# URnetwork vs TunnelBear

TunnelBear is the simplest consumer VPN and the first to publish an outside
security audit; URnetwork splits the path so the exit never learns who you
are and the operator cannot read the sealed session.

**Choose TunnelBear** if you want the easiest possible VPN, the longest
unbroken run of annual outside audits in the category, and steady
datacenter speeds. **Choose URnetwork** if you want a split path, an
email-free account, and residential exits aimed at a city. Both have free
tiers. TunnelBear is the friendlier product. URnetwork splits visibility
between its operator and a member-run provider.

[TunnelBear](https://www.tunnelbear.com) is a Toronto-built VPN, owned by
McAfee since 2018, that wraps a WireGuard/OpenVPN/IKEv2 service in bears
and plain language. In 2016 it became the first consumer VPN to publish a
third-party security audit, and Cure53 has audited it every year since
2017, nine years running by its own count. A free tier gives 2 GB each
month, and GhostBear obfuscation helps on networks that block VPNs.

URnetwork uses member-run exits. The provider does not receive your source IP
on the relayed path. Native apps seal traffic to the provider by default.
[How URnetwork works](/docs/overview) explains the full design. The
[threat model](/docs/threat-model) holds the complete record of what is stored
and enforced.

## Six differences that affect the choice

| | TunnelBear | URnetwork |
|---|---|---|
| Trust model | One company's server sees your IP and your destinations together; a policy not to record them | Two relay parties; the exit never sees your IP, and the operator cannot read the sealed session |
| Outside testing | Cure53 audits every year since 2017; full public reports for 2020–2023, none since | Open client and server code; no independent audit of the protocol or server code |
| Simplicity | Pick a country, switch on; almost nothing to configure | A connect button by default; city search, sharing, and wallet options when you want them |
| Consistency | Datacenter servers; steady speeds | Member uplinks; URnetwork puts its average streaming speed at 40 Mbps+ |
| Account and payment | Email required; credit card or the iOS App Store only | One-tap account with no email; wallet sign-in; on-chain USDC |
| Exit and targeting | Datacenter ranges; 47 countries advertised; city choice in the US and Canada only | Residential addresses; browse countries, search for a city |

Caveats below the table:

- Free tiers: TunnelBear's is 2 GB a month, and since 26 January 2026 free
  users no longer choose their country; the change was pre-announced with
  cost reasons given. URnetwork's free allowance resets daily and keeps
  location choice. Paid: TunnelBear Unlimited from $3.33/month as of
  mid-2026; URnetwork Pro $5/month or $40/year, current numbers at
  [ur.io/products](https://ur.io/products).
- Post-quantum encryption runs URnetwork's way: the X25519MLKEM768
  client-to-provider session is default in the native apps, skipping any
  provider it cannot seal to rather than downgrading. The browser extension
  has no sealed session; there, the operator's data path logs nothing, pinned
  by a test in the open code. TunnelBear makes no post-quantum claim.
- Both address blocked networks: TunnelBear with GhostBear obfuscation,
  URnetwork with extenders, entry hops on independent addresses and
  believable ports.
- TunnelBear publishes no physical-versus-virtual breakdown of its 47
  countries, and no outside study has measured it. The claim is modest by
  category standards; the gap is the missing disclosure, not inflation.
- Both ship a kill switch (TunnelBear's is named VigilantBear); URnetwork's
  is an explicit toggle on every platform, and its browser extension pairs
  with the ur.io web app.

## The audit record, exactly

TunnelBear's distinction is real: it started the consumer VPN audit habit,
and Cure53 has tested it annually since 2017, the longest such run in the
category. The record needs dating, though. Full public reports exist for
the 2020 through 2023 audits on cure53.de. The 2024 audit was announced in
November 2025 as a blog summary with no report attached, describing ten
findings of medium severity or higher, all said to be addressed; there is
no document to check. The 2025 audit has no publication at all, and
TunnelBear's own audits page still led with the 2023 report as of
mid-2026. The audits appear to continue; the publishing has stopped.

The last readable report (October–November 2023) cuts both ways: 13
findings, two rated High and none Critical, with Cure53 crediting "a
marked security improvement with each passing round of testing" while
flagging that "some flaws located in prior audits have either been
incorrectly resolved or simply ignored." Scope matters as much as cadence.
These are penetration tests and source-code audits of apps and
infrastructure, not an inspection of what TunnelBear's servers record; no
no-logs attestation exists for TunnelBear. And one marketing line should
be discarded: the homepage still claims to be "the only VPN in the
industry to perform annual, independent security audits", which is false;
Nord, ExpressVPN, Surfshark, IVPN, Mullvad, and Windscribe all publish
independent audits.

![How you verify a privacy claim — point-in-time audits vs court and raid evidence vs open continuous verification](/docs-assets/infographic-verification.svg)

*An audit is a paid, scoped snapshot; open code is checkable on any day.
They prove different things, and neither substitutes for the other.*

URnetwork sits in the other column: no independent audit covers its
protocol or the operator's server code (two 2025 assessments cover other
surfaces; see Limits), and its client and server code are open, so the
storage and routing claims can be verified continuously rather than
annually.

## One company, one policy

TunnelBear's server terminates your tunnel, so one company can see your
account, your real IP, and every destination you connect to at the same
moment. What restrains that view is policy, and TunnelBear's is among the
better-drafted in the category: it names what it does not collect
(connection IPs, DNS queries, any record of the sites and apps you use)
rather than hiding behind "no logs." The same policy lists what it does
keep: an email-identified account, paid status, app and OS versions,
monthly usage totals, geolocation at continent, country, and city level,
crash and device data, and a card's last four digits, with an analytics
processor among its providers and 30-day deletion after cancellation.

Ownership frames the jurisdiction. McAfee has owned TunnelBear since 2018,
which places it under US law, and McAfee appears nowhere on TunnelBear's
homepage or in its privacy policy; the 2023 audit engagement was
commissioned by McAfee ULC. Nothing suggests the acquisition changed what
TunnelBear collects; the fair criticism is the quiet disclosure. The
operational record is clean: no breach, leak, server seizure, or court
case on record. The one notable vulnerability, CVE-2018-10381 (2018), was
a local privilege-escalation flaw in the Windows maintenance service,
patched. Its 9.8 rating scores the exposed named pipe rather than a remote
attack: exploiting it required code already running on the machine.

![Who can see what — single-party VPN vs Apple Private Relay's closed two-party split vs URnetwork's split knowledge](/docs-assets/infographic-who-sees-what.svg)

*One company at the end of the tunnel is the left column; the split path
is the right one.*

On URnetwork's relayed path the two halves never meet: the provider that
carries your traffic does not receive your source IP, and the operator
relays a sealed session it cannot read, so no single party holds both
your identity and your activity. What the operator stores is constrained
in open server code, with the complete record in the
[threat model](/docs/threat-model).

## Where TunnelBear wins

- The easiest VPN there is for someone who will never open a settings
  screen.
- Nine years of annual outside testing, with four full reports (2020–2023)
  anyone can read; no young network can match that history.
- A privacy policy that names what it does not collect instead of
  gesturing at "no logs."
- Steady datacenter speeds.
- Corporate stability and consumer-grade support.

## Where URnetwork wins

- The split. The exit never learns who you are, and the operator cannot
  read the sealed session. No single party holds identity and destinations
  together; TunnelBear's server sees both.
- Verification that does not expire: open client and server code, versus a
  closed stack and reports that have stopped appearing.
- Account anonymity: a one-tap email-free account backed by a recovery
  seed phrase (URnetwork's own credential; it never asks for a crypto
  wallet's seed phrase or key), wallet-signature sign-in, and on-chain
  USDC payment. TunnelBear requires an email and a card.
- Residential exits with city search anywhere providers are online;
  TunnelBear offers cities in two countries.
- A free tier that keeps location choice and resets daily.
- A supply side: members can share their connection as participants in the
  [UR protocol](https://ur.xyz), with an open-source filter dropping
  file-sharing and attack traffic before it leaves a member's line.

## Limits and evidence

URnetwork's main limits:

- No independent audit covers the protocol, the connect engine, or the
  operator's server code. Two 2025 third-party assessments cover other
  surfaces: a penetration test of the web application and API (April–May
  2025), and the Leviathan MASA AL2 assessment of the Android app, which
  passed. Leviathan writes that its assessment "should not be read as a
  holistic security evaluation or comprehensive penetration test." Neither
  examined logging, retention, or the data path.
- The split assumes the operator and the providers in your window are
  independent. Nothing in the system attests that independence, and no
  outside party has measured the fleet. See the
  [threat model](/docs/threat-model), §6.1.
- The WireGuard-compatible fallback endpoint assigns one stable tunnel
  address, so several providers could recognize the same client across
  sessions. The native tunnel is the recommended path.
- Coverage counts are self-published on both sides, with no outside
  measurement of either fleet; URnetwork's mechanism, a location existing
  only while a member's device is online in it, is the checkable part.

TunnelBear's limit is the position every one-company VPN shares: its
server terminates the tunnel where it can see your address and your
destinations together, and its audits test the software around that
position rather than attesting what is recorded in it. Since 2023 there is
a second limit: the newest results exist only as vendor summaries, so the
published record a buyer can read stops at the 2023 report.

Trying URnetwork costs nothing: the Instant Account takes one tap and no
email, and both free tiers let you test against your own sites before
paying for either. More questions are answered in the [FAQ](/docs/faq).
