Security and privacy decision

ExpressVPN

A competent engineer can build a useful single-server VPN for personal use over a weekend, but they cannot realistically reproduce ExpressVPN's global server network, proprietary protocol, audited TrustedServer infrastructure, cross-platform polished apps, or bundled services.

Visit website
Subscription$2.99/month ✓ verified
Initial build12 hours
Monthly upkeep2 hours + $0
Evidence2/3 runs agree

Open-source builds that already do this

Every project below is open source and already does this job today. Fork one, self-host it, or take the parts you need — the build prompt further down assumes an empty file, and this is the shortcut past that. Licences differ; check the one on each card before you ship.

What a replacement has to do

  • Provide a secure VPN tunnel from a client device to a server so the client’s traffic is encrypted and proxied through the server.

What it still won’t have

  • Global fleet of 113+ managed servers and many geographic exit locations
  • Proprietary Lightway protocol and ExpressVPN client implementations
  • TrustedServer RAM-only infrastructure and related audited no-logs guarantees
  • Cross-platform polished apps, 24/7 live chat support, and bundled services (ExpressKeys, ExpressMailGuard, Identity Defender)
  • Dedicated IP, split-tunneling integration across platforms, and built-in ad/tracker blocking

What remains hard

  • Infrastructure at scaleServers in 113 Countries
  • Execution qualityLightway protocol supports secure, high-speed connections
  • Execution qualityTrustedServer technology with RAM-only servers
Read the build prompt

First-year cost

Keep paying

Paying ischeaper in year one.

On cash alone, building overtakes the subscription at 1 seat.

Paid seatsseats

Money you would actually spend

Keep paying

Subscription price × seats × 12

Build it

AI build APIs + hosting

Time you would spend

What you would spend

What we assumed

The verdict above measures whether you could build it. This one is only about money.

Runnable build prompt

Not run yet
Build a single-user VPN replacement using DigitalOcean/Hetzner VPS and WireGuard: deploy a Docker-based WireGuard server, run an internal DNS resolver (Unbound) configured to prevent leaks, implement scripts to generate per-device configs and QR codes, provide a minimal web UI (React + Node/Express) to list/download configs and rotate keys, and add health checks and systemd unit for auto-restart. Out of scope: multi-region server fleet, proprietary Lightway protocol, mobile/desktop native apps, commercial identity-protection or password-manager features. Include error handling, logging, automated backup of server configs, and unit/integration tests for config generation and service start/stop.
How we checked4 sources · 2/3 runs agreed · evidence score 60

How the score was reached

  • Partly verdict base52
  • An open-source build was found+5
  • 4 cited sources+3
  • Price verified on pricing page+3
  • Hard moats found in the evidence-3
  • Evidence score60

The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time — so the same evidence always produces the same number.

How scoring works →

Cited sources · 4

Every page the run actually retrieved.

Integrity checks

What held up, and what did not.

✓ Price read off the page! 2 of 3 runs agreed; the verdict is the majority✓ Citations limited to fetched pages! 3 moats quoted from the page