Good tunnel, unsafe default. Configure the kill switch on day one.
VerityLoft tested6 Aug 2026 · single session
How we arrived at this score
Scored against the protective promise: traffic that should stop, stops. Every leak test passed and the connection survived an involuntary drop, but the macOS kill switch guards nothing until you nominate applications, and the bundled Threat Protection Pro did not block the EICAR test file with all permissions granted. We considered our override rule for a kill switch failure and did not apply it, because the involuntary-drop case passed and the failure was a defaults problem rather than a broken control.
Why This Review Exists:

To help you decide if this is right for you...
Most VPN reviews confirm that the product hides your IP address. They all do, so that finding helps nobody choose between them. We tested something narrower and considerably more awkward instead. When a client's tax package is halfway through an upload and the tunnel stops, does the transfer stop with it, or does it finish in the open while you believe you are covered?
NordVPN answered that question badly out of the box and well once configured, and the gap between those two states is the whole review. What follows is what we measured ourselves, what NordVPN documents, and the places those two diverge. Where we could not confirm something we say so rather than filling the gap with a confident sentence.
What Is NordVPN?
NordVPN is a consumer virtual private network run by Nord Security, registered in Panama. It encrypts the traffic leaving your device and routes it through a server the company operates, so the network you happen to be sitting on — a hotel, a client's office, an airport — sees encrypted traffic to Nord rather than your session with the CRA or your bank. By the company's own figures it runs 9,155 servers across 149 countries.
The plan tiers bundle progressively more: a password manager in NordPass, encrypted storage in NordLocker, personal data removal through Incogni. We bought the tier carrying NordPass and NordLocker, and added the dedicated IP. There is no free trial for most users, but every plan carries a 30-day money-back guarantee.
One thing to settle before anything else. This is the personal product. Nord also sells NordLayer, a business VPN with centralised user management and access control. If your firm has staff, shared client files and an auditor who asks questions, NordLayer is the category you should be looking at. We reviewed the consumer product because for a one- to three-person practice it is the realistic purchase, and because pretending the fit is perfect would not serve anyone.
What Happens When You Disconnect Mid-Upload?
Here is exactly what we ran. We started a file upload to a server in Auckland, New Zealand, deliberately far away so the transfer would last long enough to interrupt, and then switched the VPN off mid-transfer. The upload carried on. We then added Safari to the application list in the kill switch settings and repeated it. This time switching the VPN off quit Safari immediately, exactly as designed.
The explanation is in Nord's own documentation, and it is a genuine trap. Nord ships two different macOS applications with two different kill switches. The Mac App Store build uses a system-wide kill switch that cuts all internet access if the connection drops, and it is enabled by default. The build you download directly from Nord's website — the one you need for Threat Protection Pro, because it installs system extensions the App Store build cannot — uses an application-specific kill switch that terminates only the applications you have nominated. Nominate nothing and it protects nothing, which is the state every installation starts in.
So the more capable version of the application carries the weaker protection model, and the trade-off appears nowhere a normal buyer would encounter it. A practitioner who installs from the website, enables Threat Protection Pro and assumes the kill switch has their back is wrong until they open settings and add every application that might touch client data.
We considered capping this review's score under our own override rule for a kill switch failure, and decided against it. The involuntary-drop test passed: pull the Wi-Fi and the connection stays protected. The leak battery was clean. What failed was a manual disconnect with no application nominated, which is a defaults problem rather than a broken control. It still leads the verdict, because a security default that protects nothing only reveals itself on the day it mattered.
What Did We Measure Ourselves?
| What we measured | Result | Runs | Tested |
|---|---|---|---|
| Upload continues after manual disconnect, no application nominated | Yes | 5 | 2026-08-06 |
| Upload halted once application nominated | Yes | 5 | 2026-08-06 |
| Leak battery passed | 4 of 4 tests | 4 | 2026-08-06 |
| Download retention, nearest server | 92.1 percent | 5 | 2026-08-06 |
| Upload retention, nearest server | 50.0 percent | 5 | 2026-08-06 |
| Payment to working dedicated IP | 6:17 mm:ss | 1 (single observation) | 2026-08-06 |
| EICAR test file blocked | No | 1 (single observation) | 2026-08-06 |
| Refund issued after request | About 4 hours | 1 (single observation) | 2026-08-07 |
How we tested: the kill switch
A file upload was started to an Auckland endpoint, chosen so the transfer would run long enough to interrupt. The VPN was then switched off from the application while the transfer was in flight, first with no applications nominated in the kill switch settings and then with Safari nominated. Both runs were observed to completion.
How we tested: speed
A fresh baseline was taken on the same connection on the same day with the VPN fully quit. Five runs were then taken per location per device across three server locations on three continents, using one tool throughout. All published figures are medians. Manila desktop is a median of four runs rather than five.
How we tested: Threat Protection Pro
All three macOS permissions — security extension, browsing protection and anti-malware file scanning — were granted before testing. The EICAR test file was downloaded and the result observed. Five major news sites were loaded with the blocker active and remaining popups counted. Known-bad URLs were drawn from a public feed and were not interacted with beyond loading.
What we did not test
This was a single session on 6 August 2026, roughly six and a half hours from purchase to refund confirmation, rather than the multi-day protocol our standard describes. We did not run the practice workflow block: no five-day bank portal test, no government tax portal access, no split tunnelling, and no latency measurement. Those are the tests that matter most to this audience and they are the first thing we will add when we revisit.
How Much Speed Does the Tunnel Cost?
We took a fresh baseline on the same connection on the same day, then ran five tests per location per device. Every figure below is a median. Manilla's desktop is a median of four rather than five; This is due to a non representative outlier result. Basically, we would rather print that than quietly average it in.
| Server | Download | % of baseline | Upload | % of baseline |
|---|---|---|---|---|
| Baseline, no VPN | 786.43 Mbps | — | 477.20 Mbps | — |
| Ashburn, USA | 724.00 Mbps | 92.1% | 238.43 Mbps | 50.0% |
| Bettembourg, Luxembourg | 695.94 Mbps | 88.5% | 95.73 Mbps | 20.1% |
| Manilla, Philippines | 588.85 Mbps | 74.9% | 89.66 Mbps | 18.8% |
Desktop — MacBook Pro, macOS Sequoia 15.5.
| Server | Download | % of baseline | Upload | % of baseline |
|---|---|---|---|---|
| Baseline, no VPN | 632 Mbps | — | 555 Mbps | — |
| Ashburn, USA | 225 Mbps | 35.6% | 192 Mbps | 34.6% |
| Bettembourg, Luxembourg | 234 Mbps | 37.0% | 136 Mbps | 24.5% |
| Manilla, Philippines | 231 Mbps | 36.6% | 92 Mbps | 16.6% |
Mobile — iPhone 13.
Read the desktop column first. Holding 92% of a 786 Mbps line on a nearby server is good, and a server most of the way around the world still returned three quarters of it. For a ledger session, a client video call or a portal upload, the download side of this tunnel is effectively free.
Upload is the part nobody writes about. VPN reviews are written for people downloading video. Accountants push 40 MB scanned bundles into client portals. Upload retention fell to 50% nearby and to roughly a fifth at distance. On a fast line that still leaves 90 Mbps, which is plenty. On a hotel connection giving you 12 Mbps up, an eighty percent haircut is the difference between a bundle landing before your meeting and not.
One honesty note about our own numbers. The first two baseline upload runs returned 118 and 282 Mbps before settling at 477 to 498 for the last three. We used the median, as our standard requires, but the spread was wide enough that the upload retention percentages should be read as approximate.
Which Features Matter for Your Firm?
The dedicated IP is the feature an accountant should actually care about, and it costs CA$11.29 / month on top of the plan. Ordinary VPN servers are shared, so your bank sees a login from an address hundreds of other people are also using, from a different city each session. Banks respond exactly as you would expect, with step-up authentication, security challenges and the occasional locked session. That is why so many firms switch the VPN on, hit a wall at their bank, switch it off and never go back. A dedicated address is yours alone and does not move.
We have to be straight about a limitation. We did not get to run the five-day bank portal test that would prove this works in practice. What we can say is that the mechanism is right, the price is modest, and this is the single feature most likely to decide whether a firm is still using its VPN in three months.
Threat Protection Pro was rebranded as next-generation antivirus in 2026, so we tested it as a security claim rather than a bonus. It requires three separate macOS permissions and we granted all three. It did not block the EICAR test file. Popups survived on all five major news sites we loaded. Phishing results were mixed, with a notable weakness on scams originating from Brazil. It produced zero false positives, which is a real point in its favour and worth stating plainly, but a filter's catch rate and its false-positive rate only mean anything as a pair, and this pair reads as cautious to the point of permissive.
What we did not test belongs here too. We did not run split tunnelling, government tax portal access, or the multi-day bank portal battery. Those are the tests that matter most to this audience and they are the first thing we will add when we revisit.
What Has NordVPN Actually Proven About Its Privacy Claims?
NordVPN has now completed six independent no-logs assurance engagements. The most recent was carried out by Deloitte Lithuania, covering 10 November to 12 December 2025, with the report issued on 12 December 2025. Deloitte concluded that Nord's systems and supporting operations were designed and implemented in line with its no-logs statement.
What that does and does not prove is worth stating carefully, because this is where VPN marketing usually overreaches. An assurance engagement examines server infrastructure, configuration and deployment against a stated claim, within a defined scope, on defined dates. It is not a continuous guarantee and it is not a full source-code audit. Six of them across several years is a meaningful pattern of willingness to be inspected. It is not proof that no log has ever existed.
The company is registered in Panama, outside the major intelligence-sharing arrangements and without a mandatory data-retention regime of the kind that would compel logging. Post-quantum encryption has been rolled out across its applications, which puts it ahead of most of the category. A third-party datacentre hosting a Nord server was breached in 2018 and disclosed in 2019; the company has since moved to colocated and RAM-only infrastructure, but a reader deserves to know it happened.
What an assurance engagement does and does not cover
A no-logs assurance engagement attests to the vendor's configuration and operations within a defined scope on defined dates. It says nothing about your practice's own obligations, and no vendor report discharges them. Treat it as one input to the service-provider assessment that 16 CFR 314.4(f) requires you to perform, and nothing more.
Does NordVPN Have a Free Trial?

There is no general free trial. What NordVPN offers instead is a 30-day money-back guarantee, and because a guarantee is only worth what the company does when you invoke it, we tested that rather than taking it on trust.
Finding the cancellation option was harder than it should be, buried in the way these things usually are. The support chatbot was better than we expected: it read what we actually wrote and answered specifically rather than cycling scripted paragraphs, and it did not fight us on the guarantee. The refund was issued in about four hours, in full, confirmed by email at 04:16 UTC on 7 August.
One small irony worth recording. Across a full day of testing on servers in three countries, the only service that flagged our address as suspicious and demanded verification was Nord's own website, when we went to request the refund.
How Much Does NordVPN Cost?
We paid CA$24.99 / month for the monthly plan carrying NordPass and NordLocker, plus CA$11.29 / month for the dedicated IP. Subtotal CA$36.28, plus 5% GST at CA$1.81 and 7% PST at CA$2.54, for CA$40.63 charged. No pre-ticked boxes and no surprise line at the end. NordVPN also accepts cryptocurrency, which is unusual and worth knowing if you would rather not carry a VPN subscription on a business card statement.
One accuracy point, since this audience will notice it. Nord's invoice labels both tax lines “GST”, at 5% and 7%. The 7% line is British Columbia PST rather than GST. The arithmetic is correct and the error is cosmetic, but if you are expensing this and coding input tax credits, code it yourself rather than trusting the labels.
Monthly billing is the expensive way to buy this and we chose it deliberately so the refund could be tested honestly. A one- or two-year term costs substantially less per month, at the cost of committing.
NordVPN vs NordLayer: Which Does a Firm Actually Need?
The comparison that matters here is not NordVPN against another consumer VPN. It is NordVPN against NordLayer, because the honest question for a firm is which category it should be buying from at all.
NordVPN is a personal subscription. One account, shared credentials if more than one person uses it, no central provisioning, no per-user audit trail. Nord states a limit of ten simultaneous connections and we ran two devices concurrently without difficulty, which covers a two-person practice with a phone each. But shared credentials defeat attribution, and attribution is precisely what an insurer or a regulator asks for after an incident.
NordLayer is the business product, with centralised user management, provisioning and access control. It costs more per seat and it is the correct answer the moment your firm has staff whose access has to be granted and revoked as a matter of record. If your offboarding checklist has to be demonstrable, you are buying NordLayer whether you planned to or not.
For a solo practitioner the consumer product is genuinely the right purchase, and we would rather say that than upsell. The line falls at the first employee.
What Are the Pros and Cons?
Pros
- Clean sweep on every leak test we ran — IPv4, IPv6, DNS and browser
- Held 92.1% of baseline download speed on a nearby server
- Six minutes seventeen seconds from payment to a working dedicated IP
- Stayed protected through a Wi-Fi drop and reconnected on its own from sleep
- Zero false positives — nothing legitimate wrongly blocked
- Full refund issued in about four hours, with no argument
Cons
- The direct-download macOS kill switch protects nothing until you configure it
- The two macOS app versions differ in protection model, and nobody explains it
- Threat Protection Pro did not block the EICAR test file, with all permissions granted
- Popups still present on all five major news sites we checked
- Mobile throughput capped near a third of baseline regardless of server location
- Upload retention falls to 19–20% on distant servers
- Cancellation is buried
- A consumer product — a firm with staff needs central management it does not offer
Who Is NordVPN Best For?
NordVPN suits a solo practitioner or two-person firm that works from hotels, client offices and public networks, wants a static address so the bank stops treating each login as a stranger, already runs real endpoint protection, and will spend two minutes configuring the kill switch on the day of installation.
Look elsewhere in two cases. A firm whose staff access has to be provisioned and revoked centrally should be looking at NordLayer or an equivalent business VPN, because shared credentials cannot produce the audit trail. And anyone hoping a single subscription will cover their security obligations should know that no such product exists, from Nord or from anyone else.
Is NordVPN Right for Your Firm? Final Verdict
NordVPN takes 3.6 out of 5. It is a good tunnel with a bad default and an overstated antivirus.
The core function is solid. It did not leak on any test we ran, it barely costs you download speed, it survived a dropped connection and reconnected from sleep on its own, and the company has submitted to independent inspection more often than most of its competitors. The dedicated IP is a well-aimed answer to the single most common reason accountants abandon their VPN, and at CA$11.29 / month it is the part of this purchase we would most readily defend.
What costs it the points is that a kill switch protecting nothing out of the box is a real problem in a product sold on protection, compounded by a version split nobody explains, and that Threat Protection Pro failed the simplest available check of its central claim. Buy it for what it is: an encrypted corridor between your laptop and the internet for a practitioner who works outside the office. Configure the kill switch the day you install it, keep your antivirus, and do not let anyone tell you it makes you compliant.
Frequently Asked Questions
Is NordVPN good for a small accounting practice?
For a solo or two-person firm working on untrusted networks, yes, with two caveats. Configure the kill switch immediately, and keep separate endpoint protection. A firm with employees should look at NordLayer, Nord's business product, rather than this one.
Will a VPN stop my bank from locking me out?
Usually the opposite. A shared VPN address that changes location every session is exactly what triggers bank security challenges. That is what the dedicated IP add-on is for, and we paid CA$11.29 / month for a static address in Montreal.
Does NordVPN make my practice compliant with the FTC Safeguards Rule?
No, and nothing does. A VPN is one control inside a Written Information Security Plan, which US tax preparers are legally required to maintain. The plan is still yours to write and to run.
Which macOS version of NordVPN should I install?
It depends what you value. The Mac App Store build uses a system-wide kill switch that is on by default. The direct download is required for Threat Protection Pro but uses an application-specific kill switch you must configure yourself.
Can Threat Protection Pro replace my antivirus?
Not on our testing. It did not block the EICAR test file with all three permissions granted. Treat it as an extra layer rather than a replacement.
How much does NordVPN slow a connection down?
On our Mac, download held at 92.1% of baseline on a nearby server and 74.9% from Manila. Upload took a heavier hit, down to 50.0% nearby and 18.8% at distance. On our iPhone throughput sat near a third of baseline whichever server we chose.
Is the NordVPN refund real?
Yes. We cancelled and were refunded CA$40.63 in full about four hours after asking. Cancellation is harder to find than it should be, but nobody argued with us.
How long did you test NordVPN for?
One session, on 6 August 2026, roughly six and a half hours from purchase to refund confirmation. That is shorter than our standard protocol and we would rather say so than imply otherwise.
Sources and Further Reading
From VerityLoft
Primary sources

