PIA is owned by a company that used to help inject ads into people's browsers. The owner was convicted of fraud. They changed the company name to hide the history, then went private so nobody can see what they're doing. Now they've laid off 12% of staff at a company that's supposed to protect your privacy. PIA chose to base itself in the country that built PRISM. Yes, they don't keep logs today. But the US government can legally force them to start logging tomorrow and forbid them from telling you about it. The parent company operates from three more countries that share intelligence with the US.
What they claim: PIA is a privacy-first VPN service that protects users from surveillance and tracking.
What we found: Owned by Kape Technologies (formerly Crossrider), classified as adware by Symantec and MalwareBytes. Crossrider's SDK was used to inject ads into browsers. UC Berkeley/Google identified it as a major ad injector affiliate. CEO admitted 2018 rebrand was to escape "past activities." Founder Teddy Sagi convicted of fraud in Israel (1996). Kape went fully private in 2023 via Unikmind Holdings, eliminating public reporting. 180 employees laid off in 2025-2026.
What they claim: PIA's US base doesn't compromise privacy because it keeps no logs.
What we found: PIA operates from Denver, Colorado -- a founding Five Eyes member. The US government can issue National Security Letters with gag orders (Patriot Act), conduct warrantless surveillance (FISA Section 702), and compel cooperation. While PIA's diskless servers mean there's currently nothing to seize, the legal framework allows the government to compel future logging. Post-Kape, the parent chain runs through UK, Isle of Man, and Israel -- all with intelligence cooperation agreements.
What they claim: PIA's no-logs policy is court-proven and independently verified.
What we found: Both FBI court cases that validated PIA's no-logs claim -- the 2016 Preston McWaters bomb threat case and the 2018 Ross Colby hacking case -- occurred under London Trust Media ownership, not Kape. PIA's marketing prominently cites these cases as trust signals for a product now under different ownership. Post-Kape verification relies on Deloitte Romania audits (2022, 2024, 2025), but Deloitte's track record undermines confidence: SEC fined Deloitte China $20M for asking clients to conduct their own audit work (2022), FRC fined Deloitte £15M for "serious and serial failures" auditing Autonomy before HP's $11B acquisition, PCAOB sanctioned Deloitte in Indonesia, Philippines, and Netherlands for widespread exam cheating among partners (2024-2025). Audits are also point-in-time snapshots -- they verify what exists during the audit window, not what happens between audits.
What they claim: PIA blocks ads, trackers, and malware for all users with its MACE feature.
What we found: Google forced PIA to remove the MACE ad/tracker/malware blocker from the Play Store version of its Android app. Users must sideload the APK from PIA's website for full ad and tracker blocking. The Play Store version -- which most Android users install -- lacks the feature PIA advertises as a core privacy tool. No prominent warning during Play Store installation.
What they claim: Independent review sites recommend PIA on its merits.
What we found: Parent company Kape bought vpnMentor and Wizcase for $149.1M (2021). Post-acquisition, Kape-owned VPNs including PIA rose to top recommendations while competitors dropped. Wizcase removed NordVPN and Surfshark from top picks entirely. Ownership disclosed only in hidden pop-up boxes. Both sites claim editorial independence while being owned by PIA's parent company.
What they claim: PIA maintains robust security and privacy infrastructure under Kape ownership.
What we found: Kape laid off 180 employees (12% of staff) in 2025-2026 after going private via Unikmind Holdings. ExpressVPN founder Peter Burchhardt and CTO Dan Gericke both departed. The company eliminated public financial reporting by delisting from the London Stock Exchange in 2023. Reduced staffing at a privacy company raises questions about ongoing security investment, incident response capacity, and audit continuity.