Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.
In April 2026 this provider published its first independent audit, and it is an unusually open one. X41 D-Sec spent two months inside the source code and the server network, with full access to both.
The auditors found fourteen issues, two of them critical. They also found no evidence of user activity logging.
⚠️ Its press release says one critical issue. Its own blog says two. That blog is the fuller account, and a release is the version that travels.
Is Malwarebytes Privacy VPN Any Good?
Yes, for existing Malwarebytes customers. One bill, one interface, and a VPN reviewers describe as easy to start with — unlike most security bundles we have examined.
The infrastructure is better than the brand suggests. It runs on AzireVPN’s network, which the company bought in late 2024 — diskless servers it owns rather than leases.
⚠️ The limit is the country. Malwarebytes operates from Santa Clara, California, inside the Five Eyes arrangement — and our privacy ranking weighs that lowest of five criteria, though it still counts.
The Audit, in Detail
X41 D-Sec ran a white-box penetration test between December 2025 and January 2026, published in April. White-box means the auditors had the keys rather than probing from outside.
Scope covered four operating systems and the network. Source code for the Windows, macOS, Android and iOS apps, the configuration of the global server network, and the systems implementing the no-logs claim.
One finding matters more than the rest, and it is a negative one. Auditors recorded no evidence of user activity logging, and access to systems tightly controlled with no unnecessary remote or shell access exposed.
⚠️ And the severity spread is worth reading. Two critical, none high, eight medium and four low. The most serious concerned how a new server verifies its operating system image during setup, and the company reports it fixed.

Why Critical Findings Are a Good Sign
This runs against instinct, so it is worth stating plainly.
An audit that reports nothing usually had a narrow scope. Full access to source code across four operating systems will find problems, because all software has them.
Compare the alternative. Several providers in our audit table have published nothing at all, and their no-logs claims rest on a policy page instead.
⚠️ What matters is what happened next. Malwarebytes published the findings itself, including the severity scores, and reports the critical one resolved with the rest in progress.
The Discrepancy Between Two Announcements
Its release of 2 April says vulnerabilities were identified and most already addressed, including one critical issue.
Its blog of 6 April states that X41 D-Sec found two critical issues, and explains the first in technical detail.
⚠️ An independent account confirms two. Fourteen issues in total, two critical, eight medium and four low, with none rated high.
We are not calling it a cover-up. Most likely one was fixed by the time the release went out, with the other in progress. Even so, that release undercounts the blog, and only one of the two documents gets quoted.

What It Actually Is
Two products on one platform. Malwarebytes Privacy VPN and AzireVPN run on the same servers and software after the 2024 acquisition — one more entry for our ownership map.
AzireVPN’s features came with it, including a mode designed to limit what the operator itself can observe on a server.
The data it does keep is narrow. Licence details, software version and a public key, by published accounts — not browsing activity and not addresses.
⚠️ Servers sit in many countries, and local law applies to each. The company states there would be nothing to share, which is the claim the audit examined — the distinction between a policy and an architecture.
Where It Falls Short
Streaming is not a goal. Published reviews give it little attention, and we have no consistent evidence either way — unlike the providers our streaming guide covers.
One audit is one audit. Mullvad publishes annually and has for over a decade, and Proton has five.
⚠️ And the United States base rules it out for some readers. That is a legitimate criterion, and a provider with diskless servers and a verified policy answers part of the objection rather than all of it.
We also have no renewal figure for it. So the four-year comparison we publish elsewhere is missing here, and our renewal table shows which providers we track.

How We Research
Malwarebytes’ own press release and blog post supply the audit scope, methodology and dates, both published in April 2026. CyberInsider read the report and supplies the severity breakdown of fourteen issues. For the auditor’s wording about logging and system access, we quote the company’s press materials quoting X41 D-Sec directly. Coverage of the 2024 AzireVPN deal supplies the acquisition and the diskless owned servers, and TechRadar also reported the audit. Because the release and the blog give different counts of critical findings, we cite both rather than choosing. We have no renewal figure and no streaming evidence for this provider, and we say so instead of estimating. We do not run our own tests. Our method lives on the About Us page.
Malwarebytes VPN FAQ
Yes, once, published in April 2026. X41 D-Sec ran a two-month white-box penetration test with full access to the source code of four apps and to the server network. The auditors recorded no evidence of user activity logging.
It found fourteen issues, two of them critical, eight medium and four low, with none rated high. Its most severe finding concerned how a new server verifies its operating system image during provisioning, and the company reports it resolved.
Its press release mentions one critical issue addressed; the company’s own blog states that two were found. Most likely one was fixed before the release and the other was still in progress. We cite both documents.
Malwarebytes bought AzireVPN in late 2024 and now runs both products on the same infrastructure — diskless servers the company owns rather than leases. Some of AzireVPN’s privacy features came with the acquisition.
It is a legitimate objection. Malwarebytes operates from California, inside the Five Eyes arrangement. Against that, the servers hold nothing on disk and an auditor with full access found no logging, which is the part a jurisdiction argument cannot settle on its own.
Malwarebytes Privacy VPN
The Verdict
An unusually open first audit: two months, white-box, full source code across four operating systems, and no evidence of logging. Diskless servers the company owns, inherited from AzireVPN. Against that: a single audit rather than a record, a Santa Clara headquarters inside Five Eyes, no streaming evidence either way, and a press release that reports fewer critical findings than the company’s own blog.
Final Verdict
The audit is the reason to take this seriously. Full code access, two months, and findings published with their severity scores rather than summarised away.
Two critical issues is a feature of the scope, not a scandal. Providers that publish nothing look cleaner and tell you less.
⚠️ And the announcement undercounts the blog. One critical issue in the release, two in the company’s own fuller account — worth knowing, because the release is the document that gets quoted.
