-theatrical in consumer software: perpetual "72% off" banners, long prepaid terms, and renewal prices that bear no resemblance to the intro rate. Score it the way our framework scores every cost: model the third year, not the first invoice.

  • Find the renewal price — it's in the checkout fine print, and it is the real price. Compare candidates on renewal, not intro.
  • Beware ultra-long prepaid terms as your first purchase. Multi-year deals are only good value if the service stays good; buy a short term first, trial properly, then commit if it earns it.
  • Be skeptical of "lifetime" VPN deals. Running servers costs money forever; a one-time payment funding perpetual service has a business-model math problem, and such services historically degrade or vanish.
  • Check simultaneous connections and device support against your household's reality — this is where plans quietly differ.
  • Free VPNs deserve extra scrutiny, not automatic rejection. Running a VPN costs real money, so ask where it comes from. A limited free tier funding a paid product is a legitimate trial; a "100% free unlimited VPN" with no visible business model is very plausibly monetizing the one thing you were trying to protect — your traffic. On this category's criterion 1, most free VPNs disqualify themselves.

A worked weighting

A reasonable default for a privacy-motivated individual, using the 1–5 weights from our framework:

Criterion Weight Why
Audited no-logs / trust 5 The product is trust; everything else assumes this holds
Technical safeguards 4 A tunnel that fails open defeats the purpose
Speed (on your servers) 3–4 Decides whether you keep it on or quietly disable it
Jurisdiction 2–3 Meaningful tiebreaker; less decisive than verified no-logs
Price (year three) 2 Real money, but small stakes next to the trust criteria

A streaming-first buyer would raise speed/server-network to 5 and relax jurisdiction; a journalist would do the opposite. Same facts, different weights, different correct answers — that's the framework working as designed. Score three to five providers, trial the top two inside their refund windows, decide.

FAQ

Does a VPN make me completely anonymous online?

No, and any provider claiming so is overselling. A VPN hides your IP from websites and your activity from the local network — but sites you log into still know who you are, and cookies and browser fingerprinting still track you. Think of a VPN as location and transport privacy, one layer in a stack, not an invisibility cloak.

How do I verify a VPN's no-logs policy is real?

Look for evidence in ascending strength: a clearly written policy, recent independent audits of the actual infrastructure (recurring, not one-off), published transparency reports, and — strongest of all — real-world legal incidents where the provider demonstrably had nothing to hand over. A marketing page saying "zero logs" with none of the above is a claim, not evidence.

Is a free VPN safe to use?

Judge it on the same criteria, with the business-model question front and center: servers and bandwidth cost money, so a free VPN is funding itself somehow. Limited free tiers from audited paid providers can be fine as trials. Standalone "free unlimited" VPNs frequently fail the trust criterion outright — some have been caught logging or selling traffic data, the exact thing a VPN exists to prevent.

Does using a VPN slow down my internet connection?

Some overhead is physics — encryption plus a routing detour — but with a well-run provider on a modern protocol like WireGuard, a nearby server is often fast enough that you won't notice in daily use. The honest answer is that it varies enough that you should trial it yourself: test your real tasks on your realistic servers during the refund window rather than trusting anyone's benchmark chart, including a review site's.


That's the rubric. We've applied it for you: audited logging policies, jurisdictions, kill-switch behavior, measured speeds, and true renewal pricing, scored side by side with the evidence behind each score. Compare the top VPNs side by side at top-fully.com and weight the criteria for your own use case.

Comments are disabled for this article.