VPN services can either rent or own the servers that make up their network, and the choice has important consequences for privacy, security, and performance.
While investigating VPN providers, I’ve found that some are noticeably reluctant to disclose when they’re using rented servers.

There are three main options when it comes to server ownership:
- On-Site Ownership: The VPN purchases, installs, and maintains its servers itself. It owns them outright and stores them on company premises, so only trusted employees have physical access to them.
- Colocation Agreement: The VPN owns and operates its servers but stores them off-site, usually in a data center. For a fee, the data center provides storage, cooling, and bandwidth. The company’s staff monitor the servers remotely and visit in person to repair hardware when needed.
- Rented Servers: The VPN service rents its servers straight from a data center, avoiding the expense, time, and expertise needed to buy, install, and maintain hardware. The data center handles the physical machine, and the VPN company is given remote access to handle the software.
Below, I’ll explain the different ownership options available to VPN services, along with their advantages and disadvantages.
On-Site Ownership
Table listing the pros and cons of owning VPN servers.
| Pros |
Cons |
| Complete control over hardware and network |
Huge up-front costs |
| Prevents third parties physically accessing the server |
Weakened connection speeds |
| Prevents third party logging server data |
Smaller server networks |
From a privacy and security perspective, the ideal VPN service owns its entire server network and stores it on-site.
The provider knows everything about the hardware, nobody outside the company can physically access the machines, and no third party can log server activity.
That last point is the one I care about most. A zero-logs policy is useless if the data center housing the hardware is collecting logs on the side.
First-party on-site ownership is the only way to guarantee there’s no third-party involvement beyond the company you’ve explicitly chosen to trust.
However, on-site ownership isn’t practical for most VPN services. It’s extremely expensive: VPN providers have to fund servers, bandwidth, cooling facilities, back-up hardware, and a team of administrators, with those costs multiplying for each new location.
On-site servers can also be slower than rented or colocated alternatives, since they tend to sit further from major internet exchanges.
And strict on-site ownership caps how far a VPN can expand, since the service would need to own land in every country it wants a server in.
Colocation Agreements & Rented Servers
Table listing the pros and cons of colocated and rented servers.
| Pros |
Cons |
| Remote management makes tampering easy to spot |
Third parties may have physical access to the server |
| Faster speeds, thanks to proximity to internet exchanges |
Servers may be vulnerable to upstream traffic monitoring |
| Far cheaper than on-site ownership |
|
| Larger server networks, and quicker to add new locations |
|
If a VPN service wants the security benefits of owning its own hardware without the drawbacks of housing it, the best compromise is a colocation agreement with a trustworthy data center so it can physically inspect and audit its own machines.
Renting takes the VPN provider one step further away from the hardware. Rented servers are installed, monitored, and maintained entirely by data center employees, which means that in theory, a third party has the ability to tamper with them.
In practice, that risk is smaller than it sounds. Most modern rented and colocated servers ship with a Remote System Management Card. Combined with real-time system logging, this lets a VPN provider monitor almost everything about a server’s operation remotely, and shut it down the moment anything looks suspicious.
The bigger privacy issue isn’t the server hardware itself, more so the networking environment it sits inside of.
Any server in a data center sits on that data center’s network, and a VPN can never be certain that its traffic isn’t being monitored upstream.
That’s especially relevant in countries with invasive data privacy laws, where local authorities could monitor traffic or compel the data center to log on their behalf, without the VPN provider ever knowing.
Both rented and colocated servers benefit from data center infrastructure, with proximity to internet exchanges and delivering faster speeds as a result.
Renting adds flexibility on top of that. Rental agreements scale up or down with demand, so a VPN provider can quickly offer new locations and IP addresses. Colocation keeps providers tied to the hardware they’ve already bought.
Which VPNs Rent Their Servers?
Most VPNs combine rented and colocated servers in their networks. These include popular names like NordVPN, Private Internet Access, and Windscribe. Proton VPN is one of the few that owns part of its network outright and rents the rest.
To ensure their rented servers are safe for users, these high-quality services are careful about who they rent from, picking data centers that respect user privacy and have no ties to authoritarian governments.

Some VPNs, like Mullvad, clarify whether they own or rent specific VPN servers.
The best VPNs go further and rigorously vet every data center they rent from. That process should include a full hardware audit and an inspection of the data center’s networking environment, so the provider fully understands what threats surround the machine.
I’d like to see every VPN with rented servers be far more open about how it vets its data centers. As things stand, you’re mostly being asked to take it on trust.