Signals of Trustworthiness (original) (raw)

Part I. Corporate Accountability & Business Model

  1. The public facing name is IVPN. The Legal name of the company is IVPN Limited.
    IVPN Limited has no parent or holding companies.
    There are no other companies or partners directly involved in operating the IVPN service.
  2. Does the company, or other companies involved in the operation or ownership of the service, have any ownership in VPN review websites?

No. 3. ### What is the service’s business model (i.e., how does the VPN make money)? For example, is the sole source of the service’s revenue from consumer subscriptions?
100% of revenue is generated from selling VPN consumer subscriptions.

Part II. Privacy: Logging/Data Collection Practices and Responding to Law Enforcement

  1. Does the service store any data or metadata generated during a VPN session (from connection to disconnection) after the session is terminated? If so what data? (including data from Client / VPN app, APIs, VPN gateways).

No. 5. No. 6. ### Do you have a clear process for responding to legitimate requests for data from law enforcement and courts?
Yes, please see Law Enforcement Legal Process Guidelines and transparency report.
If an adversary gains physical access to a server its prudent to assume that they will gain access to the unencrypted data stored on the server. As VPN servers are not under the direct physical control of IVPN they have been designed with the expectation that they will be compromised. To protect the privacy of IVPN customers the following controls are implemented:

Part III. Security Protocols and Protections

  1. What do you do to protect against unauthorized access to customer data flows over the VPN?

Administrative controls

Technical controls

Customer connections

  1. What other controls does the service use to protect user data?

    • IVPN accepts anonymous payments using cash since 2010. Customers are also able to pay anonymously using Bitcoin if they are able to source Bitcoins anonymously.
    • All VPN servers are built using Open Source software e.g. CentOS, OpenVPN, StrongSWAN etc.
    • Vulnerability disclosure process.
    • Warrant canary.
    • IVPN is a transparent organisation with published information about staff on the website and Linkedin profiles.
    • In-depth privacy guides for IVPN customers.

Spotted a mistake or have an idea on how to improve this page?
Suggest an edit on GitHub.