NordVPN reinforces its security credentials with independent audit

Cartoon image of three people using smartphones and laptops
(Image credit: NordVPN)

NordVPN has proved its security credentials following an independent security audit by cybersecurity auditing firm Cure53.

The team conducted a penetration test and source code review of NordVPN applications, browser extensions, and features between June and August 2024.

Leading security credentials is one of the reasons NordVPN is classed as our best VPN, and Cure53's recommendations were immediately addressed, strengthening the security of NordVPN.

NordVPN: the best VPN overall$3.39 per month

NordVPN: the best VPN overall
If you're looking for a great all round VPN provider, then look no further than NordVPN. It boasts class-leading privacy and security, backed up by independent audits. It's super fast, great for streaming, and comes packed with features. Up to 10 devices can be protected on one plan and prices for a 2-year plan start at $3.39 per month ($81.36 up front). There's also a 30-day money-back guarantee so you can try NordVPN out before committing.

Audit details

Cure53's assessment included penetration testing and a source code review of NordVPN's desktop applications (Windows, macOS, and Linux), mobile apps (iOS and Android), browser extensions (Chrome, Edge, and Firefox), and features including Threat Protection Pro and Meshnet.

A total of 31 findings were discovered. 22 were classified as security vulnerabilities and nine were categorized as general weaknesses, with lower exploitation potential. Due to the broad scope of Cure53's examination, a higher number of issues were expected but no critical vulnerabilities were found.

Several "high" severity vulnerabilities were discovered and Cure53 recommended their resolutions were prioritized. To safeguard the integrity of services and features and protect users from emerging threats and vulnerabilities, Cure53 recommended regular security assessments.

As soon as the assessment was complete and findings reported, NordVPN addressed the findings and strengthened the security of its service. Several high level vulnerabilities were carefully addressed and fixed. Remaining issues were resolved where possible and negative effects on user experience were avoided.

NordVPN no-logs graphic

(Image credit: NordVPN)

Cure53 noted that once the issues had been addressed, NordVPN will reach a sufficiently secure state. The use of libraries including NGHTTP2, OpenSSL, and Boost was commended by Cure53. They are known for stability and security and contribute to NordVPN's overall security.

"Security is at the core of everything we do at NordVPN. Independent assessments like this allow us to continuously refine our technology and stay ahead of emerging threats," said Marijus Briedis, CTO of NordVPN.

"The findings from Cure53 reinforced our strong security foundation, and our team swiftly implemented all necessary improvements to ensure the highest level of protection for our users."

As well as proving its security, NordVPN has recently proven its privacy claims. An independent audit of its IT systems, supporting infrastructure, and no-logs policy was commissioned at the end of 2024 – with its no-logs policy verified for a fifth time.

"Our work towards improving security is never finished, and we will keep moving forward," added Briedis. "The latest Cure53 assessment confirms that NordVPN apps are built on a strong foundation with no critical risks. We are proud of the results and will keep making NordVPN one of the most secure VPN services available to everyone."

Cure53's full report is available via the user control panel on NordVPN's website or by following this link.

Disclaimer

We test and review VPN services in the context of legal recreational uses. For example: 1. Accessing a service from another country (subject to the terms and conditions of that service). 2. Protecting your online security and strengthening your online privacy when abroad. We do not support or condone the illegal or malicious use of VPN services. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.

George Phillips
Staff Writer

George is a Staff Writer at Tom's Guide, covering VPN, privacy, and cybersecurity news. He is especially interested in digital rights, censorship, data, and the interplay between cybersecurity and politics. Outside of work, George is passionate about music, Star Wars, and Karate.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
NordVPN no-logs graphic
NordVPN will never store your data – and it can prove it
NordVPN vs Surfshark
NordVPN vs Surfshark: Which provider is best?
VPN audit
What is a VPN audit?
Graphic of red warning sign
Critical VPN vulnerabilities continue to impact businesses
most private vpn
The most private VPN in 2025
Mullvad on a laptop
Is Mullvad still worth buying?
Latest in VPNs
Cartoon image of three people using smartphones and laptops
NordVPN reinforces its security credentials with independent audit
ExpressVPN on an iPhone
What is ExpressVPN's Personal Data Removal?
VPN on phone in front of US flag
43% of Americans use VPNs – should you?
PIA
What is MACE from Private Internet Access?
ExpressVPN
Claim a week of ExpressVPN for free – we don't know when it's going to end
Flag of Iran flying
80% of Iranians are using VPNs to access the internet – but could government restrictions loosen?
Latest in News
3D printed models of alleged iPhone 17 Air and iPhone 17 Pro design
iPhone 17 Air dummy model shows off Apple’s big design change
Cartoon image of three people using smartphones and laptops
NordVPN reinforces its security credentials with independent audit
Christopher Briney as Conrad and Lola Tung as Belly in The Summer I Turned Pretty
Prime Video top 10 shows — here’s the 3 worth watching right now
RTX 50 series GPUs
I was hyped for Nvidia's RTX 5060 Ti and RTX 5050 — until I saw these leaked specs
iPhone 17 Air render
iPhone 17 Air screen size and specs leak — here's what you need to know
Google Chromecast in TV
Chromecast fail — users across the world are saying that their Chromecasts are not working