How to Choose a VPN in 2026: Start With Who Is Watching
A VPN is excellent against two adversaries, barely useful against a third and irrelevant against the rest. Work out which row you are in, learn what a no-logs claim is worth without an audit, and test the result yourself in ten minutes.

Almost every "best VPN" list is ordered by affiliate commission and reads like it. The more useful question is the one they skip, because answering it honestly disqualifies most of the recommendations: who are you hiding from? A VPN is extremely good against one or two adversaries, mildly useful against a third, and irrelevant against the rest. Work out which row you are in and the shortlist writes itself.
This is a framework rather than a ranking, followed by an assessment of one provider against it — including the parts that count against it.
Start with who is watching
A VPN does exactly one thing: it moves the point at which your traffic enters the open internet, from your network to someone else's, and encrypts the leg in between. Everything a VPN can and cannot do follows from that single sentence.

The two rows where it genuinely transforms your position are your ISP and untrusted local networks. Your ISP can see every domain you resolve and sells that in several countries; a VPN replaces that view with a single encrypted connection. On a café or hotel network, you are moving your trust from an operator you know nothing about to one you have at least chosen.
The row where people most often believe they are protected and are not is the websites themselves. You are identified when you log in, and tracked by cookies and browser fingerprint regardless of your IP address. Changing the address a request arrives from does not make you anonymous to a site that already knows who you are.
What a no-logs claim is actually worth
Every provider says "no logs". The words cost nothing. What separates a claim from a fact is evidence, and there are four tiers of it:
- An independent audit with a published report. Not "audited" as a badge — a named firm, a dated report you can read, and ideally a repeat engagement rather than one done once at launch. Ask what scope was audited: a no-logs audit and a security audit are different exercises, and a provider will happily let you conflate them.
- A transparency report. How many legal requests arrived, and what was produced. The valuable number is the second one.
- A warrant canary. A statement that no secret order has been received, which is removed rather than contradicted if one arrives. Legally untested in most places, but its removal is a signal.
- A court case where they had nothing to hand over. The strongest evidence there is, and only a handful of providers have it.
Treat a provider with none of these as unverified. That is not an accusation — it is the correct default for a claim about something you cannot observe.
Jurisdiction, and how much it really matters
Where the company is incorporated decides who can compel it and whether it can tell you. The UK's Investigatory Powers Act, for instance, allows orders that come with a gag; the Five Eyes arrangement means an agency in one member can often obtain what another collects. This is why privacy-focused providers cluster in Panama, Switzerland and the British Virgin Islands.
But keep it in proportion. A provider that genuinely stores nothing is safe in a bad jurisdiction, and a provider that quietly keeps connection logs is unsafe in a good one. Jurisdiction is a multiplier on your logging assessment, not a substitute for it. Use it to break ties, and weight it heavily only if your threat model involves a state that can serve legal process.
Protocols, and the one that matters on a hostile network
WireGuard is the modern default: fast, around 4,000 lines of auditable code against OpenVPN's hundreds of thousands, and quick to reconnect when you move between networks. One design detail worth knowing — it assigns each peer a static internal address, which is state a provider has to deliberately engineer around if it wants to keep nothing. Ask how they do it.
OpenVPN is slower and much larger, but has two decades of scrutiny behind it and runs over TCP 443 when it needs to blend in. IKEv2/IPsec handles network switching gracefully and is the reason your phone's VPN survives moving from Wi-Fi to mobile data.
Then there is the category that decides everything on a censored network. Standard VPN protocols have a recognisable shape, and deep packet inspection classifies traffic by shape rather than content. A censor does not need to break your encryption to block you; it only needs to recognise that a VPN handshake happened. Obfuscated or stealth protocols exist to remove that signature — making the traffic indistinguishable from ordinary TLS, and, in the better implementations, making the server itself answer an unauthenticated probe exactly like a normal web server. That second half matters more than people expect: censors actively probe suspected endpoints, and a server that replies "I am a VPN, but I need a key" has already told them what they wanted to know.
The honest position on China, Iran and Russia
No provider can promise this, and one that does is telling you something about its marketing rather than its engineering.
Circumvention is an arms race measured in weeks. A protocol that works today can be fingerprinted next month; access is throttled or cut entirely during protests and elections; providers are blocked at the app store before they are blocked on the wire. Any article stating that a particular VPN "works in China" is describing a test from whenever it was written, and the internet does not stay still.
What actually survives contact:
- Install before you travel. App stores in these countries frequently do not carry VPN clients, and provider websites are blocked. Download the app and save a direct installer.
- Carry two providers. Not two servers — two independent companies, because they fail at different times.
- Use the stealth protocol, not the fast one. On a hostile network the defaults are the wrong choice.
- Know the legal position, not just the technical one. In several of these countries the risk is not that the connection fails; it is what happens if you are found using an unapproved one. That is a decision only you can make, and no software removes it.
The metrics that are marketing
Server count. Five thousand servers in thirty countries is thirty countries. What matters is whether the locations you actually need are present, whether the hardware is owned or rented from whoever is cheapest, and whether it runs from RAM so a seized machine yields nothing.
"Military-grade encryption." This means AES-256, which is also what your bank, your browser and every HTTPS connection you make today already use. It is a phrase that describes the industry baseline as though it were a feature.
Speed test screenshots. Meaningless without the route, the time of day and the protocol. Your own trial on your own connection is worth more than any published benchmark.
Test it yourself, in ten minutes
Whatever you choose, verify it rather than trusting the app's green tick.
# 1. Address actually changed?
curl -s ifconfig.me
# 2. DNS not leaking to your ISP — check the resolver that answers
# (run it connected, then disconnected, and compare)
dig +short whoami.akamai.net @ns1-1.akamaitech.net
# 3. IPv6 not leaking around the tunnel
curl -s -6 ifconfig.me || echo "no IPv6 route — good"Then the two that need a browser: a WebRTC leak test, because WebRTC can reveal your real address from inside the page even with the tunnel up, and a kill switch test — start a large download, disable the network adapter the VPN runs over, and confirm the transfer stops rather than continuing in the clear.
JaguarVPN, assessed against the above
We picked this one to work through because its stealth design is more interesting than the category usually manages, and because it illustrates how to read a provider properly — the good and the missing together.
What stands up. The stealth protocol, Mirage, is built the way the threat actually works: multi-hop relaying across entry, relay and exit nodes so no single machine holds both ends of the picture, no classifiable signature on the wire, and servers that answer an unauthenticated probe like an ordinary website rather than announcing themselves. That last property is the one most obfuscation implementations omit. There is a published transparency report, dated and versioned, reporting zero law-enforcement requests and zero data produced since launch, alongside a warrant canary and a public law-enforcement request policy. A RAM-only fleet, a kill switch, split tunnelling, DNS-level ad and tracker blocking, and multi-hop on the higher tier. Pricing is competitive at around US$54 a year for one device and US$80 for three, with a seven-day trial that does not ask for a card — which means you can run the tests above before paying anything.
What counts against it. The network is small: its own servers page lists four countries, against sixty or more from the large providers. If you need a specific country for a specific reason, check the list before anything else — this is the constraint most likely to rule it out for you. It is UK-incorporated, which places it inside Five Eyes and under the Investigatory Powers Act; that matters less if the no-logs architecture holds, and we have no way to confirm from outside that it does. There is no independent no-logs audit published, which is the single thing that would most strengthen the claim. And both protocols are proprietary — Umbra and Mirage are the company's own, so they have not had the external cryptographic review that WireGuard and OpenVPN have accumulated over years. A well-described design is not the same as a reviewed one.
Where we land. Worth the free trial if your problem is getting a connection out of a restrictive network and you do not need broad geographic coverage — the stealth architecture is genuinely well thought through and the transparency reporting is better than most providers of this size bother with. Not the pick if you need a long country list, or if an audited no-logs claim is a requirement rather than a preference. We have not tested it under censorship conditions, and nobody should take an untested claim about that from us or anyone else.
For the record: we have no commercial relationship with JaguarVPN, no affiliate arrangement with them or with any provider mentioned, and were not asked or paid to include them.
Choosing, in one pass
- You want your ISP out of your browsing. Almost any reputable paid provider does this. Optimise for price and a client that works on your devices.
- You use public Wi-Fi a lot. Same, plus a kill switch you have actually tested.
- You need a specific country. Check the server list first. This single requirement eliminates more providers than any other.
- You are on a network that hunts VPNs. Stealth protocol and active-probe resistance are the whole decision. Carry a second provider.
- Your threat model includes legal process against the provider. Audited no-logs, a favourable jurisdiction and a transparency report — all three, not one.
- You want to be anonymous. A VPN is not the tool. Tor is closer, and even then the discipline around it matters more than the software.
Sources and scope
Provider details above — server countries, protocols, pricing, transparency reporting — were read from JaguarVPN's own published pages on 21 September 2026 and are its claims, not our measurements. Prices are as listed in US dollars and vary by currency and billing period. We have not run speed tests, have not verified any no-logs claim independently, and have not tested any provider inside a censored network; nobody can verify a no-logs claim from outside, which is precisely why independent audits matter.
Jurisdiction and protocol characteristics are general and stable; provider features, prices and server lists change frequently, so check the current pages before buying. Using a VPN is restricted or illegal in some countries, and circumventing a service's regional licensing generally breaches its terms of service. Both are your decision to make with the facts in front of you.


