← VPNs
D

Private Internet Access

Serious concerns
Kape · 🇺🇸 United States · WiFi
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: com.privateinternetaccess.android
Manufacturer: Kape Technologies

⚠️ The bottom line

PIA is owned by a company that used to help inject ads into people's browsers. The owner was convicted of fraud. They changed the company name to hide the history, then went private so nobody can see what they're doing. Now they've laid off 12% of staff at a company that's supposed to protect your privacy. PIA chose to base itself in the country that built PRISM. Yes, they don't keep logs today. But the US government can legally force them to start logging tomorrow and forbid them from telling you about it. The parent company operates from three more countries that share intelligence with the US.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
D
Parent company: Kape Technologies
Formerly Crossrider adware platform, Sole owner Teddy Sagi convicted of fraud, Owns "independent" VPN review sites +1 more
4 structural risks · 2 products →
Grade raised from C to D due to parent company risks
Audited by: Deloitte (ISAE 3000 (limited), Jun 2024)
An audit is a snapshot, not a guarantee. How reliable are these auditors?
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
3/4 HIGH
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
3/4 HIGH
Can I trust what they say?
CONFIGURE High-risk areas that can be partially mitigated with settings changes.
6Contradictions
1Critical
3High
2Medium
14Sources
Findings by concern
Spying 3/4 HIGH 3 findings
⚠️ criticalpolicy vs regulatory
PIA is owned by a company that used to help inject ads into people's browsers. The owner was convicted of fraud. They changed the company name to hide the history, then went private so nobody can see what they're doing. Now they've laid off 12% of staff at a company that's supposed to protect your privacy.

What they claim: PIA is a privacy-first VPN service that protects users from surveillance and tracking.

What we found: Owned by Kape Technologies (formerly Crossrider), classified as adware by Symantec and MalwareBytes. Crossrider's SDK was used to inject ads into browsers. UC Berkeley/Google identified it as a major ad injector affiliate. CEO admitted 2018 rebrand was to escape "past activities." Founder Teddy Sagi convicted of fraud in Israel (1996). Kape went fully private in 2023 via Unikmind Holdings, eliminating public reporting. 180 employees laid off in 2025-2026.

⚡ highpolicy vs regulatory
PIA chose to base itself in the country that built PRISM. Yes, they don't keep logs today. But the US government can legally force them to start logging tomorrow and forbid them from telling you about it. The parent company operates from three more countries that share intelligence with the US.

What they claim: PIA's US base doesn't compromise privacy because it keeps no logs.

What we found: PIA operates from Denver, Colorado -- a founding Five Eyes member. The US government can issue National Security Letters with gag orders (Patriot Act), conduct warrantless surveillance (FISA Section 702), and compel cooperation. While PIA's diskless servers mean there's currently nothing to seize, the legal framework allows the government to compel future logging. Post-Kape, the parent chain runs through UK, Isle of Man, and Israel -- all with intelligence cooperation agreements.

⚡ highpolicy vs regulatory
PIA loves to mention that the FBI couldn't get their logs. What they don't emphasise is that those cases happened under previous owners who later sold to a former adware distributor. The audits since then are by Deloitte -- the same firm fined $20 million by the SEC for letting clients do their own audit work, and fined £15 million for missing fraud at Autonomy before HP lost $11 billion. Even if the audits are honest, they check a snapshot -- not what happens the other 364 days of the year.

What they claim: PIA's no-logs policy is court-proven and independently verified.

What we found: Both FBI court cases that validated PIA's no-logs claim -- the 2016 Preston McWaters bomb threat case and the 2018 Ross Colby hacking case -- occurred under London Trust Media ownership, not Kape. PIA's marketing prominently cites these cases as trust signals for a product now under different ownership. Post-Kape verification relies on Deloitte Romania audits (2022, 2024, 2025), but Deloitte's track record undermines confidence: SEC fined Deloitte China $20M for asking clients to conduct their own audit work (2022), FRC fined Deloitte £15M for "serious and serial failures" auditing Autonomy before HP's $11B acquisition, PCAOB sanctioned Deloitte in Indonesia, Philippines, and Netherlands for widespread exam cheating among partners (2024-2025). Audits are also point-in-time snapshots -- they verify what exists during the audit window, not what happens between audits.

Security 3/4 HIGH 1 finding
⚫ mediumapp permissions vs policy
PIA advertises a built-in ad and tracker blocker called MACE. But if you downloaded PIA from the Google Play Store like a normal person, you don't have it. You'd need to know to go to PIA's website, download a separate file, and sideload it. Most people will never know they're missing the feature.

What they claim: PIA blocks ads, trackers, and malware for all users with its MACE feature.

What we found: Google forced PIA to remove the MACE ad/tracker/malware blocker from the Play Store version of its Android app. Users must sideload the APK from PIA's website for full ad and tracker blocking. The Play Store version -- which most Android users install -- lacks the feature PIA advertises as a core privacy tool. No prominent warning during Play Store installation.

Honesty 3/4 HIGH 2 findings
⚡ highmarketing vs third party research
The "independent" review sites telling you PIA is great are owned by the same company that owns PIA. They paid $149 million to control what you read about VPNs. After the purchase, their own products mysteriously rose to #1 and competitors vanished from the recommendations.

What they claim: Independent review sites recommend PIA on its merits.

What we found: Parent company Kape bought vpnMentor and Wizcase for $149.1M (2021). Post-acquisition, Kape-owned VPNs including PIA rose to top recommendations while competitors dropped. Wizcase removed NordVPN and Surfshark from top picks entirely. Ownership disclosed only in hidden pop-up boxes. Both sites claim editorial independence while being owned by PIA's parent company.

⚫ mediumpolicy vs regulatory
The company that owns PIA just fired 12% of its staff, went private so nobody can see its finances, and lost key executives. When a privacy company cuts staff and hides its books, users have to trust that security didn't get cut too.

What they claim: PIA maintains robust security and privacy infrastructure under Kape ownership.

What we found: Kape laid off 180 employees (12% of staff) in 2025-2026 after going private via Unikmind Holdings. ExpressVPN founder Peter Burchhardt and CTO Dan Gericke both departed. The company eliminated public financial reporting by delisting from the London Stock Exchange in 2023. Reduced staffing at a privacy company raises questions about ongoing security investment, incident response capacity, and audit continuity.

Sources