An independent VPN research lab
Ghost On Web exists because most VPN "reviews" are rewritten press releases with an affiliate link attached. We built a benchmarking rig instead, and we publish the server, the hour and the baseline behind every number on this site.
The reviews were all the same
In 2017 three of us were comparing VPNs for a client project and noticed something odd: across a dozen review sites, the rankings were nearly identical and the speed figures were nearly identical, but none of the sites said where or when they had measured anything. Several quoted numbers that were physically impossible on a domestic line.
So we bought a rack, a fibre line and eleven subscriptions, and started measuring properly. The first report went out to about forty people. Nine years later the methodology is roughly the same, just automated — and it still turns up results that disagree with the consensus, which is the whole point of doing the work.
We are a four-person company. Nobody here has an equity stake in a VPN provider, and we have turned down every acquisition approach from the VPN industry — there have been three, most recently in 2024.
The rig
We never measure desktop speeds over Wi-Fi. Wi-Fi variance is larger than most of the differences we are trying to detect.
How a review gets made
The order matters as much as the tests. Scoring is locked before anyone looks at commercial terms, which is the only structural defence against the obvious conflict of interest in this business.
We buy the subscription
Always at full retail price, always on a fresh account with no press contact attached. Providers do not know they are being tested until we contact them for spec verification at the end.
Baseline the line
An unprotected control run establishes the reference figure — 942 Mbps this cycle. We re-measure it before and after each provider block and discard any results where the line itself drifted more than 2%.
Six test suites, ~45 lab hours
Speed across three distance bands plus mobile, DNS/IPv6/WebRTC leak checks on three operating systems, 40 forced kill-switch drops, 36 streaming server tests, sustained P2P load, and four censorship scenarios.
Independent reproduction
A second tester re-runs the speed suite on a separate line and separate hardware. If the two sets disagree by more than 5% on any band, both are thrown out and the whole thing runs again.
Score before commerce
Category scores are calculated from the test spreadsheet by formula. Nobody on the team looks at commission rates or partnership status until after the scores are locked in version control.
Factual-accuracy window
Providers get 72 hours to correct hard specifications — server counts, protocol support, pricing. They do not see the scores, the verdict or the ranking before publication.
Score weighting
The overall score is a weighted average of five measured categories. Support is recorded and published but does not carry weight in the total.
Our funding, plainly
We take affiliate commissions and nothing else. No display advertising, no sponsored posts, no paid reviews, no "featured provider" slots. Providers cannot buy a position, cannot preview a verdict and cannot remove a finding.
For what it is worth: the two highest-paying affiliate programmes in our current top ten sit at rank 7 and rank 9. Our number one pick pays a below-average rate.
Who runs the lab
Marcus Reeve
Built the benchmarking rig and wrote the automation that runs it. Fourteen years in network engineering before this, most of it at a tier-2 transit provider. Owns the speed and P2P suites.
Priya Raghunathan
Runs the leak testing, kill-switch drops and censorship simulations, and reads every audit report end to end. Previously an application security consultant; CREST-certified.
Dani Okafor
Owns the streaming matrix and the support-desk tests, and edits every review before it ships. Ten years in consumer tech journalism, including four covering privacy tooling.
Tomas Lindqvist
Maintains the test machines, the mobile device fleet and the second verification line. Every speed figure we publish has been reproduced on his hardware before it goes live.
We publish failures
When a provider fails a test, the finding goes in the review with the date we notified them — even if they are paying us a commission. Providers cannot preview a verdict, and no finding has ever been removed at a provider's request.
Raw data on request
Per-server CSV exports for every cycle go out to anyone who emails and asks. Readers have re-run our numbers and sent corrections — three of which changed a published score.
Every figure is dated
Streaming results decay fastest, so they carry their own monthly re-test date. Nothing on this site is presented as permanently true, because none of it is.
Found something we got wrong?
Corrections are the most useful mail we get. Send us the discrepancy and how you measured it, and if you are right we will re-test and update the review with a note.