VPNSmith
self-host-vpnINFO

Security Headers of 99 VPN and Privacy Websites, Measured (August 2026)

We scanned the homepages of 99 VPN providers, password managers, encrypted messengers and privacy tools for HTTP security headers. Three score 100/100; 22 declare none at all. Full table, published method, and the scanner so you can re-run it.

By Eric Gerard · Founder · VPNSmith - Self-host VPN & GDPR VPS specialist18 min readPhoto: Pexels

When a tool's entire pitch is privacy, its own website is the first thing a visitor can actually check. So we checked it - on 99 sites across VPN providers, password managers, encrypted messengers, self-hosted tools and privacy-focused hosts.

What the score is, and what it is not

This is the part to read before the table, because a number without its meaning is worse than no number.

We measure what the web server declares to your browser. Eight headers, on the homepage, on one day. That is the whole scope.

We do not measure the product. A password manager scoring F here may have flawless cryptography; a VPN scoring A+ may still keep logs. The headers say whether someone switched on the browser-side hardening. That is a signal about engineering care, not a verdict on the software.

If you take one thing from this page: a low grade is not an accusation, and a high grade is not a guarantee.

How the score is calculated

Eight headers, weighted by what each actually prevents rather than counted equally:

HeaderPointsWhat it prevents
Content-Security-Policy25script injection - the broadest single defence
Strict-Transport-Security20silent downgrade to plain HTTP
X-Content-Type-Options10MIME sniffing
X-Frame-Options10clickjacking (or frame-ancestors in CSP)
Referrer-Policy10URL leakage to third parties
Permissions-Policy10unrequested camera, microphone, geolocation
Cross-Origin-Opener-Policy10cross-origin window interference
Cross-Origin-Resource-Policy5unwanted cross-origin embedding

Grades: A+ 90-100 · A 75-89 · B 60-74 · C 40-59 · D 20-39 · F under 20.

A site that uses frame-ancestors inside its CSP receives the X-Frame-Options points. Without that rule we would have penalised sites for choosing the more modern option - a flaw in our scoring, not in their configuration.

Seven sites could not be measured (timeout, certificate failure, or an automated client refused). Their rows are empty, not zero. A failed measurement is not a finding.

A black laminated padlock hanging on a black square-grid metal fence, photographed against a pale green-grey sky that fills the squares of the grid.
A black laminated padlock hanging on a black square-grid metal fence, photographed against a pale green-grey sky that fills the squares of the grid.

A padlock on a grid fence, the sky showing through every square. Headers work the same way: each one closes a specific opening, and the ones you leave out stay open regardless of how good the lock is.

The full ranking, August 2026

#SiteGradeScoreCSPHSTSX-CTOXFORefPermsCOOPCORP
1grapheneos.orgA+100✅✅✅✅✅✅✅✅
2mullvad.netA+100✅✅✅✅✅✅✅✅
3whonix.orgA+100✅✅✅✅✅✅✅✅
4cryptpad.frA+90✅✅✅✅✅✅,✅
5bitwarden.comA85✅✅✅✅✅✅,,
6cryptostorm.isA85✅✅✅✅✅✅,,
7duckduckgo.comA85✅✅✅✅✅✅,,
8element.ioA85✅✅✅✅✅✅,,
9exodus-privacy.eu.orgA85✅✅✅✅✅✅,,
10netbird.ioA85✅✅✅✅✅✅,,
11njal.laA85✅✅✅✅✅,✅,
12posteo.deA85✅✅✅✅✅✅,,
13startmail.comA85✅✅✅✅✅✅,,
14vaultwarden.devA85✅✅✅✅✅✅,,
15windscribe.comA85✅✅✅✅✅✅,,
16www.dashlane.comA85✅✅✅✅✅✅,,
17www.passbolt.comA85✅✅✅✅✅✅,,
181password.comA75✅✅✅✅✅,,,
19azirevpn.comA75✅✅✅✅,✅,,
20nextcloud.comA75✅✅✅✅✅,,,
21privacytools.ioA75✅,✅✅✅✅✅,
22proton.meA75✅✅✅✅✅,,,
23searx.beA75✅✅✅✅✅,,,
24standardnotes.comA75✅✅✅✅✅,,,
25threema.chA75✅✅✅✅✅,,,
26tutanota.comA75✅✅✅✅✅,,,
27www.ovpn.comA75✅✅✅✅✅,,,
28www.scaleway.comA75✅✅✅✅✅,,,
29www.startpage.comA75✅✅✅✅✅,,,
30www.torproject.orgA75✅✅✅✅✅,,,
31cryptomator.orgB65✅✅✅✅,,,,
32firezone.devB65✅✅,✅,✅,,
33ivpn.netB65✅✅✅✅,,,,
34libreswan.orgB65✅✅,✅✅,,,
35mailbox.orgB65✅✅✅✅,,,,
36tailscale.comB65✅✅✅✅,,,,
37www.lastpass.comB65✅✅✅✅,,,,
38www.privacyguides.orgB65✅✅✅,✅,,,
39www.wire.comB65✅✅,✅✅,,,
40matrix.orgB60,✅✅✅✅✅,,
41netfoundry.ioB60,✅✅✅✅✅,,
42obsidian.mdB60,✅✅✅✅✅,,
43openziti.ioB60,✅✅✅✅✅,,
44traefik.ioB60,✅✅✅✅✅,,
45www.mojeek.comC55✅,✅✅✅,,,
46airvpn.orgC50,✅✅✅✅,,,
47owncloud.comC50,✅✅✅✅,,,
48protonvpn.comC50,✅✅✅✅,,,
49www.expressvpn.comC50,✅✅✅✅,,,
50www.twingate.comC50,✅✅✅,,✅,
51hetzner.comC40,✅✅✅,,,,
52keepassxc.orgC40,✅✅,✅,,,
53tails.netC40,✅✅✅,,,,
54www.pfsense.orgC40,✅✅✅,,,,
55www.wireguard.comC40,✅✅✅,,,,
561984.hostingD35✅,,✅,,,,
57nordpass.comD30,,✅✅✅,,,
58surfshark.comD30,✅✅,,,,,
59www.privateinternetaccess.comD30,✅,✅,,,,
60briarproject.orgD20,✅,,,,,,
61contabo.comD20,✅,,,,,,
62defined.netD20,,✅,✅,,,
63getoutline.orgD20,,✅,✅,,,
64hysteria.networkD20,,✅,✅,,,
65joplinapp.orgD20,✅,,,,,,
66nginx.orgD20,✅,,,,,,
67openvpn.netD20,✅,,,,,,
68signal.orgD20,,✅,✅,,,
69simplex.chatD20,✅,,,,,,
70tosdr.orgD20,✅,,,,,,
71www.eff.orgD20,,✅✅,,,,
72www.netmaker.ioD20,✅,,,,,,
73www.opnsense.orgD20,✅,,,,,,
74www.ovhcloud.comD20,,✅✅,,,,
75www.portainer.ioD20,✅,,,,,,
76www.strongswan.orgD20,✅,,,,,,
77xtls.github.ioD20,✅,,,,,,
78runbox.comF10,,,,✅,,,
79www.cyberghostvpn.comF10,,,✅,,,,
80www.digitalocean.comF10,,,✅,,,,
81www.hostinger.comF10,,,,,,✅,
82www.shadowsocks.orgF10,,✅,,,,,
83zerotier.comF10,,✅,,,,,
84caddyserver.comF0,,,,,,,,
85calyxos.orgF0,,,,,,,,
86delta.chatF0,,,,,,,,
87headscale.netF0,,,,,,,,
88husarnet.comF0,,,,,,,,
89keepass.infoF0,,,,,,,,
90pivpn.ioF0,,,,,,,,
91psono.comF0,,,,,,,,
92rclone.orgF0,,,,,,,,
93seafile.comF0,,,,,,,,
94syncthing.netF0,,,,,,,,
95uptimekuma.orgF0,,,,,,,,
96www.qubes-os.orgF0,,,,,,,,
97www.softether.orgF0,,,,,,,,
98www.tinc-vpn.orgF0,,,,,,,,
99www.veracrypt.frF0,,,,,,,,

Did your site earn an A+, A or B? Take the badge

If your site scored B or better, you are welcome to display it. The badge links back to this page so anyone can verify the grade against the published table and re-run the scanner themselves - which is the only reason a badge like this is worth anything.

There is one badge per grade. Swap -aplus for -a or -b to match the grade in the table above.

<a href="https://www.vpnsmith.com/en/blog/vpn-privacy-security-headers-2026">
  <img src="https://www.vpnsmith.com/badges/security-headers-2026-aplus.svg"
       alt="Security Headers 2026 - grade A+ - measured by VPNSmith" width="184" height="40">
</a>
gradebadge file
A+https://www.vpnsmith.com/badges/security-headers-2026-aplus.svg
Ahttps://www.vpnsmith.com/badges/security-headers-2026-a.svg
Bhttps://www.vpnsmith.com/badges/security-headers-2026-b.svg

Each badge is a static SVG with no script and no cookie. Being a privacy audience, you will want the rest of it stated plainly: served from our domain it is a third-party request, and our web server logs it the way any web server logs an image. So host it yourself - download the SVG, put it on your own domain, keep the link. That is the version we recommend, and it changes nothing for us: we count badges by reading public HTML, never by reading our logs.

No conditions attached. We do not ask for anything in return, we do not require the link to be followed, and the badge keeps working whether or not you tell us you used it.

Download the raw data

The table above is not the dataset - it is a rendering of it. The measurements themselves are here, one row per site, one column per header:

vpn-privacy-security-headers-2026.csv

  • 106 rows: 99 measured, 7 left with empty score fields because the request failed. A failed measurement is not a zero, and writing it as one is how surveys quietly become wrong.
  • njalla.no was measured (85, grade A) and removed as the same entity as njal.la. That is why the table has 99 rows and not 100.
  • Correction, 17 August: six domains redirect their homepage elsewhere, so we measured the destination and filed it under the name we started from. A homepage_redirects_to column now records every one: openziti.io→netfoundry.io, vaultwarden.dev→vaultwarden.com, threema.ch→threema.com, tutanota.com→tuta.com, www.veracrypt.fr→veracrypt.io, uptimekuma.org→uptimekuma.co. One of those makes the table double-count: openziti.io and netfoundry.io are the same server and carry identical rows, so the 99 rows cover 98 distinct hosts. We are leaving both rows visible with the redirect annotated rather than quietly renumbering, because you can check the redirect yourself and a silent edit would be worse than the error.
  • Released into the public domain under PDDL 1.0. Reuse it, republish it, correct it. No attribution required - though if you cite it, cite the measurement date, because headers change.

Together with the MIT-licensed scanner, this is everything needed to reproduce, contest or extend the ranking. We would rather be corrected than believed.

We ran a second measurement over the same 106 domains, asking a different question of the same servers: whether any of them has told an AI crawler anything at all in robots.txt. Ninety of the hundred that answered have never named a single one - which is a useful reminder that a header table measures what a server was configured to say, not what its operator has thought about.

Improved your headers? Ask for a re-test

The scanner is MIT-licensed and dependency-free, so you can reproduce our number before you even contact us. If you have changed your configuration and want the table to reflect it, say so and we will re-measure and update the row. A site raising its score is the outcome this page exists to encourage - a ranking that only names and shames is a ranking nobody improves for.

Reproduce every number here

The measurement is worth exactly as much as your ability to check it. The scanner queries each homepage once, reads the response headers, and applies the table above. No key, no scraping, no account.

The scanner: security-headers-scan.py, MIT, no dependencies, one argument (a text file with one domain per line). It queries each homepage once, reads the response headers, and applies the weights in the table above. Run it against this list and you should reproduce our column values exactly; if you do not, we would like to know.

If you want the wider context on why these headers matter for a self-hosted setup, our WireGuard vs OpenVPN comparison covers the transport side, and choosing a VPS for a VPN covers the host you would be hardening.

The same method applied to a single provider: we scanned NordVPN's own security headers and published the result.

And your own exposure?

This page measures what 99 companies declare to your browser. The mirror question is what your browser declares to them, and it is the one you can act on today.

We built a short self-assessment on the same principle as this ranking: measured, not guessed, with the method stated. Browser fingerprint is a passive measurement, no questions asked: it counts how many distinctive attributes your setup exposes, and tells you plainly when your browser is defending itself. Attack surface and Phishing resistance are two short tests, under two minutes each.

Measure your browser fingerprint · Attack surface · Phishing resistance

Free, no account, nothing stored about you. It is ours, and we mark these links nofollow on purpose: we are sending you there because it is useful, not to pass ranking signal to ourselves.

★ Nuremberg GDPR datacenter · ✓ Dedicated IPv4 included · 200+ Mbps guaranteed

Self-host your VPN on your own VPS → ContaboFull root access · public IPv4 · pick your region→

Frequently asked questions

What exactly does this score measure?
The presence of eight HTTP security headers on the site's homepage, and nothing else. It is a measurement of what the web server declares to your browser - not a security audit of the product. A password manager can score F here and still have excellent cryptography, because the two things are unrelated. Read the grade as 'how much of the browser-side hardening is switched on', not as 'how safe is this tool'.
How is the score calculated?
Eight headers, weighted by what they actually prevent: Content-Security-Policy 25 points, Strict-Transport-Security 20, X-Content-Type-Options 10, X-Frame-Options 10, Referrer-Policy 10, Permissions-Policy 10, Cross-Origin-Opener-Policy 10, Cross-Origin-Resource-Policy 5. CSP and HSTS carry the most because they block whole classes of attack rather than one behaviour. A site using frame-ancestors inside its CSP gets the X-Frame-Options points, since that is the modern equivalent.
My site scores lower than I expected. Can I get it re-tested?
Yes. The scanner is published under the MIT licence and has no dependencies, so you can run it yourself and get the same number we did. If you change your headers and want the table updated, tell us and we will re-measure - a site improving its score is the outcome this ranking exists to encourage.
Why do some sites have no score at all?
Seven of the 106 sites we tried could not be measured: the request timed out, the certificate failed to validate from our vantage point, or the host refused an automated client. Those rows are left empty rather than scored zero. A failed measurement is not a finding, and treating it as one is how surveys quietly become wrong.
Does a high score mean the site is secure?
No, and it would be dishonest to imply otherwise. Security headers are one visible layer among many. A site can declare all eight and still have an application vulnerability, and a site can declare none and be perfectly well built underneath. What the headers do tell you is whether someone thought about browser-side defence in depth - which is a reasonable signal, and nothing more than a signal.