INDEX / DIRECTORY / EXPRESSVPN / DIGITAL

ExpressVPN DIGITAL

DIGITAL INFRASTRUCTURE AUDIT UPDATED 2026-07-04
Digital Score 0.00 /10 C ExpressVPN - BDS-1000 403
Digital 0.00

Evidence-only forensic audit. Scoring happens downstream - see the main dossier for the composite assessment.

Forensic audits like this are reader-funded - no sponsors, no ads. Support OpenIntel →

Digital Domain Audit: ExpressVPN

Target: ExpressVPN (consumer VPN; Express Technologies Ltd / ExpressVPN Inc; owned by Kape Technologies plc) Domain: Digital (Digital / Technology) Date: June 2026 Scope: ExpressVPN’s own digital/data/cyber/surveillance/AI conduct re Israel. Kape group-level and sibling-brand tech is attributed at the parent-group level except where ExpressVPN itself relies on it or where Kape’s Israeli infrastructure intersects with ExpressVPN’s operations.

Enterprise Technology Stack & Vendor Relationships

Core protocol - Lightway: ExpressVPN’s proprietary VPN protocol, Lightway, was developed in-house and open-sourced under GPLv2 in 2021.1 It is built on the wolfSSL cryptographic library (a US-based vendor), supports AES-256-GCM and ChaCha20/Poly1305 encryption, and uses DTLS 1.2 for server authentication.2 The core codebase was rewritten in Rust and released in February 2025.3 Two independent security assessments of the Rust implementation - by Cure53 (October 2024) and Praetorian (September–December 2024) - each found a low number of low-severity findings, all subsequently remediated.4 A prior Cure53 audit of the C implementation was conducted in 2022.5 No Israeli vendors are identified in the Lightway technology stack; wolfSSL is a US company.

Post-quantum encryption: ExpressVPN integrated ML-KEM (the NIST-standardised Kyber algorithm) into Lightway in 2024, making post-quantum protection active by default.6

TrustedServer architecture: Launched in 2019 and audited by PwC under ISAE 3000, TrustedServer runs every VPN server entirely on volatile RAM; no data is written to persistent storage and each reboot wipes all state.7 KPMG provided ISAE 3000 Type I reasonable-assurance opinions on TrustedServer in 2022, 2023, and February 2025, each confirming that the architecture prevents collection of user activity logs.8 As of 2024, ExpressVPN held 23 completed independent audits.9

AWS as cloud backbone: ExpressVPN uses Amazon Web Services as its primary web infrastructure provider, including Amazon EC2 for compute and AWS Nitro Enclaves for security-sensitive workloads.10 The dedicated-IP (DIP) product is implemented inside AWS Nitro Enclaves: blinded tokens bearing no user-identifying information are issued inside cryptographically attested enclave environments, preventing even ExpressVPN staff from linking a dedicated IP to a specific customer account.11 AWS is a US-domiciled vendor; no Israeli sovereign cloud or government-cloud services are identified in ExpressVPN’s stack.

Router hardware - Aircove: In September 2022 ExpressVPN launched Aircove, a Wi-Fi 6 consumer router with VPN protection built in by default, sold initially on Amazon US at $169.12 No Israeli hardware component suppliers are identified in public disclosures.

Kape group backend integration (parent-group context - flagged): Following the September 2021 acquisition, Kape’s public communications referenced “shared back-end, billing, and support” across group brands and “integrated products” as synergies.13 ExpressVPN’s own announcement stated that customer data would continue to be “held in its own entity, under BVI jurisdiction,” and that it would operate as “a separate brand and service, run by our existing team.”14 The extent to which backend or billing systems are now shared with Kape’s Tel Aviv R&D operation - which employs approximately 120 engineers at the Azrieli Sarona Tower - is not publicly confirmed. This is a material gap for assessing whether ExpressVPN’s data-handling infrastructure has any Israeli technical touchpoint.

Surveillance, Biometrics & Retail Technology

Daniel Gericke / Project Raven - the central issue for this domain:

ExpressVPN’s Chief Information Officer Daniel Gericke is one of three former US intelligence operatives who entered into a Deferred Prosecution Agreement (DPA) with the US Department of Justice on 14 September 2021.15 The DPA resolved allegations that the three men - Gericke, Marc Baier, and Ryan Adams - committed violations of US export control law (ITAR), computer fraud statutes, and access-device fraud law by providing advanced offensive cyber-intelligence services to the UAE government without a required State Department licence.16

Specifically, while working at DarkMatter (a UAE-based intelligence contractor), Gericke and colleagues were alleged to have supervised the development of “zero-click” intelligence hacking systems capable of compromising target devices without any user interaction, targeting US citizens, foreign heads of state, and dissidents critical of the UAE government, including the Emir of Qatar and Yemeni human-rights activists.17 The operation was known publicly as Project Raven following earlier Reuters reporting. The three men were fined a combined $1,685,000 and accepted employment restrictions prohibiting work involving Computer Network Exploitation (CNE) activity or export of defence articles.18

What ExpressVPN knew and when: ExpressVPN hired Gericke as CIO in December 2019 - during or immediately after the period covered by the DPA. The company’s public statement acknowledged it was aware at the time of hire that Gericke had worked at CyberPoint and at DarkMatter, describing this as background that made him “an invaluable hire for our mission.”19 ExpressVPN stated it first learned of his involvement specifically in Project Raven and the existence of the DPA on 7 September 2021, when the DOJ finalised the agreement.20 The company chose to retain Gericke after the public disclosure, citing his offensive-security expertise as strengthening its defensive posture and arguing that structural safeguards (TrustedServer, least-privilege access) mitigated any personnel risk.21

Civil society response: Edward Snowden publicly stated that “if you’re an ExpressVPN customer, you shouldn’t be,” characterising the retention of a former UAE surveillance operative as fundamentally incompatible with a privacy service.22 ExpressVPN employees reportedly questioned management internally about the disclosure.23

Israel nexus assessment: Project Raven/DarkMatter is a UAE intelligence operation, not an Israeli one. No public evidence has been identified that Gericke’s UAE surveillance work had any Israeli component or that ExpressVPN’s hiring decision was motivated by Israeli state relationships. The significance for this audit is the demonstrated willingness of ExpressVPN leadership to hire and retain a senior executive with a documented offensive cyber-surveillance background - a structural trust question relevant to assessing ExpressVPN’s digital conduct standards more broadly.

Biometrics and retail surveillance: No public evidence identified of ExpressVPN deploying biometric, facial recognition, or retail surveillance technology.

Cloud Infrastructure, Data Residency & Sovereign Cloud Participation

Server network: ExpressVPN operates VPN servers in 105+ countries.24 This network includes servers in Israel: ExpressVPN’s own server-location page lists Tel Aviv as an available location, providing Israeli IP addresses to subscribers.25 These are standard VPN egress servers providing commercial connectivity; no evidence has been identified that they constitute shared infrastructure with Israeli state entities or sovereign cloud participation.

Virtual server locations: Some ExpressVPN “server locations” are virtual - traffic is routed through a server physically located elsewhere but advertising a local IP from the named country. ExpressVPN publishes a list of virtual server locations.26 It is not publicly confirmed whether the Tel Aviv listing is a physical or virtual server.

BVI data jurisdiction: ExpressVPN customer data remains held by Express Technologies Ltd, incorporated in the British Virgin Islands.27 No US, EU, or Israeli data-residency obligations are publicly identified as applicable to ExpressVPN’s subscriber database.

TrustedServer RAM architecture and data residency: Because TrustedServer purges all state on reboot and writes nothing to persistent storage, the geographic data-residency question for VPN traffic metadata is substantially moot by design - there is no persistent log to reside anywhere.28 This claim has been independently verified by PwC and KPMG.

DNS leak incident (2022–2024): A bug introduced in May 2022 in ExpressVPN’s Windows app (version 12.23.1) and persisting until February 2024 (version 12.72.0) caused DNS requests to leak outside the VPN tunnel when split tunnelling was enabled, routing them to users’ ISPs.29 ExpressVPN estimated less than 1% of its user base was affected. No Israeli data-handling dimension to this incident has been identified.

Sovereign cloud participation: No public evidence identified of ExpressVPN participating in Israeli sovereign cloud programmes or government-cloud procurement.

Defence, Intelligence & Security Sector Technology Relationships

DOJ deferred prosecution / Project Raven: The core defence-sector relationship already documented is the confirmed prior employment of ExpressVPN’s CIO Daniel Gericke in an offensive cyber programme operated by a state intelligence contractor (DarkMatter/UAE). This is the only confirmed defence-intelligence sector technology relationship for ExpressVPN directly.

Israeli defence sector: No public evidence identified of ExpressVPN holding contracts with, or providing services to, the Israel Defense Forces, Israeli intelligence agencies (Shin Bet, Mossad, Unit 8200), or Israeli defence contractors.

Kape Technologies leadership - Israeli military backgrounds (parent-level context - flagged): Kape’s co-founder and early CEO Koby Menachemi is reported to be a Unit 8200 veteran.30 Kape’s subsequent CEO Ido Erlichman (2016–2023) is a veteran of the IDF’s Duvdevan commando unit.31 These are Kape group-level personnel, not ExpressVPN personnel, and are attributed to Kape at the parent level, recorded as context only. No evidence has been identified that these individuals’ intelligence backgrounds were operationalised through ExpressVPN’s product or infrastructure.

Teddy Sagi - ownership and donations (owner-level context - flagged): Kape’s controlling shareholder Teddy Sagi (via his holding company Unikmind) is an Israeli billionaire who reportedly donated $3 million for IDF soldier scholarships in 2019 and approximately $1 million in 2023 for transport of soldiers during military operations in Gaza.32 This is owner-level conduct, distinct from ExpressVPN’s own corporate behaviour, and is attributed to Sagi at the owner level.

Government data requests (transparency reports): ExpressVPN received 333 government, law enforcement, and civil requests in 2024, reporting that it disclosed no user data in response to any of these.33 In H1 2025, 374 such requests were received; again no data was disclosed.34 Breakdown by requesting jurisdiction is not published, so it is not possible to determine whether any requests originated from Israeli authorities.

Turkey 2017 server seizure: Turkish police seized an ExpressVPN server in January 2017 during the investigation of the assassination of Russian ambassador Andrey Karlov. ExpressVPN confirmed it held no user logs, and Turkish authorities were unable to recover any data.35 This is not an Israeli-nexus event.

AI, Algorithmic & Autonomous Systems

ExpressAI: In February 2026 ExpressVPN announced, and on 31 March 2026 began rolling out, ExpressAI - a browser-based private AI platform for ExpressVPN Pro subscribers.36 The architecture uses confidential computing enclaves in which each interaction is processed with encryption keys generated inside hardware and inaccessible to ExpressVPN or infrastructure operators.37 Users can enable “Ghost Mode” for automatic conversation deletion. ExpressVPN states no prompts or files are used for AI model training and no human review of user data occurs.38

AI models offered: At launch, ExpressAI provides access to models from OpenAI, DeepSeek, Alibaba/Qwen, and NVIDIA.39 The inclusion of DeepSeek - a Chinese AI lab subject to China’s National Intelligence Law - is a noted privacy concern in public commentary, though ExpressVPN’s confidential-computing architecture is designed to prevent the underlying model providers from accessing user prompts.40

ExpressAI security audit: Cure53 conducted a penetration test and source-code review of ExpressAI’s frontend, backend, cryptographic implementations, and key management between February and March 2026, concluding that the platform’s architecture meets its stated privacy goals.41

AI and Israel nexus: No Israeli AI vendors, Israeli military AI systems, or Israeli government AI contracts are identified in ExpressVPN’s AI product stack. The confidential computing approach relies on general cloud hardware enclaves; no Israeli-specific components are identified.

Keys (password manager): ExpressVPN launched Keys as an integrated password manager in November 2023 and subsequently as a standalone app (ExpressKeys).42 No AI-driven behavioural profiling or algorithmic systems with an Israeli nexus are identified in these products.

Technology Ecosystem & R&D Footprint

ExpressVPN’s own R&D geography: ExpressVPN’s engineering and product teams are described as distributed globally across approximately 20 cities.43 The company’s careers pages and public disclosures do not identify an Israeli engineering office. No public evidence has been identified that ExpressVPN maintains its own R&D presence in Israel.

Kape Technologies Tel Aviv R&D (parent-level context - flagged): As of March 2022, Kape Technologies employed approximately 120 engineers at its Tel Aviv development centre, located in the Azrieli Sarona Tower, with approximately 850 employees globally.44 This is Kape group infrastructure, not ExpressVPN’s own. The degree to which ExpressVPN’s product or infrastructure development benefits from Kape’s Tel Aviv R&D resource is not publicly confirmed and represents a material transparency gap.

Crossrider/adware legacy (parent-level context - flagged): Kape Technologies was founded as Crossrider in 2011 by Koby Menachemi and Shmuel Achdut, as a cross-browser extension development framework.45 By 2013 the platform had over 300 million users and was identified in a Google/UC Berkeley study as one of approximately 1,000 businesses involved in ad injection.46 Malwarebytes and Symantec documented Crossrider-associated malware variants, although the malware was created by third-party abusers of the Crossrider SDK rather than by Crossrider/Kape itself.47 Kape closed the Crossrider platform in 2016 and rebranded as Kape Technologies in 2018. ExpressVPN was acquired five years after this pivot; the legacy does not directly attach to ExpressVPN’s own technology.

Kape-owned VPN review sites conflict of interest: In May 2021, Kape acquired Webselenese, owner of vpnMentor and Wizcase - two of the most-trafficked VPN review websites. Following the acquisition, both sites’ top recommendations shifted to Kape-group VPN products (ExpressVPN, CyberGhost, PIA). Neither site discloses Kape ownership prominently in its on-page text.48 This is a group-level digital ecosystem issue with direct relevance to how ExpressVPN is presented to prospective users.

Open-source contributions: ExpressVPN has open-sourced the Lightway protocol (GPLv2 on GitHub) and makes audit reports publicly available via its Trust Center.49

Civil Society Scrutiny & Regulatory History

Edward Snowden (September 2021): Following the DOJ DPA announcement, Snowden publicly urged all ExpressVPN customers to stop using the service, citing Gericke’s retention as evidence of a fundamental conflict with the company’s stated privacy mission.50

ExpressVPN employees (September 2021): Vice/Motherboard reported that ExpressVPN employees internally questioned management about the Gericke/Project Raven revelation and the company’s decision to retain him.51

Privacy community and press (2021–2022): Multiple VPN-focused publications published critical analyses of the Kape acquisition and the Gericke scandal, questioning the credibility of ExpressVPN’s privacy claims given its parent’s adware history and CIO’s surveillance background.52

DNS leak disclosure (2024): The public disclosure in February 2024 of the DNS-leak bug - which had persisted undetected for nearly two years - drew criticism regarding ExpressVPN’s internal security monitoring.53

No FTC, FCC, or data-protection regulatory enforcement actions: No public evidence has been identified of ExpressVPN being the subject of enforcement action by the FTC, FCC, UK ICO, or any EU data-protection authority.

Transparency reports: ExpressVPN publishes semi-annual transparency reports covering government, law enforcement, and civil data requests. All reports to date record zero user data disclosed.54 No breakdown by requesting country is published.

Kape review-site conflict of interest - civil society scrutiny: Independent researchers (e.g. CyberInsider) have published detailed analyses of Kape’s ownership of vpnMentor and Wizcase, documenting the shift in recommendations post-acquisition and the absence of prominent ownership disclosure on those sites.55 ExpressVPN has not publicly addressed this conflict in the context of its own transparency commitments.

End Notes

Footnotes

  1. https://tomsguide.com/news/expressvpns-lightway-protocol-goes-open-source-alongside-fresh-security-audit

  2. https://www.wolfssl.com/wolfssl-expressvpns-lightway/

  3. https://www.expressvpn.com/blog/expressvpn-releases-lightway-in-rust/

  4. https://www.expressvpn.com/blog/lightway-audits-cure53-praetorian/

  5. https://www.expressvpn.com/blog/cure53-lightway-audit/

  6. https://www.expressvpn.com/blog/ml-kem-lightway-upgrade/

  7. https://www.prweb.com/releases/expressvpn-publishes-pwc-audit-report-leading-way-in-industry-transparency-837316170.html

  8. https://www.expressvpn.com/blog/kpmg-2025-no-logs-policy-audit/

  9. https://www.webpronews.com/expressvpn-achieves-23rd-audit-strengthening-no-logs-policy-and-vpn-transparency-leadership/

  10. https://aws.amazon.com/solutions/case-studies/expressvpn-case-study

  11. https://www.expressvpn.com/blog/expressvpn-launches-dedicated-ip/

  12. https://www.prnewswire.com/news-releases/expressvpn-launches-industrys-first-hardware-product-aircovea-wi-fi-6-router-with-built-in-vpn-protection-301630820.html

  13. https://www.businesswire.com/news/home/20210913005652/en/ExpressVPN-to-Join-Kape-Technologies-with-Shared-Vision-to-Transform-Privacy-and-Security

  14. https://www.expressvpn.com/blog/expressvpn-officially-joins-kape/

  15. https://cybernews.com/news/expressvpn-cio-daniel-gericke-fined-335-000-for-cyber-espionage/

  16. https://www.vice.com/en/article/expressvpn-uae-hacking-project-raven-daniel-gericke/

  17. https://www.privacyaffairs.com/expressvpn-daniel-gericke-project-raven/

  18. https://cybernews.com/news/expressvpn-cio-daniel-gericke-fined-335-000-for-cyber-espionage/

  19. https://www.expressvpn.com/blog/daniel-gericke-expressvpn/

  20. https://www.expressvpn.com/blog/daniel-gericke-expressvpn/

  21. https://www.techtarget.com/searchsecurity/news/252506801/ExpressVPN-stands-behind-CIO-named-in-UAE-hacking-scandal

  22. https://hackread.com/edward-snowden-stop-using-expressvpn/

  23. https://www.vice.com/en/article/expressvpn-employees-ask-questions-project-raven/

  24. https://www.expressvpn.com/trust

  25. https://www.expressvpn.com/vpn-server/israel-vpn

  26. https://www.expressvpn.com/support/knowledge-hub/virtual-server-locations/

  27. https://www.expressvpn.com/blog/expressvpn-officially-joins-kape/

  28. https://www.expressvpn.com/blog/pwc-audits-expressvpn-servers-to-confirm-essential-privacy-protections/

  29. https://www.securityweek.com/expressvpn-user-data-exposed-due-to-bug/

  30. https://en.wikipedia.org/wiki/Kape_Technologies

  31. https://blog.boycat.io/posts/expressvpn-israeli-ownership-1b-privacy-risk

  32. https://blog.boycat.io/posts/expressvpn-israeli-ownership-1b-privacy-risk

  33. https://cyberinsider.com/expressvpn-received-333-govt-requests-in-2024-shared-no-user-data/

  34. https://www.expressvpn.com/blog/expressvpn-transparency-report-h1-2025/

  35. https://torrentfreak.com/vpn-server-seized-to-investigate-russian-ambassadors-assassination-1171219/

  36. https://www.expressvpn.com/blog/expressvpn-launches-expressai-privacy/

  37. https://www.expressvpn.com/expressai

  38. https://gizmodo.com/expressvpn-launches-expressai-an-ai-nobody-can-spy-on-2000740293

  39. https://cyberinsider.com/expressvpn-debuts-privacy-focused-ai-platform-with-secure-enclaves/

  40. https://www.expressvpn.com/blog/is-deepseek-safe/

  41. https://cyberinsider.com/expressvpn-debuts-privacy-focused-ai-platform-with-secure-enclaves/

  42. https://www.expressvpn.com/blog/expressvpn-keys-password-manager-launch/

  43. https://www.israeldefense.co.il/en/node/51870

  44. https://officesnapshots.com/2022/01/04/kape-offices-tel-aviv/

  45. https://en.wikipedia.org/wiki/Kape_Technologies

  46. https://cyberinsider.com/kape-technologies-crossrider-malware/

  47. https://cyberinsider.com/kape-technologies-crossrider-malware/

  48. https://cyberinsider.com/vpn-review-websites-owned-by-vpns/

  49. https://www.expressvpn.com/trust

  50. https://hackread.com/edward-snowden-stop-using-expressvpn/

  51. https://www.vice.com/en/article/expressvpn-employees-ask-questions-project-raven/

  52. https://www.techradar.com/news/expressvpn-and-project-raven-everything-we-know-so-far

  53. https://www.securityweek.com/expressvpn-user-data-exposed-due-to-bug/

  54. https://www.expressvpn.com/blog/expressvpn-transparency-report/

  55. https://cyberinsider.com/kape-technologies-owns-expressvpn-cyberghost-pia-zenmate-vpn-review-sites/