VPN kill switch, split tunnel and protocols
Why kill switch, split tunnel and protocol lists vary by OS and app version on stored VPN records. A documented yes is not a leak test. Unknown cannot satisfy. Not a ranking.
platforms rows already on this site. Official Australian guidance is used for Australian claims. It is not a ranked winner list, not a numeric security score, and not a claim that a kill switch, split tunnel or protocol makes you untraceable, legally compliant or universally protected. Live app tests remain not tested.The same product is not the same on every OS
A VPN app is a per-OS binary. Kill switch, split tunnel and the in-app protocol picker are stored per platform. Formula: OS-specific no is not a product-wide no. A protocol listed on Windows is not listed on Linux unless that Linux row says so.
ASD’s Australian Cyber Security Centre tells people connecting to public Wi-Fi to consider a VPN and to read the provider’s privacy policy because the operator can see a large amount of user data. That advice does not name a kill-switch matrix. ACSC, Connecting to public Wi-Fi and hotspots (last updated 11 Apr 2023; fetched 12 Sep 2026).
A documented yes is not a leak test
Stored kill_switch: yes means the vendor documents a kill switch on that OS. It is not a measurement that DNS, IPv6, WebRTC or an OS service stayed inside the tunnel. Apps were not installed. Tunnels were not opened. Leak tests on this dataset: 0.
IVPN removed the iOS kill switch for iOS 16+ after documenting that Apple-service traffic can leave the tunnel even with includeAllNetworks enabled. That is a vendor blog dated 1 Aug 2023, not a test run here. IVPN, Removal of kill switch from the iOS app. IVPN review. Hand check 4+1=5: four core apps document yes; iOS is no.
Private Internet Access’s current iOS help lists WireGuard and OpenVPN and says Leak Protection is unavailable with those protocols. That is a vendor caveat on the stored iOS row, not a leak result from this site. Private Internet Access review.
Kill switch by OS
Missing platforms is unknown, not unsupported. Missing a platform key is unknown for that OS, not a product-wide no. plan_dependent is not a universal yes. Unknown cannot satisfy a hard requirement.
PureVPN’s features copy names kill switch on Windows, Mac and Linux. The iOS and Android general-settings articles do not document one, so those cells stay unknown. TunnelBear and PrivadoVPN have no dedicated Linux GUI; stored Linux kill switch is no. Eight personal products document yes on all five core apps; that is still not a leak test.
Business remote-access products are a different class. NordLayer documents a kill switch; split tunnelling is gateway-level on Core+, stored as plan_dependent. Tailscale AlwaysOn is plan_dependent (MDM); Linux kill switch is no. Twingate has no kill-switch page; transport is TLS 1.2, stored as other. A business overlay is not a consumer public-internet kill switch. Business remote access.
Split tunnel by OS
Personal iOS split on this dataset: four documented yes, seven documented no, one unknown (NordVPN). Hand check 4+7=11 ≠ 12. Unknown is not no. Personal Linux split is 7+5=12.
PureVPN documents split tunnel on Windows and Android only: 2+3=5. hide.me documents it on Windows, macOS and Android, not iOS or the Linux CLI: that is a 3-versus-2 split across five core apps. Surfshark Bypasser is not documented on Linux. Proton’s split-tunneling how-to does not list iOS.
Protocol lists by OS
NIST SP 800-77 Rev. 1 describes IPsec as network-layer encryption of packets. That is confidentiality on a path, not anonymity, and not a reason to treat one in-app protocol as equivalent on every OS. NIST SP 800-77 Rev. 1 (June 2020; fetched 12 Sep 2026).
ExpressVPN’s servers table documents WireGuard on Windows, iOS and Android, not macOS or Linux. Lightway is on all five. Hand check 3+2=5 for the stored WireGuard id. ExpressVPN review.
Proton’s protocol article lists OpenVPN on the Linux GUI only and IKEv2 on macOS only (being withdrawn). Hand check 1+4=5 for OpenVPN. Proton VPN review. Mullvad removed OpenVPN from the desktop app in 2025.14; stored OpenVPN yes-count on the five core apps is 0. Surfshark’s protocol article lists WireGuard for Windows/iOS/Android/macOS and OpenVPN on Linux. An empty protocol list stays unknown, not unsupported. NordLynx and Lightway stay named as stored; they are not relabelled as WireGuard.
ACSC’s October 2021 Using Virtual Private Networks publication is about organisational site-to-site and remote-access VPNs. It is not a consumer kill-switch or protocol shopping list. ACSC Using VPNs (October 2021 PDF). Essential Eight still expects organisations to patch, MFA and log. Essential Eight explained.
Worked example: classify stored rows
Independent count over records already on this site. Hand checks: 4+1=5 IVPN kill switch, 3+2=5 ExpressVPN WireGuard, 1+4=5 Proton OpenVPN, 2+3=5 PureVPN split, 4+7=11 ≠ 12 personal iOS split. Same class on two products is not a ranking. Counts are integers, not billed totals.
Café iPhone + Windows filter: personal VPN, documented iOS, documented Windows, kill switch yes on both, split tunnel yes on both. Unknown cannot satisfy. plan_dependent is not a universal yes. A documented yes is not a leak test. Result on this dataset: 4 pass. Leak tests: 0.
| Product | iOS kill switch | Windows kill switch | iOS split | Windows split | Café filter | Leak tested |
|---|---|---|---|---|---|---|
| NordVPN | Yes | Yes | Unknown | Yes | Unknown | No |
| Surfshark | Yes | Yes | Yes | Yes | Pass | No |
| ExpressVPN | Yes | Yes | Yes | Yes | Pass | No |
| Proton VPN | Yes | Yes | No | Yes | Fail | No |
| Mullvad VPN | Yes | Yes | No | Yes | Fail | No |
| IVPN | No | Yes | No | Yes | Fail | No |
| Private Internet Access | Yes | Yes | No | Yes | Fail | No |
| Windscribe | Yes | Yes | No | Yes | Fail | No |
| TunnelBear | Yes | Yes | Yes | Yes | Pass | No |
| hide.me VPN | Yes | Yes | No | Yes | Fail | No |
| PrivadoVPN | Yes | Yes | Yes | Yes | Pass | No |
| PureVPN | Unknown | Yes | No | Yes | Fail | No |
OS variation counts
| Product | Kill switch yes/no | Split yes/no | WireGuard yes/no | OpenVPN yes/no | Varies by OS |
|---|---|---|---|---|---|
| IVPN | 4+1 | 3+2 | 5+0 | 5+0 | Yes |
| ExpressVPN | 5+0 | 5+0 | 3+2 | 5+0 | Yes |
| Proton VPN | 5+0 | 4+1 | 5+0 | 1+4 | Yes |
| PureVPN | 3+0 | 2+3 | 5+0 | 5+0 | Yes |
| hide.me VPN | 5+0 | 3+2 | 5+0 | 5+0 | Yes |
| Surfshark | 5+0 | 4+1 | 4+1 | 5+0 | Yes |
| Mullvad VPN | 5+0 | 4+1 | 5+0 | 0+5 | Yes |
Machine-readable formula and counts: classify.json. Method: How we test.
Decision checklist
- Read the OS you actually use. IVPN’s iOS kill switch is not the Windows one.
- Treat a documented yes as documentation. A documented yes is not a leak test.
- If the iOS split cell is unknown, it cannot satisfy a hard split-tunnel requirement. NordVPN is in that class here.
- Check the protocol picker on that OS. ExpressVPN WireGuard is not on macOS or Linux in the stored servers table. Proton OpenVPN is Linux GUI only.
- For company apps, a consumer VPN kill switch is the wrong product. Business remote access.
Sources
- ASD’s ACSC, Connecting to public Wi-Fi and hotspots checked 2026-09-12
- ASD’s ACSC, Using Virtual Private Networks (October 2021) checked 2026-09-12
- ASD’s ACSC, Essential Eight explained checked 2026-09-12
- NIST SP 800-77 Rev. 1, Guide to IPsec VPNs checked 2026-09-12
- IVPN, Removal of kill switch from the iOS app (1 Aug 2023) checked 2026-09-12
- IVPN, kill switch / VPN firewall knowledge base checked 2026-09-12
- ExpressVPN servers table (WireGuard on Windows, iOS, Android) checked 2026-09-12
- ExpressVPN Network Lock (kill switch) checked 2026-09-12
- Proton VPN, which protocols are available on each app checked 2026-09-12
- PureVPN split tunneling (Windows and Android) checked 2026-09-12
- hide.me split tunnel (Windows, macOS, Android) checked 2026-09-12
- Mullvad, removing OpenVPN from the app (2025.14) checked 2026-09-12
- Surfshark, which protocols can I use (Linux omits WireGuard) checked 2026-09-12