Is CyberGhost Safe? Security, Privacy & Audit Analysis

Is CyberGhost safe? Independent audit results, encryption protocols, jurisdiction analysis, kill switch testing, and no-logs policy verification.

··9 min read

Is CyberGhost Safe? Encryption, Audits, and Logging Explained

612 Mbps 11,500+ servers 100 countries 45-day money-back guarantee

CyberGhost earns a trust score of 85/100. It uses AES-256 encryption, operates under Romanian jurisdiction outside 14 Eyes alliances, and publishes quarterly transparency reports. An independent audit by Deloitte in 2022 confirmed its no-logs policy. CyberGhost routes traffic through 11,500+ servers across 100 countries with built-in leak protection.

Jurisdiction: Why Romania Matters

CyberGhost operates under CyberGhost S.R.L., headquartered in Bucharest, Romania. Romania has no mandatory data retention laws for VPN providers. The country rejected the EU Data Retention Directive twice, in 2009 and 2014.

Romania sits outside the 5 Eyes, 9 Eyes, and 14 Eyes intelligence-sharing alliances. This means foreign agencies cannot compel CyberGhost to hand over user data through partner agreements. Romanian authorities need a valid court order to request information from any company.

Even with a court order, CyberGhost states it cannot provide what it does not store. The company’s parent organization is Kape Technologies, based in the UK. However, CyberGhost’s data processing stays in Romania under Romanian law. Kape also owns ExpressVPN, Private Internet Access, and ZenMate.

CyberGhost Audit History

Deloitte Romania completed an independent audit of CyberGhost’s no-logs infrastructure in 2022. The auditors examined server configurations, internal policies, and data handling processes across CyberGhost’s entire network. Deloitte confirmed that the server setup matched CyberGhost’s public no-logs claims.

This audit followed the Type 1 SOC framework, evaluating whether controls existed and were properly designed. Deloitte found no evidence that CyberGhost stored connection logs, browsing activity, or traffic data. The audit report confirmed that servers operated in RAM-only mode.

Before Deloitte, CyberGhost had not undergone a formal third-party audit. The company relied on quarterly transparency reports starting in 2011 to demonstrate its commitment. These reports detail the number of law enforcement requests received and how CyberGhost responded to each one.

CyberGhost publishes these transparency reports on its website every 3 months. Each report shows that zero data requests have been fulfilled because no identifiable data exists. A second Deloitte audit would strengthen long-term trust, but no follow-up has been announced publicly.

CyberGhost No-Logs Policy: What Gets Stored

CyberGhost’s privacy policy explicitly states it does not log browsing history, traffic destinations, or DNS queries. It also does not store connection timestamps, session durations, or assigned IP addresses. The policy covers all 11,500+ servers across its network.

What CyberGhost does NOT store:

  • Browsing activity or visited websites
  • Downloaded file names or torrent data
  • Original IP addresses or assigned VPN IP addresses
  • Connection timestamps or session length
  • DNS queries or traffic volume per session

What CyberGhost does collect:

  • Anonymous, aggregated connection attempts for troubleshooting (no user identification)
  • Account email address and payment information for subscription management
  • Approximate device type for app improvement analytics

CyberGhost uses anonymous tokens for authentication on its servers. This system breaks the link between your account credentials and your VPN session. The company cannot match a specific user to a specific server connection at any given time.

RAM-only servers add another layer. These servers write nothing to hard drives, and every reboot wipes all session data completely. Physical seizure of a server yields zero usable information about past connections.

Encryption Standards and Protocols

CyberGhost uses AES-256-GCM encryption as its default cipher across all applications. This is the same encryption standard that the U.S. government uses for classified information. Breaking AES-256 would require computational power that does not exist today.

CyberGhost supports 4 VPN protocols across its apps:

  • WireGuard: Default on most platforms. Uses ChaCha20 encryption. Averages 15-30% faster speeds than OpenVPN.
  • OpenVPN (UDP/TCP): Uses AES-256-GCM. UDP offers faster speeds. TCP works better on restricted networks.
  • IKEv2/IPsec: Preferred on iOS and mobile devices. Handles network switching efficiently between Wi-Fi and cellular.
  • L2TP/IPsec: Legacy option. Available but not recommended for primary use.

Each protocol implements Perfect Forward Secrecy through ephemeral key exchanges. This means each session generates a unique encryption key. Compromising one session key does not expose past or future sessions.

Kill Switch and DNS Leak Protection

CyberGhost includes a kill switch on Windows, macOS, iOS, Android, and Linux applications. The kill switch blocks all internet traffic if the VPN connection drops unexpectedly. It activates automatically with no user configuration required.

On Windows and macOS, the kill switch operates at the system level. It modifies firewall rules to prevent any packet from leaving outside the VPN tunnel. Testing with standard leak detection tools shows zero IPv4, IPv6, or WebRTC leaks during connection drops.

CyberGhost also runs its own private DNS servers. Every DNS query routes through encrypted tunnels to CyberGhost-operated resolvers. This prevents ISPs and third parties from seeing which domains you request. No third-party DNS services like Google or Cloudflare handle your queries.

IPv6 leak protection is enabled by default. CyberGhost blocks IPv6 traffic entirely rather than routing it through the tunnel. This approach eliminates a common vulnerability that cheaper VPNs often overlook.

Past Security Incidents

CyberGhost has not suffered a confirmed data breach or server compromise as of early 2025. No user data has been exposed through vulnerabilities in CyberGhost’s infrastructure.

In 2016, concerns emerged when Crossrider (later renamed Kape Technologies) acquired CyberGhost. Crossrider had past associations with adware distribution. CyberGhost addressed this by stating that its operations, team, and infrastructure remained independent in Romania. Kape has since repositioned itself entirely as a privacy and security company.

In 2019, a report surfaced about a data breach at a CyberGhost-linked customer support platform. CyberGhost clarified that only 120 email addresses and support ticket content were potentially affected. No VPN usage data, passwords, or payment information was exposed. The incident involved a third-party support tool, not CyberGhost’s VPN servers.

CyberGhost responded by migrating its support systems and increasing security requirements for third-party tools. The company added 2-factor authentication for internal systems and reviewed all vendor relationships.

Unique Security Features

CyberGhost offers several features that distinguish it from competitors in the 85-trust-score range.

NoSpy Servers: CyberGhost operates a set of premium servers in its own data center in Romania. The company manages these servers exclusively without third-party involvement. NoSpy servers use dedicated uplinks and are physically accessible only to CyberGhost staff.

Content Blocker: Built into the apps, this feature blocks ads, trackers, and malicious domains at the DNS level. It processes blocking before traffic reaches your browser. This reduces data exposure without requiring a separate browser extension.

Dedicated IP Option: Users can purchase a static IP address that only they use. This token-based system assigns the IP without linking it to your account identity. It helps avoid CAPTCHAs and blocklists while maintaining privacy.

Automatic Wi-Fi Protection: CyberGhost detects new or unsecured Wi-Fi networks and connects the VPN automatically. Users can set rules for trusted and untrusted networks. This feature prevents accidental unprotected browsing on public hotspots.

Split Tunneling: Available on Android and Windows, split tunneling lets you route specific apps outside the VPN. You choose which apps use the encrypted tunnel and which use your regular connection.

Frequently Asked Questions

Is CyberGhost actually safe to trust with my data?

Yes. CyberGhost carries an 85/100 trust score, uses AES-256 encryption by default, and operates under Romanian jurisdiction outside the 5, 9, and 14 Eyes alliances. Deloitte independently audited its no-logs infrastructure in 2022 under the Type 1 SOC framework, confirming servers run RAM-only and store no browsing, connection, or DNS data.

Why does Romanian jurisdiction actually matter for CyberGhost’s privacy claims?

Romania has no mandatory data retention law and rejected the EU Data Retention Directive twice, in 2009 and 2014. Sitting outside 5, 9, and 14 Eyes intelligence-sharing means foreign agencies can’t compel CyberGhost through partner agreements. Romanian authorities still need a valid court order, and CyberGhost states it cannot hand over data it never stores.

Has CyberGhost ever had a data breach or security incident?

No breach has hit CyberGhost’s VPN infrastructure as of early 2025. A 2019 incident affected a third-party customer support platform, exposing roughly 120 email addresses and ticket content, not VPN usage data or passwords. CyberGhost responded by migrating support systems, adding two-factor authentication internally, and reviewing all vendor relationships afterward.

What encryption and protocols back CyberGhost’s security claims?

CyberGhost defaults to AES-256-GCM encryption and supports four protocols: WireGuard (ChaCha20, the default on most platforms), OpenVPN UDP/TCP, IKEv2/IPsec for mobile, and a legacy L2TP/IPsec option. Every protocol implements Perfect Forward Secrecy through ephemeral key exchanges, generating a unique key per session so compromising one session never exposes past or future traffic.

Has an independent auditor actually verified CyberGhost’s no-logs policy?

Yes. Deloitte Romania audited CyberGhost’s no-logs infrastructure in 2022, examining server configurations and data handling under the Type 1 SOC framework, confirming RAM-only server operation and no stored connection or browsing logs. Before that, CyberGhost relied solely on quarterly transparency reports since 2011. No follow-up audit has been publicly announced since 2022.

What information does CyberGhost actually collect if it doesn’t log activity?

CyberGhost collects only your account email and payment details for billing, an approximate device type for app analytics, and anonymized aggregated connection attempts used strictly for troubleshooting. It explicitly does not store browsing history, DNS queries, assigned IP addresses, timestamps, or session length, according to its published privacy policy and the 2022 Deloitte audit.

How do I confirm CyberGhost’s kill switch is actually protecting me?

Connect to a CyberGhost server on Windows or macOS, then force-disconnect your network mid-session. The kill switch operates at the system level, modifying firewall rules so no packet leaves outside the tunnel, and it’s available across Windows, macOS, iOS, Android, and Linux apps. Leak-detection testing shows zero IPv4, IPv6, or WebRTC leaks during drops.

What happens if CyberGhost’s DNS or IPv6 traffic leaks?

It shouldn’t under normal use: CyberGhost runs its own private DNS resolvers so queries never reach your ISP or third parties like Google or Cloudflare, and it blocks IPv6 traffic entirely by default rather than tunneling it, closing a leak vector cheaper VPNs often miss. If you suspect a leak, run a standard leak-detection tool while connected to confirm.

Does CyberGhost’s ownership by Kape Technologies raise any privacy red flags?

Kape Technologies, CyberGhost’s UK-based parent, was formerly Crossrider, which had past associations with adware before its 2016 acquisition of CyberGhost. CyberGhost states its team, infrastructure, and data processing remain independent and based in Romania under Romanian law. Kape also owns ExpressVPN, Private Internet Access, and ZenMate, and has since repositioned as a privacy-focused company.

How does CyberGhost’s security profile stack up against NordVPN and ExpressVPN?

CyberGhost ranks #10 of 22 in our Speed Lab, aggregated from independent labs, versus NordVPN’s #1 and ExpressVPN’s #8. All three run independently audited no-logs policies (Deloitte for CyberGhost, Cure53 for NordVPN, PwC and Cure53 for ExpressVPN) and offer AES-256 encryption with a kill switch, though CyberGhost’s 45-day refund window beats both providers’ 30-day guarantees.

How many devices can I keep protected under CyberGhost’s security features?

A single CyberGhost account covers 7 simultaneous device connections, each getting the same kill switch, AES-256 encryption, and DNS leak protection. That’s fewer than NordVPN’s 10 or ExpressVPN’s 10 to 14 depending on plan, but CyberGhost also offers NoSpy servers, company-owned Romanian infrastructure with no third-party involvement, as an added layer for sensitive use.

What if I’m not convinced by CyberGhost’s privacy claims after subscribing?

CyberGhost backs every plan with a 45-day money-back guarantee, longer than NordVPN’s or ExpressVPN’s 30-day windows, giving you extra time to test the kill switch, run leak-detection tools, and review the quarterly transparency reports yourself before committing. If the audited no-logs claims don’t hold up to your own scrutiny, you can cancel within that window.

Can CyberGhost be forced to hand over my data if authorities request it?

Only with a valid Romanian court order, and even then CyberGhost states it has nothing to hand over since it stores no browsing, connection, or DNS data. The company publishes transparency reports every three months detailing law enforcement requests received, and every report to date shows zero requests fulfilled because no identifiable data exists to release.