What I Actually Look For When Choosing a VPN

Sep 02, 2026By Jay Kells
Jay Kells

What I Actually Look For When Choosing a VPN

Everyone tells you to "get a VPN" the same way they tell you to eat more vegetables, as a vague piece of good advice nobody explains properly. What nobody tells you is that VPN providers vary enormously, and picking one badly can leave you with something that's slow, leaks your data anyway, or quietly logs everything it claims to protect. When I actually sat down and compared providers properly, five things ended up mattering far more than the marketing pages suggested they would. None of this is about brand names, it's about the specific features that separate a VPN that actually does its job from one that just looks like it does.


A No-Logs Policy I Can Actually Verify


Every VPN provider claims a "no-logs policy" somewhere on their homepage, which makes the phrase almost meaningless on its own. What actually matters is whether that claim has been independently audited by a third party, and whether the company has ever been tested by a real legal request and had nothing to hand over. I look specifically for a published independent audit rather than just a page of marketing language, because a claim nobody's checked is just a sentence, and I'm wary of any provider that treats "we don't log" as something you should simply take on trust. NordVPN is one of the few providers I've seen back this up with repeated third-party audits rather than a single one-off report years ago, which is the kind of ongoing verification I actually want from something handling all my traffic, not just a badge on a homepage that was accurate once and never checked again.


Overhead view of minimalist dispatch desk with red alert button and sharp studio shadows

A Kill Switch That Actually Works When It Matters


A kill switch is supposed to cut your internet connection instantly if the VPN drops, so you're never accidentally browsing unprotected without realising it. The problem is that not every provider's kill switch actually works the way it's described, some only trigger on a full app crash rather than a brief connection drop, which is exactly the moment you'd want it to catch. I test this deliberately when I'm evaluating a VPN, forcing a disconnect on purpose and watching whether my regular internet access actually stops or just quietly keeps working in the background. A kill switch you've never tested is a feature you're only assuming works, not one you actually know does.


Enough Simultaneous Device Connections for Everyone in the House


I used to assume one VPN subscription covered "a device," singular, until I actually needed it running on my laptop, my phone, a tablet, and a router all at once and discovered plenty of providers cap you at three or five connections. That number matters a lot more once you're not the only person in the house who needs coverage, and running out mid-month means constantly logging devices in and out just to free up a slot. I specifically look for providers offering unlimited or generously high simultaneous connections now, because the alternative is either paying for multiple subscriptions or rationing protection across your own household, which defeats the point of having it at all. The NCSC's own guidance on securing home networks makes a similar point about covering every device that connects, not just the laptop you happen to be using right now, and a low connection cap quietly works against exactly that.


Speed I Don't Notice, Which Is the Whole Point


Every VPN slows your connection down to some degree, because your traffic is being routed and encrypted rather than travelling the shortest possible path, but a well-built one keeps that slowdown small enough that you genuinely don't notice it in everyday use. A badly optimised one turns video calls choppy and page loads sluggish, which is exactly the kind of friction that gets a VPN switched off "just for now" and never switched back on. I run a quick speed test with the VPN on and off before committing to anything, and if the difference is dramatic rather than marginal, that's disqualifying regardless of how good the rest of the feature list looks on paper. None of this makes a VPN a complete security solution by itself, it's worth being clear-eyed about what it does and doesn't actually protect against, which I've covered in more detail separately, and it works best sitting alongside a password manager and proper antivirus software rather than instead of them.


A Provider Based Somewhere With Sensible Data Laws


Where a VPN company is legally headquartered actually matters, because it determines what data-retention laws it operates under and what a government could theoretically compel it to hand over, no matter what its own policy says. I look for providers based outside data-retention-heavy jurisdictions, somewhere a no-logs policy isn't just a promise but genuinely has nothing to hand over even if legally pressured to. It's a detail that's easy to skip past on a features comparison page, but it's the one that actually determines whether "no logs" holds up under real pressure rather than just sounding reassuring on a website.


Picking a VPN properly took longer than just grabbing whatever ranked first in a "best VPN" listicle, but it meant I ended up with something I actually trust running on every device I own, not just something I hoped was doing its job. If you want the specific everyday moments that convinced me a VPN was worth having in the first place, I've written about that separately, and my free Safety Toolkit covers the wider setup I'd recommend having in place alongside it.