方法論
証拠を数値に変える方法
当サイトのすべての数値は引用された一次情報源まで辿ることができ、それを生み出した計算はこのページで公開されています。ここにあるのは、信じるよう求められる評価ではありません。検証するよう招かれている計算です。
プレビュー、まだ人間による検証を経ていません。
現在のコーパスは機械が収集し、引用を確認したものです。すべての抜粋を情報源に照らして確認した人はまだおらず、そのため当サイトのいかなる情報も推奨として提示されていません。このページは、レビュー済みのコーパスを規定することになる方法を説明したものです。方法は今日すでに実在しますが、人間によるレビューはまだ完了していません。
1 · 証拠なくしてスコアなし
ある事実が採点ルールに達するのは、一次情報源、プライバシーポリシー、監査レポート、裁判資料、ソースコード、または当サイト自身が行った計測、への引用を少なくとも1つ伴う場合に限られます。これは守ろうと努めるガイドラインではありません。証拠リストが空の事実はそもそも構築できず、したがってルールに達することもできないのです。
当サイトは競合のレビューサイトを決して引用しません。誰かが引用しようとすると、ドメインのブロックリストがビルドを失敗させます。他のランキングサイトがVPNについて述べたことを部分的にでも根拠にランク付けすれば、彼らの結論を当サイトの結論へと洗浄することになります。そして彼らの結論こそ、当サイトが取って代わるために存在しているものです。
出典を得ていない事実は、フィールドを省略することで表現され、ゼロや空の引用で表現されることは決してありません。この違いは、次のルールにとって重要です。
Independent security assessment
How we audit a VPN application
This protocol describes the hands-on security assessment used for SingLinkVPN v2.5 and future VPN client audits. It is version-, platform-, environment-, and time-bound: every result belongs to the exact build and test matrix recorded in the report.
Governing principles
- Freeze the product version, platform build, test date, account state, network, and test environment before execution.
- Record expected behavior, actual behavior, raw evidence, severity, retest status, and reviewer for every test case.
- Treat “not reproduced” as a bounded observation, never proof that a vulnerability cannot exist.
- Test normal use, failure states, adversarial requests, network transitions, and regression after remediation.
- Keep provider statements separate from our measurements; a claim cannot replace a test result.
- Publish scope exclusions and unavailable evidence beside the result, not in fine print.
Minimum test matrix
The exact matrix varies by product. A cross-platform audit should cover every supported client that can create a materially different security path.
| Area | Required coverage |
|---|---|
| Platforms | iOS, Android, macOS, Windows, Linux, TV clients, and web dashboard where offered |
| Networks | Wi-Fi, mobile data, IPv4, IPv6, network loss, network switching, captive or restricted conditions where available |
| Connection states | First connect, reconnect, server switch, sleep/wake, app restart, process termination, logout, expired session |
| Tunnel modes | Full tunnel, split tunnel, application and domain exclusions, automatic routing |
| Accounts | Valid, invalid, expired, logged-out, cross-device, and unauthorized request states |
| Builds | Production build identifiers and remediated builds; debug-only behavior is excluded unless explicitly tested |
Execution procedure
1. Scope, authorization, and asset freeze
Define what is permitted and preserve the identity of everything being tested before touching the product.
- Written authorization and rules of engagement
- Product/version/build hashes
- Platform and device inventory
- Domains, APIs, dashboard, and excluded assets
- Test accounts and data-handling rules
- Start and cut-off times
2. Baseline and attack-surface mapping
Map the connection lifecycle and trust boundaries so tests exercise the real data paths rather than only visible interface states.
- Authentication and token flow
- VPN startup and configuration flow
- API endpoints and request parameters
- Local storage and diagnostic paths
- Routing, DNS, tunnel adapter, and reconnection behavior
- Privileged operations and platform permissions
3. Connection lifecycle and safe failure
Verify that displayed connection state matches the operating system’s actual route and that failures do not silently expose traffic.
- Connect, disconnect, reconnect, and server switch
- Loss of local connectivity
- Server-side interruption
- App restart and abnormal process termination
- Device sleep and wake
- Wi-Fi/mobile transition
- Automatic recovery without stale routes
4. DNS, IP, IPv6, WebRTC, and route leakage
Observe public addresses, resolvers, ICE candidates, interfaces, and route tables before, during, and after tunnel transitions.
- IPv4 source-address exposure
- IPv6 bypass or fallback
- DNS resolver leakage
- WebRTC candidate exposure
- Local-network information exposure
- Prolonged unprotected traffic after interruption
- Split-tunnel boundary enforcement
5. Account, session, and authorization controls
Attempt to cross authentication and tenant boundaries using realistic invalid and adversarial requests.
- Unauthenticated endpoint access
- Invalid and expired tokens
- Token invalidation after sign-out
- Parameter and object-identifier modification
- Cross-account subscription/data access
- Session state across devices
- Dashboard authorization
6. Internal connection and configuration protection
Probe the APIs that provide server, route, certificate, credential, or internal connection material without publishing sensitive data.
- Requests from non-standard clients
- Missing, malformed, replayed, and expired authorization
- High-frequency and automated probing
- Request signing and freshness controls where used
- Rate limiting and anomaly blocking
- Isolation of internal configuration from public endpoints
7. Local data and production-build hygiene
Inspect what the client leaves on the device and what its production diagnostics disclose.
- Credential and token storage
- Operating-system secure storage use
- Logs, crash reports, and temporary files
- Sensitive configuration remnants
- Debug endpoints and verbose production logs
- Unnecessary network-activity or account data
8. Cross-platform consistency
Compare controls across clients because one weaker platform can create the practical bypass for an otherwise sound design.
- Equivalent leak protection
- Equivalent session invalidation
- Equivalent safe-failure behavior
- Platform-specific permissions
- Version drift and missing controls
- Dashboard/client policy consistency
9. Finding validation and severity
Reproduce suspected issues, remove environmental false positives, document prerequisites, and grade impact before reporting.
- Independent reproduction
- Minimal proof of concept
- Affected versions and platforms
- Exploit prerequisites
- User and infrastructure impact
- Evidence preservation without exposing secrets
10. Remediation and regression retest
A finding is closed only after the fixed build is identified, the original issue no longer reproduces, and adjacent controls still behave correctly.
- Fix and build identity
- Original proof rerun
- Negative and boundary cases
- Cross-platform regression
- New attack surface check
- Closed, partially fixed, accepted, or unresolved status
Severity model
Severity combines impact, exploitability, prerequisites, affected scope, and remediation urgency.
- Critical
- Large-scale sensitive-data exposure, remote code execution, core-system control, complete authentication bypass, or broad VPN traffic exposure.
- High
- Account takeover, important private-data exposure, unauthorized protected access, traffic bypass, or failure of a core security control.
- Medium
- Material impact requiring specific conditions or affecting a limited platform, feature, dataset, network, or device environment.
- Low
- Limited direct impact that weakens defense in depth or exposes non-core technical information.
- Informational
- No directly exploitable vulnerability, but a concrete security-engineering or hardening improvement.
How a 100-point audit score is calculated
The report must publish the scored checklist and item weights. Each item begins with its assigned points; a reproducible unresolved finding removes the points attached to the affected control according to the report’s declared rule.
A remediated issue earns its points only after a documented retest passes. Untested, blocked, or out-of-scope items cannot silently receive full credit; they must be excluded from the denominator or shown separately.
A result of 100/100 therefore means all scored in-scope items passed in the tested build. It is not a lifetime guarantee, a claim of zero possible vulnerabilities, or an overall provider score.
Evidence and reproducibility requirements
- Test-case identifier, owner, date, platform, device, OS, application version, and environment
- Expected result, actual result, reproducibility status, and severity rationale
- Sanitized screenshots, packet/route observations, request traces, logs, or hashes where safe to publish
- Build matrix, scoring worksheet, change log, remediation record, and reviewer sign-off
- Separation between public evidence, redacted security evidence, and confidential material
- Content hash or immutable archive for public artifacts so later edits are detectable
Mandatory limitations
- Testing samples behavior; it cannot prove the absence of every vulnerability.
- Results do not automatically transfer to later versions, untested platforms, different backends, networks, accounts, or configurations.
- Black-box and grey-box testing cannot verify source-code paths or server operations that were not made available.
- No-logs claims require operational or infrastructure evidence; client leak testing alone cannot prove them.
- Unavailable signed reports, worksheets, build matrices, or raw evidence reduce independent reproducibility and must be disclosed.
Reproducible VPN leak-test protocols
The versioned kill-switch, DNS, WebRTC, and IPv6 specifications define the test matrix, evidence requirements, pass conditions, limitations, and blank raw-data format. Protocol pages are not results: no provider receives a pass until completed evidence and reviewer records are published.
Read the protocols and download blank result templates2 · 当サイトの調査の欠落がスコアを下げることは決してない
ある評価項目に証拠がない場合、その評価項目はゼロとして採点されるのではなく、加重平均から除外されます。当サイトの調査の穴を理由にプロバイダーを罰すれば、たまたま最も調査が浅かったプロバイダーをひそかに優遇することになります。それこそ、このモデル全体が回避するために構築された、まさにその失敗です。
このルールの代償は、スコアが自動的には比較可能でなくなることであり、当サイトはそれを公然と支払います。各評価項目にはカバー率、ルールのうちどれだけに評価に足る証拠があったか、が付され、各スコアには採点加重が付されます。方法論の 72% に基づいて採点された 8.4 は、28% にデータがなかったことを意味し、ページは数値の横にそう記載します。事実がまったくない評価項目は、0でも10でもなく、無得点となって除外されます。
3 · 数値の出所は、数値とともに移動する
当サイトは、グローバルな速度マトリクスやストリーミングのブロック解除テスト一式を実施していません。ベンダー自身のスループット数値を、当サイトが一行ずつ読んだプライバシーポリシーと同じ書体で表示すれば、まさに重要な区別が消えてしまいます。そのため、すべてのスコアには出所の取得方法が刻印されています。4つの種類があります。
- 実測
- この数値は当サイトが自ら計測したもので、再現が可能です。
- 文書化
- 一次文書から読み取ったもの。プライバシーポリシー、監査レポート、またはソースコードです。
- ベンダー主張
- プロバイダーが主張しているもの。当サイトは独自に検証しておらず、スコアはそれに応じて上限が設けられています。
- 証拠なし
- 採点できる材料が見つかりませんでした。この評価項目はゼロとして数えるのではなく、加重平均から除外されます。
出所は上限も定めます。当サイトは独自の速度テストを実施せず他者のものを引用するため、速度は 8.5 が上限となります。ストリーミングの主張は、当サイトが実施したテストではなくマーケティングページであるため、ストリーミングは 6.5 が上限となります。当サイトが認証する資格を得ていない数値は、スケールの最上限には到達できず、上限は隠されるのではなく表示されます。
4 · 11の評価項目と、その加重方法
プロバイダーは11の評価項目で採点されます。デフォルトの加重は、当サイトが独立して検証できるものに最も大きな加重を、ベンダーのページから読み取ることしかできないものに最も小さな加重を割り当てます。速度とストリーミング、ここではどちらもベンダーの領域です、は、業界標準が与える加重のおよそ半分を担います。その加重は、プライバシー、透明性、サーバー真正性へと移されます。
| 評価項目 | 出所の種類 | 上限 | デフォルト | Top10VPN パリティ |
|---|---|---|---|---|
プライバシー ログ記録ポリシー、法域、所有関係、ポリシーと届出資料から読み取ります。 | 文書化 | 10 | 24% | 20% |
セキュリティ プロトコル、キルスイッチ、暗号方式の選択、ドキュメントとソースから読み取ります。 | 文書化 | 10 | 18% | 15% |
透明性 公開された監査、カナリア、オープンソースクライアント。 | 文書化 | 10 | 12% | , |
サーバー真正性 当サイト独自のプローブネットワークによるレイテンシの三点測量、当サイトが保有することになるデータセットです。 | 実測 | 10 | 10% | , |
サーバー所在地 件数はプロバイダーの主張です。それを検証するのがサーバー真正性です。 | ベンダー主張 | 10 | 7% | 10% |
ストリーミング 地球上のあらゆるサービスを列挙したマーケティングページ。当サイトはブロック解除テスト一式を実施していません。 | ベンダー主張 | ≤ 6.5 | 7% | 15% |
速度 第三者による計測。当サイトが生み出したものではないため、スケールの最上限には到達できません。 | 文書化 | ≤ 8.5 | 7% | 15% |
デバイス対応 対応プラットフォームとアプリ掲載情報を、直接読み取ります。 | 文書化 | 10 | 5% | 5% |
使いやすさ セットアップとインターフェースを、ドキュメントとストア掲載情報から読み取ります。 | 文書化 | 10 | 4% | 10% |
トレント ポートフォワーディング、キルスイッチの動作、P2Pポリシーを、ドキュメントから読み取ります。 | 文書化 | 10 | 3% | 5% |
追加機能 スプリットトンネリング、マルチホップ、広告ブロック、ドキュメントに基づき、有無を判定します。 | 文書化 | 10 | 3% | 5% |
「出所の種類」の列は、この方法における各評価項目の典型的な情報源を示すものであり、今日の未レビューのコーパスにおける実際の出所ではありません。サーバー真正性、速度、使いやすさは、当サイトが自ら計測または読み取る予定の評価項目ですが、現在のコーパスにはまだそれらの証拠がありません、そのため、ルール2に従い、今日は無得点です。
「Top10VPN パリティ」の列は、競合が公開している加重を当サイトの証拠に適用して再現したものです。透明性とサーバー真正性をゼロにします、その方法論には同等のカテゴリーが存在しないためです、そしてこれは意図的に提供されています。「データが一致しない」のか「方法論が一致しない」のかを切り分けられるようにするためです。当サイトが結論に至るよう加重を調整したのではと疑うなら、彼らの加重で数値を計算し、何が動くかを確認してください。
同じ証拠は、3つの用途別加重の下でも公開されています。それらは誘導用のページではありません。同じデータに、異なる問いを投げかけたものです。
- Default (evidence-weighted)
- Weights are allocated toward what this site independently verifies. Speed and streaming are vendor-claimed rather than measured here, so they carry roughly half the weight the industry standard assigns them; that weight moves to privacy, transparency and server authenticity, all of which are checked against primary documents or our own probe network.
- Top10VPN parity
- Reproduces the published Top10VPN category weighting (privacy 20%, streaming 15%, speed 15%, security 15%, server locations 10%, user experience 10%, torrenting 5%, device compatibility 5%, additional features 5%). Transparency and server authenticity are zeroed because that methodology has no equivalent category. Published so readers can see exactly how much of a ranking is the data and how much is the weighting.
- Privacy first
- For readers whose threat model is surveillance rather than geo-blocking. Logging policy, jurisdiction, published audits and open-source clients dominate; streaming access is worth nothing.
- Streaming
- For readers unblocking geo-restricted catalogues. Note the honesty cost: this site does not run its own unblock suite, so the streaming dimension is capped at a vendor-claimed ceiling and this ranking is the least independently grounded one we publish.
- Torrenting
- For P2P users. Weighted toward what actually exposes a seeder: the logging policy, a kill switch that fails closed, and whether port forwarding exists at all. Mirrors Top10VPN's observation that torrenting quality is mostly a function of the privacy and security categories.
Top10VPN との意図的な相違が1つあります。彼らのトレントスコアは、自社のプライバシースコアとセキュリティスコアをその評価項目に組み込み直します。当サイトはそうしません、トレントの加重はすでにプライバシーとセキュリティにそれぞれ独自のトップレベルの加重を割り当てており、それらを二度目に組み込めば、同じ証拠を二重に数えることになるからです。
5 · 評価項目のルールを組み合わせる3つの方法
背後にある計算を知らずに数値を検証することはできません。そのため、3つのモデルのどれが評価項目を生み出したかが、その横に公開されています。
| モデル | ルールの組み合わせ方 | 使用する項目 |
|---|---|---|
| 絶対 | 基準値から始め、符号付きの減点または加点を加えます。減点方式の評価項目は基準値10、加点していく項目は基準値0です。 | セキュリティ、サーバー真正性、速度、ストリーミング、使いやすさ |
| 正規化 | 獲得した点数を、利用可能な点数で割ります。ただし、証拠があったルールに限ります。これはルール2がひそかに水増しする比率です、以下の限界をご覧ください。 | 透明性、サーバー所在地、デバイス対応、トレント、追加機能 |
| 複合 | 名前の付いたサブスコア、それぞれ絶対または正規化、の加重平均を、採点された部分にわたって取ります。 | プライバシー |
当サイトのデータにおいて、スコアが裸の数値であることは決してありません。スコアは、そのモデル、上限、そして適用されたすべてのルールを、符号付きの寄与と背後にある証拠IDとともに保持しています。別個の独立した実装が、レビューページに表示されている情報だけから各表示スコアを再構築します。内訳が不完全であれば、その検証はビルドを失敗させます。つまり、雰囲気ではなく、特定の減点に対して異議を唱えられるということです。
6 · プライバシーは複合であり、買い戻すことはできない
プライバシーは唯一の複合評価項目であり、5つのサブスコアに分割されます。どのデータがログ記録されるか(60%)、インシデント履歴(20%)、法域(10%)、信頼性(5%)、そしてプライバシー強化機能(5%)です。加点をこれらの小さな部分に限定するのは意図的です。フラットなモデルでは、現金対応への加点が支払い記録の保持への減点を相殺し、10での上限抑制が残りを覆い隠しかねません、ログを記録するプロバイダーとしないプロバイダーが、同じ満点を表示しうるのです。
加重平均は依然として相殺的であり、プライバシーは安全性に関わる性質であるため、この評価項目は自身のログ記録サブスコアに1.5を加えた値を上限とします。有利な法域、透明な所有関係、支払い方法をどう組み合わせても、プライバシースコアを、ログ記録ポリシー単独で得られる値から1.5ポイントを超えて引き上げることはできません。閲覧履歴を無期限に保持するプロバイダーは、Panama の住所でそこから逃れることはできないのです。
7 · 公開される数値は、抑制された区間である
たまたま計測できた評価項目にわたってスコアを再正規化することは、擁護できる推定ではありますが、限界値ではありません、そして旧来型のレビューサイトは、その推定をあたかも限界値であるかのように公開していました。そのため、すべてのスコアは1つではなく3つの数値を持ちます。
未計測のすべてをゼロと数えて、プロバイダーが確実に獲得した値です。証拠が取り除かれたときにしか下がりません、だからこそ、これに基づいてランク付けしても安全なのです。
公開される数値です。再正規化した平均を、上限を決して超えないよう抑え込んだものです。両者が異なる場合、ページは再正規化がプロバイダーを過剰に加算したこと、そしてその差を伝えます。
未計測の各評価項目がそれぞれの上限値に達した場合に到達しうる最大値です、そのため、未計測のストリーミングは10ではなく6.5で加算されます。推測ではなく、保証された最大値です。
縮尺どおりに描かれたこのバーは、当サイトがまだ知らないことの正直な幅を表しています。以下はデフォルトの加重における Proton VPN です。
6.88 から 8.88 の間にあることが証明可能
網掛けの帯は下限 → 上限まで伸び、目盛りが表示スコアです。この抑制は見た目のためのものではありません。ストリーミングの加重において、当サイトがストリーミングの証拠を保有しないあるプロバイダーは、証明可能な最大値8.45に対して9.9に再正規化されました。表示スコアは、どのプロバイダーも到達できない数値を表示する代わりに、それを最大値に抑えています。
8 · ランキングは表示スコアではなく優越関係による
証拠が許す唯一の順序はこれです。AがBより上位になるのは、当サイトが未計測のすべてにおいて、Aの保証された最小値がBの到達しうる最大値を上回るとき、floor(A) > potential(B) のときです。これは厳密な半順序であり、決定的に重要なのは、当サイトがたまたまプロバイダーを調査する順序によって動かされないことです。再正規化した平均では、そう断言できません。
今日の5プロバイダーのコーパスでは、優越関係は空です。最も高い下限、6.88 の Proton VPN、は、最も低い上限、7.55 の SingLink VPN、を大きく下回っており、どのプロバイダーも他を上回りません。それは正直な5者同着であり、当サイトは1-2-3を捏造するのではなく、そう明言します。当サイト独自の計測が揃うにつれ、実際の差が現れてきます。
同着を分ける処理はありません。以前のバージョンは、各プロバイダーをどれだけ調査したかで同着を並べていましたが、それは最も知らないプロバイダーを上位に押し上げていたため、削除されました。
9 · これで解決しないことを、率直に述べる
優越関係は情報の秘匿に対して耐性があるわけではなく、当サイトはそう主張しません。評価項目全体の証拠を削除すれば、秘匿する側の下限が下がり、順位を得ることは決してできません。しかし、正規化された評価項目の中で単一の引用を削除すると、その評価項目の値が上がることがあります。除数は証拠があったルールだけを数えるからです。これは不変条件2を比率に適用したものです、「欠落したデータがスコアを下げることは決してない」は、分母がそれとともに縮む瞬間、「欠落したデータが比率を上げる」に変わります。
これは仮定の話ではなく、現在のコーパスで実際に起きています。あるプロバイダーは、カバー率33%で追加機能に満点の10を獲得しています。当サイトはそのプロバイダーが持つ3つの機能の出典を得ましたが、持っていない機能を示したはずのページについては、そのサイトが当サイトの取得ツールにエラーを返します。欠落したページが満点を買ったのです。
これを塞ぐには、スキーマが「当サイトは調べたが、プロバイダーは開示していない」、それに触れていないページを引用した、採点済みの否定的事実、を、当サイト側の欠落である「当サイトは調べていない」と区別できる必要があります。それまでは、区間と優越関係のルールが再正規化の経路を塞ぎますが、引用の経路は開いたままにします。完全性のゲートがそれを塞ぐのは、公開時のみです。プロバイダーが公開可能となるのは、採点された評価項目に未評価の欠落がない場合に限られるため、スコアを水増しするために引用を削除すると欠落が再び生じ、ページがブロックされます。それは当サイトが公開するものに対するゲートであり、計算の性質ではありません。当サイトは、保証を誇張するよりも、そう明言することを選びます。
計算を検証する
上記のすべては、1つの成果物の上で動いています。これらのページを生成するのと同じコーパスがダウンロード用に提供されているため、任意の表示スコアを再導出したり、異なる加重の下で計算したり、任意の減点の背後にある正確な引用を見つけたりできます。
当サイトはアフィリエイト報酬を一切受け取らず、広告も販売せず、いかなるVPNプロバイダーとも商業的関係を持ちません。