Surfshark vs NordVPN: How to Find Out Who Operates a Service
People searching this pair are often circling a question that is not really about which is better: who is actually behind each of these services, and are they as separate as they appear? That is a legitimate question, and a more durable one than any feature comparison.
This page will not answer it with claims. Corporate arrangements change through acquisition, restructuring, and reorganisation, and any page stating them becomes confidently wrong without changing a word. What it will do is show you where the authoritative answer lives, so you can establish it yourself, today, for these two or for any other pair.
Why the question is worth asking at all
Because it decides whether a comparison means anything. If two services share operators, infrastructure, or policies, then comparing them is not the exercise you thought it was, and choosing between them does not diversify anything.
Because it identifies your actual counterparty. Your contract, your payment, and your data are with a legal entity, not with a brand. Brands are marketing artefacts; entities have registered addresses, obligations, and a jurisdiction.
Because concentration is a risk in itself. If several services you might treat as alternatives resolve to the same operator, then a single failure — a breach, a policy change, a legal event, an insolvency — reaches all of them at once. Someone deliberately keeping a fallback should be checking this rather than assuming that different names mean different fates.
Because it makes retention promises legible. A commitment about data handling is made by an entity operating under a legal system. Knowing which one is prerequisite to assessing what the commitment is worth, which is the argument in what a no-logs VPN policy means.
Where the answer lives, in order of authority
Do this yourself. It takes a quarter of an hour and the result is current, which nothing you read about it will be.
- The terms of service and the privacy policy on each provider’s own site. These name the entity you contract with and the entity acting as data controller. This is the most useful single fact available to you, it is authoritative, and it is published because it has to be. Read to the bottom, where the names usually are.
- The legal or company-information page. Many jurisdictions require a published statement of the operating company, its registration number, and its registered address. Where present, this is definitive.
- The public business register for that jurisdiction. With a company name and number from step one, official registers will show the entity’s status, filings, and — depending on the jurisdiction — its officers or holding structure. This is primary-source research and it is usually free.
- The provider’s own statements about ownership and structure. Some publish this directly. Take it as the provider’s current account of itself, which is worth having, and note the date.
- Transparency reports and audit reports. These usually name the entities within scope, which occasionally reveals more about structure than the marketing pages do. Read them for scope and date, as set out in ExpressVPN: not a review.
- Reporting by others. Useful for pointing you at things to verify. Never the final answer, because it ages and because it is frequently copied from other coverage rather than from records.
Work from the top of that list. Anything you cannot trace to steps one to three is a lead rather than a fact.
What the contracting entity actually tells you
Once you have the name, three things follow that a brand comparison cannot give you.
Which legal system applies. Both to your contract and to demands that can be made of the company. There is no jurisdiction beyond legal process, and the categories of regulation that differ between them are covered in why VPN rules differ by country.
What obligations attach. Data-protection regimes, consumer-protection rules, and disclosure requirements vary by jurisdiction, and they apply to the entity rather than to the marketing.
Who you would pursue. If something goes wrong — billing, a breach, a broken promise — the entity in the terms is the party. This is unglamorous and it is the part that matters if you ever need it.
What it does not tell you
Be careful about over-reading. A shared operator does not automatically mean identical practice: separate services can genuinely run separate infrastructure with separate policies. Equally, separate operators do not guarantee independence, since providers can share suppliers, hosting, or transit without any corporate relationship at all.
So the finding is a starting point for questions, not a verdict. And the honest limit is that you can establish structure from public records but not conduct: no register tells you how a company behaves day to day.
Questions to put to both, in writing
Ask before subscribing, and judge the responsiveness as well as the answer.
- Which legal entity will I be contracting with, and where is it established?
- Which entity is the data controller for my account information?
- Is any part of the service operated by another company in the same group, and if so which parts?
- Which suppliers or subprocessors are involved, and where are they?
- What is your process when an authority requests customer information?
- What notification would I receive after a security incident?
A provider that answers these plainly has told you something real. A provider that will not answer them has also told you something.
If you are choosing between two services precisely to have a fallback
Then this research is the whole point of the exercise, and it should come before any comparison of features. Establish the entities first. If they turn out to be related, your fallback is thinner than you thought, and you should be looking at an unrelated operator rather than at a different logo. If they are unrelated, you have a genuine second option — and the differences between them matter far less than the fact that they can fail independently.
Bottom line
Take the entity names from each provider’s own terms and privacy policy, confirm them in the relevant public business register, and treat everything written about ownership elsewhere as a lead that ages. The entity determines your counterparty, the applicable law and the obligations that attach — but it tells you nothing about conduct, and a shared operator is a reason for questions rather than a conclusion. If your reason for comparing two services is to keep a fallback, do this research first, because it is the only part that determines whether you have one.