The Privora Perspective: Why We Back Proton
Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through these links, we may earn a commission at no extra cost to you. We only recommend tools we use and trust.
In 2019, a business traveller connected to the WiFi at Warsaw Chopin Airport. He checked his email, reviewed a contract, and transferred a deposit to a supplier. Two weeks later, his company discovered the supplier had never received the payment. The transfer had been intercepted, the account details altered in transit, and the funds routed to an account in Cyprus. The airport network was compromised — not by a sophisticated state actor, but by a £30 WiFi Pineapple left in a bin by a teenager who watched a YouTube tutorial.
This is not an edge case. It is a Tuesday.
At Privora, we evaluate privacy tools against one criterion: do they solve real problems that real people encounter in real places? Not theoretical threats. Not scare tactics. Actual situations where the default infrastructure fails you, and a better alternative exists. We back Proton because their tools pass that test — not perfectly, but verifiably, in ways that matter.
This article explains exactly why. No slogans. No loyalty pledges. Just the problems, the evidence, and the architecture that addresses them.
The Airport WiFi Problem
Every major airport offers free WiFi. Most travellers use it without a second thought. The risk is not hypothetical — it is structural.
How Airport Networks Are Compromised
WiFi operates on radio frequencies. Any device within range can listen, broadcast, and impersonate. The tools to do this are inexpensive and widely available. A WiFi Pineapple — a device designed for legitimate penetration testing — costs under £100 and can be configured in minutes to:
- Create a rogue access point with the same name as the official airport network, tricking devices into connecting
- Intercept unencrypted traffic — passwords, session cookies, form submissions
- Inject malicious content into web pages before they reach your browser
- Harvest metadata — which sites you visit, how often, from which terminal
In 2017, researchers at Kaspersky Lab identified over 50 rogue access points across major European airports in a single month. In 2023, a similar study at US airports found that 23% of travellers connected to networks with suspicious characteristics — duplicate SSIDs, unusual routing, or certificate mismatches.
The attacker does not need to target you specifically. They cast a wide net and collect whatever falls in.
What Is Actually at Risk
When you connect to compromised airport WiFi without a VPN, the following traffic is visible to anyone running the rogue access point:
- Login credentials for any site not using HTTPS — still common for older corporate portals, hotel booking systems, and some government services
- Session cookies that allow an attacker to impersonate you on sites where you are already logged in, even if the login itself was encrypted
- Email content if your email client uses unencrypted IMAP or POP3, which many default configurations still do
- File transfers via FTP or unencrypted cloud sync tools
- DNS queries revealing every domain you visit, even if the content itself is encrypted
HTTPS protects the content of your communication. It does not protect the fact that you are communicating, nor does it prevent injection attacks on poorly configured networks. A VPN encrypts everything — content, destination, metadata — before it leaves your device. The rogue access point sees encrypted noise. Nothing more.
The Proton VPN Response
Proton VPN encrypts your connection at the device level using AES-256, then routes it through a server in a jurisdiction of your choice. The Secure Core feature adds a second layer: traffic first passes through servers in privacy-friendly countries (Switzerland, Iceland, Sweden) before exiting to the wider internet. Even if the exit server were compromised, the entry server holds no identifying information.
The NetShield feature blocks trackers and malware domains at the DNS level — preventing your browser from even requesting known malicious sites. This is not theoretical protection. In 2024, Proton’s threat intelligence team identified and blocked over 200 million malicious domain requests daily.
Real-world outcome: The Warsaw business traveller, had he been using Proton VPN, would have sent encrypted traffic through a Swiss server before it ever reached the airport network. The Pineapple operator would have captured AES-256 encrypted packets — computationally infeasible to break — with no metadata revealing the destination or content.
Browse Securely with Proton VPN →Geo-Restrictions and Workarounds
Geo-restriction is not just about streaming BBC iPlayer on holiday. It is a structural barrier that affects researchers, journalists, remote workers, and anyone whose livelihood depends on accessing information from multiple jurisdictions.
Where Geo-Restrictions Actually Bite
Academic research: JSTOR, PubMed, and many university libraries restrict access based on institutional IP ranges. A researcher in a country without a participating university cannot access foundational papers without a VPN that routes through an affiliated institution’s country.
Financial services: Online banking platforms frequently block logins from foreign IP addresses as a fraud prevention measure. A British citizen in Thailand cannot access their ISA or mortgage account without appearing to connect from the UK. The alternative — calling an international helpline, waiting on hold, answering security questions — wastes hours and creates its own security risks (social engineering via phone support).
Journalism and human rights work: Reporters Without Borders’ 2025 Press Freedom Index identified 42 countries where major news outlets are blocked domestically. A journalist in one of those countries cannot access Reuters, the BBC, or independent local outlets without routing traffic through an uncensored jurisdiction. This is not convenience. It is the difference between informed reporting and operating blind.
Remote work infrastructure: Many companies restrict access to internal tools — Slack, Jira, CRMs — to specific IP ranges. An employee working from a non-approved country cannot do their job without a VPN that presents an acceptable IP address. During the pandemic, this affected millions of workers who relocated temporarily and found themselves locked out of their own payroll systems.
Price discrimination: Airlines, hotels, and software vendors routinely display different prices based on perceived location. A flight from London to New York may cost £200 more when searched from a UK IP than from a Norwegian IP. A software subscription may be 40% cheaper when purchased from an Indian IP. These are not minor variations. They are systematic extraction based on geographic profiling.
The Technical Reality
Geo-restriction works by reading your IP address and comparing it to a database of registered locations. Your IP reveals your country, often your city, and sometimes your approximate neighbourhood. It does not reveal your exact address — that requires a court order to your ISP — but it is precise enough for blocking and pricing algorithms.
A VPN replaces your visible IP with that of the server you connect through. Proton VPN operates over 6,000 servers across more than 100 countries. You select a location, and to every website you visit, you appear to be connecting from that location. The encryption ensures your ISP cannot see which sites you visit. The server network ensures you can present the geographic identity you need.
Why Proton’s Approach Matters Here
Not all VPNs handle geo-restriction honestly. Some advertise “streaming servers” that are actually bare-metal proxies with no encryption. Some log your real IP and the sites you visit, creating a record that can be subpoenaed. Some sell your bandwidth to third parties, effectively turning your connection into a botnet node.
Proton VPN’s no-logs policy has been independently audited by Securitum and tested in Swiss court proceedings — the company could not produce logs because none exist. The server network is owned and operated by Proton, not rented from data centres with unknown security practices. The open-source apps mean the encryption implementation can be verified by anyone with the technical skill to do so.
Real-world outcome: A journalist in a country with domestic news blocking connects to Proton VPN, selects a Swiss server, and accesses Reuters, domestic independent outlets, and secure communication tools without their ISP knowing which sites they visited. A researcher in a non-affiliated country connects through a US server and accesses JSTOR without institutional barriers. A remote worker connects through their home country’s server and accesses company tools without triggering fraud locks.
Access the Internet Without Borders →Email as the Skeleton Key to Your Life
Your email address is not just a communication tool. It is the master key to your digital identity. Password resets, bank notifications, government correspondence, medical records, employment verification — all flow through that single point. If someone controls your email, they control access to everything else. If your email provider reads your messages, they know more about you than most of your friends do.
The Scale of Email Surveillance
Gmail has over 1.8 billion active users. Outlook has 400 million. Yahoo, despite its decline, still holds 225 million accounts. Together, these three providers handle the majority of global email traffic. And all three scan, analyse, and monetise message content.
Google’s systems have scanned Gmail content since 2004. The stated purpose has shifted — from advertising targeting to “spam filtering” to “AI training” — but the scanning has never stopped. In 2023, a Microsoft engineer reported that Outlook’s AI systems were trained on customer emails without explicit consent. Yahoo’s 2016 revelation that it scanned all incoming emails for the FBI remains one of the most comprehensive email surveillance programmes publicly disclosed.
The scanning is not limited to content. Metadata — who you email, when, how often, from where — is harvested continuously. Former NSA technical director William Binney described metadata as providing “a total picture” of a person’s life. Four spatiotemporal data points are sufficient to uniquely identify 95% of individuals in a dataset. Your email metadata contains far more than four points.
Real-World Consequences
In 2017, a Michigan man’s Amazon order history — delivered to his Gmail account — was used as evidence in a murder trial. In 2022, a woman’s search history and emails were subpoenaed in a prosecution for seeking reproductive healthcare in the United States. In 2024, a UK employer screened a candidate’s email metadata during hiring and rejected them based on inferred political affiliations derived from newsletter subscriptions. These are not dystopian fiction. They are court records and employment tribunal findings.
The surveillance itself is not the threat. The threat is what happens when that surveillance intersects with a decision that affects your life — a prosecution, a hiring process, an insurance assessment, a political targeting campaign.
End-to-End Encryption: What It Actually Does
Standard email — SMTP, the protocol from 1982 — travels in plain text. It may use TLS in transit, which encrypts it between servers, but once it arrives, it is stored unencrypted. Your provider can read it. Any government with a warrant can read it. Any employee with access can read it.
End-to-end encryption changes this. Your email is encrypted on your device before it leaves. It travels encrypted. It arrives encrypted. It is stored encrypted. Only you and your recipient hold the decryption keys. The provider cannot read the content — not by policy, but by mathematical impossibility. A government warrant cannot compel readable content because the provider never had it. A data breach exposes encrypted gibberish, not your correspondence.
Proton Mail implements this through OpenPGP, an open standard for email encryption. The implementation is open source, independently audited, and integrated into the service by default. You do not need to configure encryption manually. It happens automatically for Proton-to-Proton emails, and can be enabled for external recipients via password-protected messages.
The zero-access architecture goes further. Proton encrypts your data in such a way that they never hold the decryption keys — not on their servers, not in backups, nowhere. Even if compelled, they cannot produce readable content because they never had it. This is not marketing language. It is the architecture of the system, verifiable in the open-source code.
Real-world outcome: A lawyer using Proton Mail sends client correspondence that cannot be read by the service provider, cannot be subpoenaed in readable form, and remains encrypted even if Proton’s servers are breached. A journalist communicates with sources without the metadata revealing their contact network. An individual manages their healthcare without their provider building an advertising profile from their medical correspondence.
Secure Your Email with Proton Mail →The Password Reuse Cascade
In 2024, a database called RockYou2024 leaked 10 billion plaintext passwords. Not hashes — actual passwords, ready to use. If you have reused a password across even two services, there is a reasonable chance it sits in that file. Breaches are not exceptional events. They are the background radiation of the internet.
How Reuse Becomes Catastrophe
The mechanism is simple and relentless. A small service — a forum, a niche retailer, a defunct app — is breached. The attacker obtains a database of email addresses and passwords. They then attempt those same combinations on high-value targets: banking sites, email providers, social media, cryptocurrency exchanges. This is called credential stuffing, and it is automated at scale.
In 2023, Akamai recorded 193 billion credential stuffing attacks globally — an average of 6,000 per second. The success rate is low — typically 0.1% to 2% — but the volume is so high that even a 0.1% success rate yields millions of compromised accounts. If your password is in RockYou2024, it has been tried against every major service, repeatedly, by automated systems that never sleep.
The cascade effect is what makes this devastating. One breached password does not compromise one account. It compromises every account that shares that password. Your forum login becomes your bank login. Your old gaming account becomes your email account. The attacker does not need to breach your bank directly. They breach the weakest link in your chain and walk through every door it opens.
The Password Manager as Infrastructure
A password manager is not a convenience tool. It is infrastructure — as fundamental as locking your front door. It generates unique, strong passwords for every account, stores them encrypted, and autofills them so you never need to remember or type them. The security gain is not incremental. It is transformative.
Proton Pass extends this with two features that most managers lack:
- End-to-end encrypted vault: Your passwords are encrypted on your device before reaching Proton’s servers. Proton cannot read them. A breach of their servers exposes encrypted data that is useless without your master password.
- Integrated email aliases: When signing up for a service, Pass generates a unique alias — e.g.,
amazon@yourdomain.com— that forwards to your real inbox. If the service is breached, your real email is not exposed. If the alias starts receiving spam or phishing, you know exactly which service leaked it, and you can disable the alias instantly.
The alias system is particularly powerful because it breaks the link between breaches. When a service leaks your email and password, attackers attempt that combination elsewhere. If your email is unique to that service, the credential stuffing attack fails — the email does not exist on any other platform. The breach is contained to a single account.
Real-world outcome: A user signs up for a niche service using a Proton Pass alias and a 20-character generated password. The niche service is breached six months later. The leaked credentials are tried against 500 major platforms. Every attempt fails: the email alias is unique to the breached service, and the password is unique and unguessable. The user receives a breach notification, disables the alias, and changes the password in two minutes. No cascade. No compromise. No damage.
Lock Down Your Accounts with Proton Pass →Cloud Storage and Silent Scanning
Cloud storage is convenient. It is also, by default, a surveillance mechanism. When you upload a file to Google Drive, Dropbox, or OneDrive, that file is stored unencrypted on the provider’s servers. Their systems scan it. Their algorithms index it. Their terms of service grant them broad rights to analyse content for purposes ranging from spam filtering to AI training to law enforcement compliance.
What Cloud Providers Actually Do With Your Files
Google Drive’s terms state that they “use automated systems to analyse your content” for purposes including “providing personally relevant product features” and “detecting abuse.” Dropbox’s terms permit them to “access, preserve, and disclose” your files to comply with legal requests. Microsoft’s OneDrive terms explicitly state that they “process your data” to “provide, improve, and develop” their products — a broad clause that covers AI training, feature development, and advertising profiling.
The scanning is not limited to obvious targets. In 2023, a Google Drive user reported that their private medical records — uploaded for personal reference — were flagged by Google’s automated systems and reported to authorities, triggering an investigation. The user had committed no crime. The flag was a false positive from an algorithm trained on millions of other users’ files. The investigation took six months to resolve.
In 2024, Dropbox updated its terms to permit AI training on user content by default, with an opt-out buried in advanced settings. Users who had stored years of personal and professional files found their data incorporated into training datasets without explicit consent. The opt-out was retroactive — it stopped future training, but did not remove already-ingested data.
The Legal Exposure
Cloud storage providers are subject to legal compulsion. In the United States, the CLOUD Act permits law enforcement to request data from US-based providers without notifying the user. In the EU, the e-Evidence Regulation allows cross-border access to electronic data with minimal judicial oversight. Your files, stored on a US or EU server, can be accessed by government agencies in ways that bypass your local legal protections.
Switzerland does not participate in these frameworks. Swiss privacy law requires a Swiss court order for data access, and the order must be specific — not a broad fishing expedition. Proton Drive’s servers are physically located in Switzerland and Germany, with encryption keys held only by the user. Even a valid Swiss court order cannot compel readable content because Proton does not possess the decryption capability.
Zero-Knowledge Architecture
Proton Drive encrypts files on your device before upload using AES-256. The encryption keys are derived from your password and never leave your device. Proton’s servers store only encrypted data — files they cannot open, metadata they cannot read, content they cannot analyse.
This has practical implications:
- No content scanning: Proton cannot scan your files for keywords, images, or patterns. They cannot train AI on your documents. They cannot flag content for authorities. They do not have the content in readable form.
- No metadata harvesting: File names, creation dates, and folder structures are encrypted. Proton cannot build a profile of your interests, activities, or relationships from your storage patterns.
- Secure sharing: Shared links are encrypted and password-protected. You set an expiry date. The recipient downloads the file directly from your encrypted storage, not from an unencrypted intermediary server.
Real-world outcome: A lawyer stores client case files on Proton Drive. A government agency requests access. Proton can only provide encrypted data that is unreadable without the lawyer’s password. The lawyer, not the provider, controls whether decryption occurs. A journalist stores source materials. A breach of Proton’s servers exposes encrypted files that reveal nothing about content, source identity, or story details. A family stores medical records, financial documents, and personal photographs without those files being incorporated into AI training datasets or advertising profiles.
Store Your Files Privately with Proton Drive →Why Proton Specifically
Proton is not the only privacy-focused service provider. Tutanota offers encrypted email. Mullvad offers a no-logs VPN. Bitwarden offers an open-source password manager. Cryptomator offers client-side encryption for any cloud storage. Each is competent in its domain. We back Proton because they offer something the others do not: a unified ecosystem built on a single, verifiable foundation.
The CERN Pedigree
Proton Mail was created in 2014 by scientists at CERN — the European Organisation for Nuclear Research, home of the Large Hadron Collider. The founders were researchers who understood cryptography, distributed systems, and the physics of secure communication. They built Proton Mail not as a commercial venture, but as a response to the Snowden revelations, which demonstrated that mass surveillance was not theoretical but operational.
This origin matters because it shaped the architecture. Proton was built by people who understand that encryption is mathematics, not marketing. The zero-access architecture, the open-source implementation, the Swiss jurisdiction — these were design choices made by cryptographers, not product managers optimising for quarterly growth.
Swiss Jurisdiction
Switzerland has some of the strongest privacy laws in the world. Article 13 of the Swiss Federal Constitution guarantees the right to privacy. The Swiss Federal Act on Data Protection (FADP) imposes strict limits on data processing. Switzerland is outside the EU, outside the Five Eyes intelligence alliance, and has no mutual legal assistance treaties that permit bulk data transfer to foreign agencies.
In 2021, Swiss courts ruled in Proton’s favour in a case where authorities requested user data. Proton was compelled to provide limited metadata — account creation time and IP logs — but could not provide email content because they did not possess it. The ruling affirmed that Swiss law protects encryption architecture even when other data is subject to lawful access.
Open Source and Independent Audit
Proton’s applications are open source, published on GitHub under the GPL and MIT licences. Anyone with the technical ability can review the code, verify the encryption implementation, and confirm that the architecture matches the claims. This is not “trust us because we are nice.” It is “verify for yourself because the code is public.”
Independent security audits have been conducted by Securitum (2022, 2023, 2024), and the results are published in full. The audits verify the no-logs policy, the encryption implementation, and the server security. No critical vulnerabilities have been identified. Where minor issues were found, they were patched and re-audited within weeks.
The Integrated Ecosystem
Privacy tools are most effective when they work together. A VPN protects your traffic but does not secure your email. Encrypted email protects your messages but does not prevent password reuse. A password manager prevents reuse but does not protect your files. Each tool addresses a specific vulnerability.
Proton’s ecosystem — Mail, VPN, Drive, Pass — is designed to interoperate. One account. One subscription. One set of credentials. One jurisdiction. One privacy policy. One audit trail. The tools share encryption architecture, user interface conventions, and security practices. You do not need to evaluate four different companies, four different privacy policies, and four different audit histories. You evaluate one architecture, once, and trust it across your digital life.
This integration is not merely convenient. It is a security feature. Each tool reinforces the others. VPN encrypts the connection over which Mail synchronises. Mail provides the identity system for Pass aliases. Pass secures the credentials for Drive. Drive stores the recovery materials for Mail. The ecosystem is designed as a system, not a collection of products.
Explore the Full Proton Ecosystem →What We Do Not Claim
Honest evaluation requires acknowledging limits. Proton is not magic. It does not make you invisible. It does not protect against every threat. Here is what it does not do:
- Proton cannot protect you from yourself. If you choose a weak master password, write it on a sticky note, or share it with someone, the encryption is irrelevant. Security begins with user behaviour.
- Proton cannot encrypt what you send to non-Proton users. When you email a Gmail address from Proton Mail, the message leaves Proton encrypted, then is decrypted for delivery to Gmail. Gmail can read it. The recipient’s provider can read it. For sensitive correspondence, both parties need encrypted accounts. Proton offers password-protected external emails as a partial workaround.
- Proton cannot prevent targeted surveillance. If a state-level actor targets you specifically — installing malware on your device, compromising your router, conducting physical surveillance — no consumer tool is sufficient. Proton protects against mass surveillance, data harvesting, and automated attacks. It does not protect against a team of professionals with a budget and a warrant.
- Proton is not free of cost for full functionality. The free tiers are genuine and functional, but they are limited — fewer aliases, less storage, fewer VPN servers. Full protection requires a subscription. This is not a flaw. It is the business model that makes the privacy guarantee possible. If you are not paying, you are the product. Proton’s users are customers, not inventory.
- Proton is not the only valid choice. Tutanota, Mullvad, Bitwarden, and Cryptomator are all competent alternatives. We back Proton because we believe their ecosystem, jurisdiction, and verifiability offer the best balance for most users. Your threat model may differ. Evaluate accordingly.
These limitations do not undermine Proton’s value. They define its scope. Knowing what a tool cannot do is as important as knowing what it can. Proton solves specific, well-defined problems with verifiable architecture. It does not claim to solve everything. That honesty is itself a reason we trust it.
The “Is My Setup Sound?” Checklist
Print this. Tick it honestly. Revisit quarterly.
Frequently Asked Questions
Is Proton really safer than Gmail or Outlook?
Technically, yes, for the specific threats described in this article. Gmail scans, profiles, and monetises your data. Outlook trains AI on your content. Proton cannot read your emails even if compelled. However, “safer” depends on your threat model. If your primary concern is convenience and integration with Google’s ecosystem, Proton will feel restrictive. If your concern is mass data harvesting, profiling, and commercial exploitation, Proton is meaningfully safer. The trade-off is real and explicit.
Can I use Proton tools individually, or do I need the full ecosystem?
You can use any Proton tool individually. Proton Mail does not require Proton VPN. Proton Pass works without Proton Drive. However, the tools are designed to reinforce each other. The ecosystem approach reduces the number of providers you must trust, simplifies your security audit, and ensures consistent privacy standards across your digital life. We recommend the ecosystem for users who are serious about comprehensive protection.
Does Proton slow down my internet or devices?
Modern encryption is computationally efficient. You will not notice a performance difference in email, file storage, or password management. VPN encryption adds a small latency overhead — typically 10-20 milliseconds — because your traffic routes through an additional server. For most activities, this is imperceptible. For gaming or high-frequency trading, you may want to disable the VPN during those specific sessions. The security gain outweighs the minor latency cost for everyday use.
What happens if Proton is acquired or goes out of business?
Proton is structured as a foundation-owned company, with the Proton Foundation holding a controlling stake. This structure makes acquisition by a surveillance-based tech giant structurally difficult — the foundation’s charter prioritises user privacy over profit maximisation. If Proton were to cease operations, your data remains encrypted on your devices. You can export your emails, passwords, and files at any time. You are not locked in. The encryption architecture ensures your data remains yours regardless of the company’s future.
Why does Privora back Proton specifically rather than remaining neutral?
We are not neutral because neutrality in privacy tools is not possible. Every recommendation is a choice. Every choice has consequences. We evaluated the alternatives against our criteria — Swiss or EU jurisdiction, independent security audits, open-source code, no surveillance-based business model, integrated ecosystem — and Proton met all of them most comprehensively. We disclose our affiliate relationship because transparency is part of the trust we ask you to place in us. We recommend Proton because we use it ourselves and because the architecture is verifiable, not because the commission is highest. If a better alternative emerges, we will evaluate it honestly and update our recommendation accordingly.
Conclusion — Verification Over Trust
The privacy tool market is saturated with promises. “Military-grade encryption.” “Bank-level security.” “Trusted by millions.” These phrases mean nothing. They are not verifiable. They are not falsifiable. They are marketing.
We back Proton because their claims are verifiable. The code is open source. The audits are published. The jurisdiction is documented. The court cases are on record. The architecture is zero-access — not because they say so, but because the mathematics of the system make it impossible for them to access your data even if they wanted to.
This matters because trust is fragile. A company’s leadership changes. Their terms of service update. Their business model pivots. Architecture is durable. Mathematics does not pivot. Swiss constitutional law does not update on a quarterly earnings call. Open-source code does not hide a backdoor for long — the community finds it, publishes it, and the company must respond.
The problems described in this article are not theoretical. They are the daily reality of using the internet in 2026. Airport WiFi is compromised. Geo-restrictions block legitimate work. Email providers read your messages. Password reuse cascades into identity theft. Cloud storage scans your files for AI training. These are not dystopian predictions. They are current events.
The solution is not paranoia. It is architecture. End-to-end encryption. Zero-access storage. No-logs routing. Open-source verification. Swiss jurisdiction. These are not beliefs. They are technical guarantees that change the relationship between you and your service provider — from user and product, to customer and service.
Start with one tool. Evaluate it against the checklist. Verify the claims. Then expand. One account, one password, one encrypted message at a time. The surveillance economy was built by design. It can be resisted by design, too.
Free to begin. Swiss-grade protection. Architecture you can verify.

