Is Surfshark Safe? Security, Privacy & Audit Analysis
Is Surfshark safe? Independent audit results, encryption protocols, jurisdiction analysis, kill switch testing, and no-logs policy verification.
Most Secure VPNs
Is Surfshark Safe? A Direct Assessment
Surfshark earns a trust score of 85/100. It operates under Netherlands jurisdiction, uses AES-256-GCM encryption, and maintains a strict no-logs policy verified by independent audits from Deloitte. With 3,200+ servers across 100+ countries, it provides kill switch protection, DNS leak prevention, and RAM-only server infrastructure. Surfshark is safe for most users.
Jurisdiction and What It Means for Data Requests
Surfshark relocated its legal headquarters from the British Virgin Islands to the Netherlands in 2021. The Netherlands sits within the EU but offers specific advantages for VPN providers. Dutch law does not require VPN companies to retain user data.
The Netherlands belongs to the 9 Eyes intelligence-sharing alliance. This concerns some privacy advocates. However, alliance membership only matters if the provider stores data that governments can request. A verified no-logs policy neutralizes this risk entirely.
If Dutch authorities issue a valid legal request, Surfshark can only hand over what it has. According to its transparency report, Surfshark has received government requests and complied with zero data transfers. The company physically cannot produce browsing records, connection timestamps, or IP address logs.
Independent Audit History
Deloitte No-Logs Audit
Deloitte completed an independent audit of Surfshark’s no-logs infrastructure in 2023. The Big Four firm examined server configurations, deployment processes, and internal data handling procedures. Deloitte confirmed that Surfshark’s infrastructure aligns with its stated no-logs policy.
This Surfshark audit followed an earlier 2022 examination by Deloitte covering the same scope. Both assessments found no evidence of user activity logging on any server.
Cure53 Security Audit
Cure53, a German cybersecurity firm, audited Surfshark’s browser extensions in 2018. The team identified 2 critical, 2 high-severity, and 2 medium-severity vulnerabilities. Surfshark patched all 6 issues before the audit report went public.
Cure53 also conducted a follow-up assessment of Surfshark’s server infrastructure in 2021. That review found no critical vulnerabilities. The firm noted that Surfshark’s security posture had improved significantly since the initial examination.
What These Audits Mean
Two separate firms have now validated Surfshark’s privacy and security claims. Deloitte focused on logging practices while Cure53 tested technical defenses. Together, these audits provide stronger assurance than either would alone.
Logging Policy Details
Surfshark’s privacy policy specifies exactly what the company collects and what it does not collect. The distinction matters more than any marketing claim.
What Surfshark Does NOT Store
- Browsing history or traffic destinations
- IP addresses used to connect to the VPN
- Session timestamps showing connection or disconnection times
- Network traffic volume or bandwidth consumption
- DNS queries made while connected
What Surfshark DOES Collect
Surfshark stores your email address and encrypted password for account management. It collects billing information processed through third-party payment providers. The company gathers anonymized diagnostic data and crash reports for performance improvements.
Surfshark also tracks aggregate connection frequency data. This means it knows how many times a user connects per day but not when or where. This data cannot identify individual browsing sessions or visited websites.
RAM-Only Server Infrastructure
All 3,200+ Surfshark servers run entirely on volatile RAM memory. This means every server wipes all data automatically upon reboot. Even a physical server seizure would yield zero usable information. This architecture makes the Surfshark no-logs claim technically enforceable rather than just policy-based.
Encryption Standards and Protocols
Surfshark uses AES-256-GCM encryption as its default cipher. This standard protects classified government communications worldwide. No known attack can break AES-256 with current computing technology.
Available Protocols
| Protocol | Speed | Security Level | Best For |
|---|---|---|---|
| WireGuard | Fastest | High | Daily browsing, streaming |
| OpenVPN UDP | Moderate | Very High | Maximum compatibility |
| OpenVPN TCP | Slower | Very High | Restrictive networks |
| IKEv2 | Fast | High | Mobile devices |
WireGuard serves as the default protocol on most Surfshark apps. It provides roughly 40% faster speeds than OpenVPN while maintaining comparable security. Surfshark adds a double NAT system on top of WireGuard to address its known privacy limitation around static IP assignment.
OpenVPN remains available for users who prefer its 20-year track record. Both UDP and TCP variants use 4096-bit RSA handshake keys alongside the AES-256 data channel encryption.
Kill Switch Behavior and DNS Leak Protection
Surfshark includes a kill switch on Windows, macOS, iOS, Android, and Linux applications. The feature blocks all internet traffic if the VPN connection drops unexpectedly. This prevents your real IP address from leaking during brief disconnections.
The kill switch operates at the system level on desktop platforms. It intercepts traffic at the network adapter before packets can escape unencrypted. Mobile implementations use platform-specific APIs to achieve similar protection within OS constraints.
DNS Leak Protection
Surfshark runs private DNS on every server in its network. All DNS queries route through encrypted tunnels to Surfshark-controlled resolvers. This eliminates DNS leak risks from third-party DNS providers like your ISP.
Independent tests on dnsleaktest.com and ipleak.net consistently show zero DNS leaks across Surfshark’s protocol options. IPv6 leak protection is enabled by default, blocking IPv6 traffic that could bypass the IPv4 VPN tunnel.
Past Security Incidents
Surfshark has not suffered a confirmed data breach or server compromise as of early 2025. No user data has appeared in public breach databases connected to Surfshark infrastructure.
In 2020, security researchers flagged a potential vulnerability in Surfshark’s Windows application. The issue involved an outdated OpenSSL library that could theoretically allow privilege escalation. Surfshark released a patch within 48 hours of disclosure. No exploitation in the wild was documented.
The Cure53 audit in 2018 represents the most significant vulnerability discovery. Those 6 findings in the browser extensions were resolved before public disclosure. Surfshark credits its bug bounty program with catching issues early. The company pays external researchers who responsibly disclose valid vulnerabilities.
Unique Security Features Specific to Surfshark
CleanWeb
CleanWeb blocks ads, trackers, and malware domains at the DNS level. It prevented over 1 billion tracking attempts across its user base in 2023. The feature works without installing separate browser extensions.
MultiHop (Double VPN)
MultiHop routes traffic through 2 VPN servers in different countries simultaneously. This adds a second encryption layer and makes traffic correlation attacks significantly harder. Users choose from preset server pairs or create custom combinations.
Nexus Technology
Surfshark Nexus connects users to its entire server network rather than a single server. Traffic enters through one server and can exit through another using SDN routing. This reduces latency while improving IP rotation and load distribution across 3,200+ servers.
Alternative ID
Alternative ID generates disposable email addresses and online personas. Users can register for services without exposing real personal information. This feature separates Surfshark from competitors who focus only on connection-level privacy.
Rotating IP
Surfshark changes your visible IP address every 5 to 10 minutes without disconnecting the VPN session. Your connection stays active while your digital fingerprint shifts continuously. This makes long-term tracking across websites substantially harder.
Frequently Asked Questions
Is Surfshark actually safe to use?
Yes, Surfshark earns an 85/100 trust score in our testing. It operates under Netherlands jurisdiction, uses AES-256-GCM encryption, and its no-logs policy has been independently audited by Deloitte in 2022 and 2023. Combined with RAM-only servers across its 3,200+ server network and a working kill switch, Surfshark is safe for most users.
What does Surfshark’s Netherlands jurisdiction mean for government data requests?
The Netherlands doesn’t require VPN companies to retain user data, despite belonging to the 9 Eyes intelligence-sharing alliance. Surfshark relocated its legal headquarters from the British Virgin Islands to the Netherlands in 2021. Its transparency report shows it has received government requests and complied with zero data transfers, since a verified no-logs policy leaves nothing to hand over.
What did Surfshark’s Deloitte no-logs audits actually find?
Deloitte, a Big Four accounting firm, audited Surfshark’s no-logs infrastructure in 2022 and again in 2023, examining server configurations and internal data handling procedures. Both assessments found no evidence of user activity logging on any server. That gives Surfshark two consecutive annual no-logs verifications from the same major auditor, stronger evidence than a single audit alone.
What vulnerabilities did Cure53 find during its Surfshark audits?
Cure53, a German cybersecurity firm, audited Surfshark’s browser extensions in 2018 and found 2 critical, 2 high, and 2 medium-severity vulnerabilities, all patched before the report went public. A 2021 follow-up examined server infrastructure instead and found no critical vulnerabilities, with Cure53 noting Surfshark’s security posture had improved significantly since 2018.
What information does Surfshark actually collect from users?
Surfshark stores your email address and encrypted password for account management, plus billing details processed through third-party payment providers. It also collects anonymized diagnostic data, crash reports, and aggregate connection frequency, meaning how many times you connect per day, not when, where, or which sites you visited. Browsing history, IP addresses, and DNS queries are never stored.
How does Surfshark’s RAM-only server infrastructure protect user data?
Every one of Surfshark’s 3,200+ servers runs entirely on volatile RAM rather than hard disks, wiping all data automatically on reboot. A physical server seizure would therefore yield zero usable logs, connection records, or IP history. This architecture, backed by Deloitte’s no-logs audits, makes Surfshark’s no-logs claim technically enforceable rather than just a policy promise.
What encryption and protocols back Surfshark’s security claims?
Surfshark defaults to AES-256-GCM encryption paired with WireGuard, which runs roughly 40% faster than OpenVPN while maintaining comparable security. Surfshark layers a double NAT system on top of WireGuard to address its known static-IP privacy limitation. OpenVPN UDP/TCP and IKEv2 remain available too, both using 4096-bit RSA handshake keys alongside AES-256 data channel encryption.
How can I confirm Surfshark’s kill switch is actually working?
Force-disconnect your Wi-Fi or unplug ethernet mid-session while connected to a Surfshark server; a working kill switch stops all internet traffic instantly instead of falling back to your unprotected connection. On Windows, macOS, and Linux the switch operates at the network adapter level, while iOS and Android use platform-specific APIs to achieve similar protection within OS constraints.
Has Surfshark ever suffered a data breach?
No, Surfshark has not suffered a confirmed data breach or server compromise as of early 2025, and no user data tied to its infrastructure has appeared in public breach databases. In 2020, researchers flagged an outdated OpenSSL library in the Windows app that could theoretically allow privilege escalation; Surfshark patched it within 48 hours with no documented exploitation.
What’s the difference between Surfshark’s MultiHop and Nexus features?
MultiHop routes your traffic through 2 VPN servers in different countries simultaneously, adding a second encryption layer that makes traffic correlation attacks harder. Nexus instead connects you to Surfshark’s entire server network using SDN routing, letting traffic enter through one server and exit through another, which improves IP rotation and load distribution across the 3,200+ server network.
Does all this encryption and privacy tech slow Surfshark down?
Not meaningfully. Surfshark ranks #4 of 22 in our Speed Lab, aggregated from independent labs, despite running AES-256-GCM encryption and a double NAT layer on top of WireGuard. WireGuard itself runs roughly 40% faster than OpenVPN while maintaining comparable security, so the added privacy layer doesn’t meaningfully undercut real-world throughput.
Can I get a refund if Surfshark’s security doesn’t meet my expectations?
Yes, Surfshark backs every plan with a 30-day money-back guarantee, giving you a full month to test its kill switch, RAM-only servers, and audited no-logs claims before committing. This applies regardless of which plan tier you pick, from the cheapest at $1.99/month on its longest-term plan up through the bundled security suites.
Does protecting more devices on one account increase my exposure?
No. Surfshark allows unlimited simultaneous device connections on a single account, and each one benefits from the same audited no-logs policy and RAM-only server infrastructure. Since Surfshark doesn’t store browsing history, IP addresses, or session timestamps on any server, adding more devices under one account doesn’t create an additional data footprint.
What should I do if I suspect a DNS leak on Surfshark?
Run a check at dnsleaktest.com or ipleak.net while connected; independent tests consistently show zero DNS leaks across Surfshark’s protocol options. Surfshark routes all DNS queries through encrypted tunnels to its own private DNS resolvers on every server, and IPv6 leak protection is enabled by default to block IPv6 traffic from bypassing the IPv4 tunnel.