Opera’s built-in VPN encrypts a claimed 1.2 petabytes of user traffic each year. That is substantial usage by any measure, but it signals uptake rather than trust. The gap between those two measures is where the conversation about Opera’s security strategy begins.
Opera ships more security features than any other mainstream browser. Paste Protect, built-in VPN, Manifest V2 extension support, native ad blocking: the cadence is real, and we have covered it across this series. But Opera holds 1.78% of the global browser market while Chrome commands 68.02% and Edge grows through Windows bundling. Firefox, the browser with the strongest privacy positioning in the market, fell from 5.88% to 3.79% on desktop in twelve months. If privacy features could not save Firefox, can security features grow Opera? And if not, what is the feature strategy actually for?
What Are the Security Trade-Offs Between Opera’s Built-In VPN and a Standalone Enterprise VPN?
Opera’s built-in VPN encrypts only browser traffic. It is a browser-level TLS proxy, not a full-device VPN. System processes, non-browser DNS queries, and other applications travel over your network as though the VPN does not exist.
Opera’s VPN uses AES-256 encryption inside an HTTPS/TLS tunnel, which is adequate for protecting browser traffic against local network eavesdropping. But the service is fundamentally different from a real VPN tunnel using WireGuard or OpenVPN, and that difference produces four trade-offs that matter once you move past coffee-shop Wi-Fi into an organisational context.
The coverage gap is structural. A standalone enterprise VPN, or a zero trust network access deployment, encrypts all device traffic and routes it through infrastructure your organisation controls or has contracted. Opera’s VPN covers browser traffic only, cannot be forced on via Group Policy or MDM, and offers no centralised logging or auditing. It is consumer-grade by design, and the enterprise VPN market, projected at $4.2 billion in 2025, exists because consumer-grade does not meet compliance requirements.
The trust model is different too. When your organisation deploys a VPN, the infrastructure belongs to you or to a provider you have contracted and can audit contractually. Opera’s VPN routes traffic through Opera’s infrastructure. You are taking Opera’s word that it does not log your traffic, and that its servers are hardened, and that the browser container collecting your device ID, IP address, and location data is walled off from the VPN tunnel. The Deloitte no-log audit verified the VPN infrastructure does not log originating IPs, browsing history, or DNS requests, but it did not examine the browser’s broader data collection.
The threat model is narrower than you might expect. Opera’s VPN protects against local network snooping and ISP monitoring. It does not protect against endpoint compromise, malicious browser extensions, or targeted surveillance. And while the VPN can shift your apparent geolocation to one of a few broad regions (Europe, Americas, Asia), it does not allow specific server selection in the free tier and has no kill switch to prevent data leaking if the tunnel drops.
For the individual user on public Wi-Fi, Opera’s VPN is useful. For an organisation in a regulated industry, it is supplementary at best. The enterprise manageability piece is absent: no forced-on compliance mode, no policy configuration, no way to route traffic through your own infrastructure. Opera VPN Pro, the paid tier launched in 2023, adds system-level protection and runs on NordVPN’s infrastructure, but that introduces a different dependency rather than solving the trust question.
Why Hasn’t Opera Published Third-Party Security Audits for Its VPN, and Does It Matter?
The trust-model question leads directly to the audit question. Opera has published three third-party engagements: a Deloitte no-log audit in August 2024, a Cure53 security review, and a Leviathan Security Group audit of Opera for Android including the free VPN in January 2025. That is more than most browser vendors have done for their bundled features.
But none of these constitutes a full-stack infrastructure security review. A comprehensive audit would verify server hardening, access controls, VPN client code for vulnerabilities, and the separation between VPN infrastructure and the browser’s data-collection pipelines. The Deloitte audit verified that Opera’s VPN servers do not log originating IP addresses, browsing history, DNS requests, or geolocation. It did not verify that the Opera browser itself does not collect that data through its own instrumentation, and audits only verify what was true at the time of testing. They do not change the fundamental limitations of a proxy-based service.
The comparison with Mullvad is instructive. Mullvad publishes comprehensive Cure53 and Assured AB audits covering infrastructure, applications, and no-logging claims. Brave Firewall+VPN benefits from Guardian’s published audit infrastructure. Opera’s VPN has no comparable published validation, and Opera has not explained why. It is possible that browser VPNs have not adopted the audit norms that consumer VPN providers established over the past five years. It is also possible that an audit revealing infrastructure gaps would create more problems than it solves.
For procurement, the absence matters in proportion to regulatory exposure. Average GDPR fines reach $4.6 million and healthcare data breach costs average $10.93 million. If you are evaluating browsers for a fintech or healthtech environment, the VPN feature cannot be treated as a documented security control without infrastructure-level validation. It remains viable as a consumer convenience, and that distinction is one your procurement process needs to register.
There is a paradox: the VPN tunnel is verified clean, but the browser container around it is not. Opera’s privacy policy discloses collection of device identifiers, IP addresses, location data, and sharing with Facebook for advertising. Opera is headquartered in Norway and majority-owned by Chinese company Kunlun Tech. The VPN infrastructure operates under Norwegian and EU data protection law, but comprehensive audits are how you resolve the residual trust questions those facts generate. Right now, that resolution is not available.
Why Did Firefox’s Market Share Collapse, and What Does That Mean for Security-Driven Browser Adoption?
If you want to know whether features can overcome structural forces, Firefox is the empirical test. Firefox fell from 5.88% to 3.79% on desktop between May 2025 and May 2026, and sits at 2.26% across all platforms with roughly 138 million users. It was at 31.82% in November 2009. The decline is not new, but the acceleration is, and it happened despite Firefox shipping Enhanced Tracking Protection, Total Cookie Protection, DNS-over-HTTPS by default, and support for both Manifest V2 and V3 extensions.
The structural factors are well documented. Mozilla has cycled through layoffs, leadership changes, and diversification attempts that pulled resources from the browser. Firefox uses the Gecko engine, the only major rendering engine not based on Chromium, which creates compatibility friction that Chromium-based alternatives like Edge and Opera avoid. And on mobile, where most browsing now happens, Safari owns iOS and Chrome owns Android. Firefox has no automatic distribution channel.
Firefox scored weakly on privacy tests relative to specialised browsers like Brave and Mullvad Browser, but its defaults were still stronger than Chrome’s or Edge’s, and it made privacy a marketing pillar for years. None of it prevented the contraction.
The cautionary lesson for Opera is direct: features do not drive adoption at scale. Distribution does. Opera differs from Firefox in ways that partly insulate it. It runs on Chromium, so compatibility is not a friction point. Its revenue model combines search deals with consumer subscription services, reducing the single-point dependency that made Mozilla vulnerable to Google’s search-contract decisions. And its share has been stable rather than declining, which suggests the security-feature cadence may be achieving retention: existing users have fewer reasons to leave.
Retention is commercially meaningful. It protects search revenue and creates a base for subscription upsell. But it does not change market structure, and the Firefox data makes clear that even the strongest feature set cannot deliver what distribution withholds.
What Is the Browser Choice Alliance and Why Has It Targeted Microsoft Edge?
The Browser Choice Alliance is a coalition of browser vendors that filed an open letter to Microsoft CEO Satya Nadella on 3 June 2026, alleging Microsoft uses its Windows platform dominance to preference Edge through tactics that restrict and distort user choice. Its members include Opera, Vivaldi, and Google Chrome. Mozilla is explicitly not a member, though the Alliance has cited Mozilla’s independent research as corroboration.
The complaint lists seven specific practices: coercive rebates that foreclose rival preinstallation, preventing Edge uninstallation, intrusive messages when users download competing browsers, update-driven default resets, ignoring user defaults for links in Teams and Outlook, hardwiring Edge to Windows Search and Widgets, and blocking one-click default switching. A Mozilla study tested Windows 10 and 11 across four regions and found these obstacles exist everywhere except the European Economic Area, where the Digital Markets Act has forced Microsoft to remove them.
The presence of Chrome in the Alliance is the detail that makes the structural argument hard to dismiss. Chrome commands 68.02% market share. It does not need regulatory help to compete with Edge on features. But Edge’s integration with Microsoft 365, Copilot, and Intune creates a structural advantage that Chrome cannot match through browser engineering alone. If the market leader believes OS-level bundling is anticompetitive, feature-based competition is not the level playing field anyone pretends it is.
For Opera, the Alliance’s existence is an acknowledgement that security features have not been able to overcome platform defaults. The Digital Markets Act provides experimental evidence: EU browser-choice screens shifted roughly 6 million users toward Firefox in the EEA. Structural intervention moved the needle. Feature marketing did not.
The Firefox collapse and the Browser Choice Alliance complaint are two expressions of the same dynamic. One shows what happens when features compete against defaults without distribution leverage. The other shows the industry organising around the recognition that this is not a fair fight. Opera’s stable share, viewed through this lens, looks less like stagnation and more like a retention strategy working as designed. The VPN audit gap remains an addressable trust problem. Comprehensive infrastructure audits would not shift market share, but they would resolve the procurement disqualification for regulated industries and reinforce trust among the users Opera already has. Security features cannot drive browser adoption at scale without distribution leverage. But they can sustain a viable niche, provided the trust infrastructure around them holds up.
Frequently Asked Questions
Is Opera’s VPN actually free, and how does Opera make money from it?
Yes, Opera’s built-in VPN is genuinely free with no bandwidth caps or payment required. Opera generates revenue primarily through search engine partnerships: the browser’s default search agreements with Google and other search providers account for the majority of Opera’s income. The VPN functions as a retention feature that keeps users within the Opera ecosystem, where their search activity generates advertising revenue. Opera VPN Pro, a paid tier introduced in 2023, offers additional server locations and device-wide protection, but the core built-in VPN remains fully free and monetised indirectly.
Does Opera’s built-in VPN slow down my browsing speed?
Some speed reduction is inherent to any VPN. Traffic must travel through Opera’s proxy servers in Sweden or the Netherlands before reaching its destination, adding latency proportional to your physical distance from those servers. For typical browsing in Australia, users report acceptable performance for web pages and streaming, but the proxy architecture means latency-sensitive applications like competitive gaming or real-time video conferencing may notice the overhead. The free tier routes through shared infrastructure with no guaranteed bandwidth allocation, so speeds can vary with server load. Opera VPN Pro offers dedicated servers with higher throughput.
Can I use Opera’s VPN to access geo-blocked streaming services?
Opera’s free VPN can occasionally bypass geo-restrictions on streaming platforms by routing traffic through its European proxy servers, but it is not designed or optimised for this purpose. Major streaming services including Netflix and BBC iPlayer actively detect and block known VPN exit nodes, and Opera’s proxy IP ranges are well catalogued. Unlike dedicated streaming VPNs that rotate IP addresses to evade detection, Opera’s VPN uses fixed server locations. For consistent access to geo-blocked content, a dedicated paid VPN with streaming-optimised servers remains the more reliable choice.
Is Opera’s VPN safe to use for online banking?
Opera’s VPN encrypts browser traffic between your device and Opera’s proxy servers, which provides meaningful protection against local network eavesdropping when banking on public Wi-Fi. However, the absence of published infrastructure security audits means you cannot independently verify how Opera handles traffic at its servers. For banking, your connection is already encrypted via HTTPS regardless of whether a VPN is active, so the additional benefit is marginal. In regulated financial contexts, most organisations prefer standalone VPNs with audited infrastructure rather than browser-level proxy solutions.
How does Opera’s VPN differ from Apple’s Private Relay?
Both are browser-level privacy services, not full-device VPNs, but their architectures differ fundamentally. Apple Private Relay uses a dual-hop design: your traffic is encrypted through Apple’s servers, then routed through a third-party relay, so no single party sees both your IP address and your destination. Opera’s VPN uses a single-hop proxy model where Opera’s servers see both. Private Relay also supports per-site granularity in Safari, while Opera’s VPN is a binary on-off toggle. The key distinction is Apple’s separation-of-knowledge architecture versus Opera’s single-party trust model.
What personal data does the Opera browser collect alongside its VPN?
Opera’s privacy policy discloses collection of device identifiers, IP address data, location information, and browsing behaviour for product improvement and personalisation. The browser also shares data with Facebook for advertising purposes under its data controller framework. This creates the paradox the article identifies: the VPN tunnel encrypts traffic leaving your browser, but the browser container itself collects data through its own instrumentation. Opera’s Deloitte audit verified no-logging on the VPN infrastructure specifically, not on the browser’s broader data collection practices. Users seeking comprehensive privacy should review Opera’s full privacy policy, not rely on the VPN alone.
What is the difference between Opera’s free VPN and Opera VPN Pro?
Opera’s free built-in VPN is a browser-level proxy encrypting only Opera traffic and routing it through shared servers in Sweden and the Netherlands with no bandwidth limits. Opera VPN Pro, launched in 2023, extends protection to the entire device using a system-level VPN profile, adds server locations across 30-plus countries, and provides dedicated bandwidth on Pro servers. The Pro tier is a subscription product designed to compete with standalone VPN services, while the free tier remains a browser convenience feature. Neither tier has published comprehensive third-party infrastructure audits comparable to those from Mullvad or IVPN.
If security features do not drive browser adoption, why does Opera keep building them?
Opera’s security feature cadence serves retention, not mass-market conversion. Each new feature (Paste Protect, built-in VPN, Manifest V2 extension support, native ad blocking) gives existing Opera users one less reason to switch to a competitor. In a browser market where platform defaults dominate, reducing churn among a stable 1.78 percent user base protects the search revenue those users generate. The strategy is commercially rational even if it never moves the market-share needle: keeping a smaller but loyal user base engaged is more cost-effective than trying to outspend Google and Microsoft on distribution.
Is Opera Browser owned by a Chinese company, and does that affect VPN trust?
Opera Software AS is headquartered in Oslo, Norway, and is publicly listed on NASDAQ. A consortium of Chinese investors led by Kunlun Tech acquired the original Opera browser business in 2016, and Kunlun remains a majority shareholder. Opera’s consumer browser and VPN operations are managed from Norway under Norwegian and EU data protection law. The ownership structure does raise questions about jurisdictional data risk, particularly for users in government or defence sectors, but Opera maintains that VPN traffic handling occurs entirely within its European infrastructure. Comprehensive third-party audits would help resolve residual trust concerns tied to ownership.
What does the Firefox collapse mean for Opera’s long-term survival?
Firefox’s 63 percent decline is not a predictor of Opera’s fate but a warning about the structural vulnerability all alternative browsers share. Opera differs from Firefox in three ways that blunt the comparison: it runs on Chromium, eliminating the compatibility friction that hurt Firefox’s Gecko engine; its revenue model combines search deals with consumer subscription services, diversifying beyond Mozilla’s near-total search-deal dependency; and its 1.78 percent share has been stable rather than declining. The real lesson for Opera is that retention strategy must be backed by institutional stability and diversified revenue, not that alternative browsers are doomed.