Security and privacy decision
Surfshark
A competent engineer can build a small, single-server VPN replacement (WireGuard + web UI) in ~1 week, but Surfshark’s value—large global server fleet, rotation/Nexus features, bundled privacy products, and brand-scale—is not reproducible at that scope, so keep paying for the full product unless you only need a private single-server VPN.
Visit website↗Open-source builds that already do this
Every project below is open source and already does this job today. Fork one, self-host it, or take the parts you need — the build prompt further down assumes an empty file, and this is the shortcut past that. Licences differ; check the one on each card before you ship.
What a replacement has to do
- Provide encrypted VPN connectivity for a single user/household (WireGuard/OpenVPN) and deliver client configs/installer.
What it still won’t have
- Global fleet of 4500+ RAM-only servers and multi-country exit choices
- IP rotation, Dynamic MultiHop/Nexus features and patented Everlink self-healing
- Cross-platform polished apps, browser extensions, and unlimited-simultaneous-device UX
- Bundled antivirus, private search, identity/alert services, and identity-theft coverage
- 24/7 customer support and audited company-scale no-logs assurances
What remains hard
- Infrastructure at scale
4500+ RAM-only servers
- Brand trust
Widely trusted with 40M+ global app downloads, rewarded with 30+ recognition awards
First-year cost
Keep paying
Paying is—cheaper in year one.
On cash alone, building overtakes the subscription at 2 seats.
Money you would actually spend
Time you would spend
—
What you would spend
What we assumed
The verdict above measures whether you could build it. This one is only about money.
Runnable build prompt
Build a single-server personal VPN using Ubuntu 24.04 on a $10/mo VPS, WireGuard for tunneling, Postgres for one-row user metadata, and a small Node.js + Express web UI. In scope: automated server provisioning script (Terraform or cloud-init), WireGuard server config, per-user key generation, a web page to create a user and download QR/.conf, basic firewall (ufw) rules, DNS (cloudflare or DNS over HTTPS) stub resolver, health-check endpoint, logging of connections (connection timestamp only) and unit tests for key generator and config endpoints. Out of scope: multi-region server fleet, custom mobile/desktop apps, antivirus, search, identity services, IP rotation, and paid support. Include sensible error handling, TLS for the web UI, automated backups of server config, and tests for provisioning and config generation.
How we checked
How the score was reached
- Partly verdict base52
- An open-source build was found+5
- 5 cited sources+3
- Price verified on pricing page+3
- Hard moats found in the evidence-3
- Evidence score60
The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time — so the same evidence always produces the same number.
How scoring works →Cited sources · 5
Every page the run actually retrieved.
- official productSurfshark — official product
- official docsSurfshark features — server count
- official pricingSurfshark pricing — Starter
- open sourceOutlineFoundation/outline-apps
- open sourcehwdsl2/setup-ipsec-vpn
Integrity checks
What held up, and what did not.






