noKYCme

Case file · VPN

AirVPN

Activist-run and Monero-friendly, with no personal data required. Strong on anonymity, but never independently audited.

No-KYC · Level 1
Based
Italy
Price
From ~€2–7 / month (longer plans cheaper)
Reviewed
2026-07-21
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

8.9/10 · No-KYC in practice

Run by digital-rights activists in Italy, AirVPN requires no personal data at all (email is optional), takes Monero, offers an Onion endpoint, and publishes real-time server stats. Genuinely identity-free in practice. The catch is verification: unlike the audited leaders its no-logs claim has never been independently audited, though a 2015 Toronto server seizure recovered nothing. Level 1, held below the account-number VPNs by the lack of a hard guarantee and its 14-Eyes jurisdiction.

What the internet says

3 recurring praises · 3 recurring gripes

Most praised: long trusted by privacy purists for the no-personal-data signup, monero and onion endpoint. Most cited downside: the complete absence of any independent audit is the most common criticism.

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Specs & jurisdiction.

Jurisdiction
Italy
Intel-sharing
14 Eyes member
Logging
No traffic logs
Anon. payment
Monero + many crypto
Protocols
OpenVPN, WireGuard
Network
~250 servers · ~23 countries
Devices
5+ (configurable)
Kill switch
Yes (Network Lock)
RAM-only
No
Open source
Yes (Eddie client)
Audited
No formal audit
Free tier
No (cheap 3-day)

The full read

Our analysis, in plain words.

AirVPN, run by digital-rights activists in Italy since 2010, has one of the most anonymous account models in the whole category: no personal data is required to register (email is optional), it accepts Monero and a range of other cryptocurrencies, and it offers an Onion endpoint and SSL/SSH obfuscation. On the collection axis it is close to the account-number leaders, which is why privacy is 94.

The reason it is not a top-tier overall score is verification, and this is the honest tension at the heart of noKYCme. AirVPN has never had an independent audit of any kind: no no-logs audit, no infrastructure audit. Its (verbatim, strong) no-logs claim therefore rests on self-attestation, a sixteen-year clean record, and one real-world test rather than on external verification. That is why we hold trust at 80: above PIA (77), because AirVPN's clean, independent, never-acquired ownership beats PIA's Kape-era baggage, but clearly below every audited peer (Windscribe 84, NymVPN 85, IVPN 88, Proton 90). An unaudited provider should not out-rank the audited field on trust.

The one external stress test is instructive: in 2015 Toronto police seized an AirVPN server and recovered no data, which is exactly what the no-logs design predicts and a genuine point in its favour. The caveat is that AirVPN disclosed the seizure late and later removed the forum thread about it, a transparency stumble that we note but that did not expose any user.

On identity it is level 1, not 0: no ID or verification is ever required, but the terms carry no explicit unconditional "identity is never required" guarantee, and Italy is a 14 Eyes member. And per the ratified badge rule it carries no VERIFIED badge, because that badge requires external evidence (audit, raid, court, our own test) and AirVPN has none. Worth flagging the resulting paradox for review: AzireVPN keeps a VERIFIED badge on a single 2026 audit despite dropping anonymous payment, while AirVPN, arguably the more privacy-respecting operator, cannot earn it. That is the badge rule working as written, but it is a question worth revisiting.


The score, broken down

How the 8.9 is built.

Privacy 4.7Trust 2.4Reliability 1.8 Headroom 1.1

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

94/100

94 × 50% = 4.7 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

80/100

80 × 30% = 2.4 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

90/100

90 × 20% = 1.8 of 10

Weighted total 8.9 / 10 · no reliability rule triggered, so the score stands. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +10Identity-free registration: no email, name or phone required (email optional)
  • +5Accepts Monero and many cryptocurrencies
  • +5Onion (Tor) endpoint + OpenVPN over SSL/SSH obfuscation
  • +3No-logs: activity/IP not inspected, logged or stored

Trust

  • +6Open-source Eddie client (GPL)
  • +5Independent, unacquired operator since 2010 (Paolo Brini, Italy)
  • +4Real-time public infrastructure transparency

The fine print, read for you

Terms reviewed — no trapdoor found.

Verbatim — the honest version
“Activity traffic and/or traffic content and/or IP addresses of the customers or users are not inspected, logged or stored into any mass storage device.”

What it meansThe verbatim no-logs commitment; no discretionary identity clause exists. The only "sole discretion" clause is bounded to specific abuse under Terms point 4 (spam, malware, port-scanning), not an identity demand, so it does not gate access or force a KYC level.

Read the source →
KYC trigger threshold

No personal data is required to register: no email (it is optional), name, phone or ID, and Monero keeps payment anonymous. It is level 1 rather than 0 not because of any identity handle, but because the terms carry no explicit unconditional "identity is never required" guarantee, and it operates from Italy, a 14 Eyes member.

Policy review — point by point

  • Verbatim no-logs commitment

    Activity traffic, traffic content and IP addresses are "not inspected, logged or stored into any mass storage device."

  • Sole-discretion clause bounded to abuse

    The only discretionary-termination clause is limited to specific Terms point-4 violations (spam, malware, port-scanning), not an identity demand, so it does not gate access or set the KYC level.

  • Italian courts, no forced arbitration

    Disputes fall under Italian/EU courts rather than binding arbitration with a class-action waiver, unlike several US-facing peers.

  • Never independently audited

    AirVPN has never commissioned or published an independent audit, so its no-logs claim is unverified externally. This is the main reason its trust score sits below the audited leaders.

Jurisdiction analysis

Italy, a member of the 14 Eyes intelligence-sharing arrangement, which is a mark against it. The mitigation is structural rather than legal: the no-logs design means little exists to compel, as the 2015 Toronto server seizure (nothing recovered) demonstrated. Ownership is independent and unacquired (Paolo Brini, Perugia), avoiding the corporate-parent risk seen at PIA, ExpressVPN and AzireVPN.


We keep watching

Incident & policy timeline.

  1. 2015

    Toronto server seized - nothing recovered

    Toronto police seized an AirVPN server and recovered no data, a real-world validation of the no-logs design. AirVPN disclosed it late (citing the ongoing investigation) and later removed the forum thread, which drew transparency criticism, so we log it as a passed test with a communication caveat.

    source ↗
  2. Ongoing

    Real-time public server stats

    Publishes live per-server load, users and bandwidth, an unusual openness that lets you verify claims yourself.

    source ↗

The verdict

Where it stands.

Strengths

  • No personal data to register (email optional)
  • Monero and wide crypto support
  • Onion endpoint + strong obfuscation (SSL/SSH/Tor)
  • Open-source Eddie client, activist-run since 2010
  • 2015 Toronto seizure recovered nothing

Trade-offs

  • Never independently audited - no external verification of the no-logs claim
  • Italy (14 Eyes member)
  • Delayed, opaque handling of the 2015 seizure
  • Smaller network; dated apps
Visit AirVPN No affiliate relationship. We link to the official site directly.

Across the internet

What reviewers report.

Consistently praised

  • Long trusted by privacy purists for the no-personal-data signup, Monero and Onion endpoint
  • Open-source Eddie client and real-time server transparency respected
  • The 2015 Toronto seizure recovering nothing is cited as proof the no-logs holds

Recurring complaints

  • The complete absence of any independent audit is the most common criticism
  • Italy (14 Eyes) jurisdiction
  • The delayed, later-deleted disclosure of the 2015 seizure hurt trust

Sentiment is strongly positive on anonymity and independence, and split on the lack of any external audit. No corroborated data-betrayal or freeze pattern exists; the 2015 seizure is consistent with the no-logs claim.


Keep exploring

Related lists & categories.


Ask the bureau

AirVPN, common questions.

Is AirVPN no-KYC?

Effectively yes. It requires no personal data to register (email is optional) and no name, phone, ID or verification, and it accepts Monero. We rate it level 1 (no-KYC in practice) rather than 0 because the terms carry no unconditional no-ID guarantee and it is based in Italy, a 14 Eyes country.

Can you pay AirVPN anonymously?

Yes. It accepts Monero and other cryptocurrencies alongside cards and PayPal, so payment need not identify you.

Is AirVPN audited?

No. Unlike Proton, IVPN or Mullvad, AirVPN has never had an independent audit, so its (strong, verbatim) no-logs claim rests on self-attestation, its 16-year record, and one real-world test: a 2015 Toronto server seizure that recovered no data. That lack of external verification is why its trust score sits below the audited leaders.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.