VPN kill switch, split tunnel and protocols

Why kill switch, split tunnel and protocol lists vary by OS and app version on stored VPN records. A documented yes is not a leak test. Unknown cannot satisfy. Not a ranking.

What this isA source-based reading of stored platforms rows already on this site. Official Australian guidance is used for Australian claims. It is not a ranked winner list, not a numeric security score, and not a claim that a kill switch, split tunnel or protocol makes you untraceable, legally compliant or universally protected. Live app tests remain not tested.

The same product is not the same on every OS

A VPN app is a per-OS binary. Kill switch, split tunnel and the in-app protocol picker are stored per platform. Formula: OS-specific no is not a product-wide no. A protocol listed on Windows is not listed on Linux unless that Linux row says so.

ASD’s Australian Cyber Security Centre tells people connecting to public Wi-Fi to consider a VPN and to read the provider’s privacy policy because the operator can see a large amount of user data. That advice does not name a kill-switch matrix. ACSC, Connecting to public Wi-Fi and hotspots (last updated 11 Apr 2023; fetched 12 Sep 2026).

A documented yes is not a leak test

Stored kill_switch: yes means the vendor documents a kill switch on that OS. It is not a measurement that DNS, IPv6, WebRTC or an OS service stayed inside the tunnel. Apps were not installed. Tunnels were not opened. Leak tests on this dataset: 0.

IVPN removed the iOS kill switch for iOS 16+ after documenting that Apple-service traffic can leave the tunnel even with includeAllNetworks enabled. That is a vendor blog dated 1 Aug 2023, not a test run here. IVPN, Removal of kill switch from the iOS app. IVPN review. Hand check 4+1=5: four core apps document yes; iOS is no.

Private Internet Access’s current iOS help lists WireGuard and OpenVPN and says Leak Protection is unavailable with those protocols. That is a vendor caveat on the stored iOS row, not a leak result from this site. Private Internet Access review.

Kill switch by OS

Missing platforms is unknown, not unsupported. Missing a platform key is unknown for that OS, not a product-wide no. plan_dependent is not a universal yes. Unknown cannot satisfy a hard requirement.

PureVPN’s features copy names kill switch on Windows, Mac and Linux. The iOS and Android general-settings articles do not document one, so those cells stay unknown. TunnelBear and PrivadoVPN have no dedicated Linux GUI; stored Linux kill switch is no. Eight personal products document yes on all five core apps; that is still not a leak test.

Business remote-access products are a different class. NordLayer documents a kill switch; split tunnelling is gateway-level on Core+, stored as plan_dependent. Tailscale AlwaysOn is plan_dependent (MDM); Linux kill switch is no. Twingate has no kill-switch page; transport is TLS 1.2, stored as other. A business overlay is not a consumer public-internet kill switch. Business remote access.

Split tunnel by OS

Personal iOS split on this dataset: four documented yes, seven documented no, one unknown (NordVPN). Hand check 4+7=11 ≠ 12. Unknown is not no. Personal Linux split is 7+5=12.

PureVPN documents split tunnel on Windows and Android only: 2+3=5. hide.me documents it on Windows, macOS and Android, not iOS or the Linux CLI: that is a 3-versus-2 split across five core apps. Surfshark Bypasser is not documented on Linux. Proton’s split-tunneling how-to does not list iOS.

Protocol lists by OS

NIST SP 800-77 Rev. 1 describes IPsec as network-layer encryption of packets. That is confidentiality on a path, not anonymity, and not a reason to treat one in-app protocol as equivalent on every OS. NIST SP 800-77 Rev. 1 (June 2020; fetched 12 Sep 2026).

ExpressVPN’s servers table documents WireGuard on Windows, iOS and Android, not macOS or Linux. Lightway is on all five. Hand check 3+2=5 for the stored WireGuard id. ExpressVPN review.

Proton’s protocol article lists OpenVPN on the Linux GUI only and IKEv2 on macOS only (being withdrawn). Hand check 1+4=5 for OpenVPN. Proton VPN review. Mullvad removed OpenVPN from the desktop app in 2025.14; stored OpenVPN yes-count on the five core apps is 0. Surfshark’s protocol article lists WireGuard for Windows/iOS/Android/macOS and OpenVPN on Linux. An empty protocol list stays unknown, not unsupported. NordLynx and Lightway stay named as stored; they are not relabelled as WireGuard.

ACSC’s October 2021 Using Virtual Private Networks publication is about organisational site-to-site and remote-access VPNs. It is not a consumer kill-switch or protocol shopping list. ACSC Using VPNs (October 2021 PDF). Essential Eight still expects organisations to patch, MFA and log. Essential Eight explained.

Worked example: classify stored rows

Independent count over records already on this site. Hand checks: 4+1=5 IVPN kill switch, 3+2=5 ExpressVPN WireGuard, 1+4=5 Proton OpenVPN, 2+3=5 PureVPN split, 4+7=11 ≠ 12 personal iOS split. Same class on two products is not a ranking. Counts are integers, not billed totals.

Café iPhone + Windows filter: personal VPN, documented iOS, documented Windows, kill switch yes on both, split tunnel yes on both. Unknown cannot satisfy. plan_dependent is not a universal yes. A documented yes is not a leak test. Result on this dataset: 4 pass. Leak tests: 0.

Café iPhone + Windows filter from stored platform rows. A documented yes is not a leak test. Not a ranking.
ProductiOS kill switchWindows kill switchiOS splitWindows splitCafé filterLeak tested
NordVPNYesYesUnknownYesUnknownNo
SurfsharkYesYesYesYesPassNo
ExpressVPNYesYesYesYesPassNo
Proton VPNYesYesNoYesFailNo
Mullvad VPNYesYesNoYesFailNo
IVPNNoYesNoYesFailNo
Private Internet AccessYesYesNoYesFailNo
WindscribeYesYesNoYesFailNo
TunnelBearYesYesYesYesPassNo
hide.me VPNYesYesNoYesFailNo
PrivadoVPNYesYesYesYesPassNo
PureVPNUnknownYesNoYesFailNo

OS variation counts

Stored yes versus no on five core apps. Same class is not a ranking. Counts are integers, not billed totals.
ProductKill switch yes/noSplit yes/noWireGuard yes/noOpenVPN yes/noVaries by OS
IVPN4+13+25+05+0Yes
ExpressVPN5+05+03+25+0Yes
Proton VPN5+04+15+01+4Yes
PureVPN3+02+35+05+0Yes
hide.me VPN5+03+25+05+0Yes
Surfshark5+04+14+15+0Yes
Mullvad VPN5+04+15+00+5Yes

Machine-readable formula and counts: classify.json. Method: How we test.

Decision checklist

  • Read the OS you actually use. IVPN’s iOS kill switch is not the Windows one.
  • Treat a documented yes as documentation. A documented yes is not a leak test.
  • If the iOS split cell is unknown, it cannot satisfy a hard split-tunnel requirement. NordVPN is in that class here.
  • Check the protocol picker on that OS. ExpressVPN WireGuard is not on macOS or Linux in the stored servers table. Proton OpenVPN is Linux GUI only.
  • For company apps, a consumer VPN kill switch is the wrong product. Business remote access.
LimitsNo live tunnels, leak tests or speed tests were run. Apps were not installed. Checkout was not started. Vendor-documented caveats (IVPN iOS 16+, PIA iOS Leak Protection, Proton Apple DNS, Mullvad early-boot) are quoted as documentation, not as results from this site. This guide is not legal advice and not a compliance certificate.

Sources

Shortlist

0 of 3 products

Add products from a review, category table or finder results. Maximum 3.

Add two or three products in the same category to compare.