HMA (HideMyAss!)
Founded 2005 by Jack Cator. In 2011 complied with a UK court order and handed connection logs to the FBI (LulzSec/Cody Kretsinger case). Introduced a no-logs policy in May 2020, independently audited by VerSprite (2020). Now owned by Gen Digital; no current raw server count published.
About HMA (HideMyAss!)
HMA (HideMyAss!) is a consumer VPN founded in 2005 by Jack Cator and now owned by Gen Digital, the security conglomerate behind several well-known privacy and antivirus brands. In our documented-evidence database it carries a Scout Score of 72, with a privacy sub-score of 74, placing it as a competent mainstream option rather than a privacy purist's first pick.
Jurisdiction is the headline reality here. HMA is based in the United Kingdom (GB), which we classify as TIER_4 — a Five Eyes member with a track record of intelligence-sharing and legal data-compulsion powers. That history is not theoretical for this provider. In 2011, HMA complied with a UK court order and handed connection logs to the FBI in the LulzSec case involving Cody Kretsinger. That is a matter of public record, and it is the single most important fact to weigh when reading everything else on this page.
What changed since then is documented too. HMA introduced a no-logs policy in May 2020, and that policy was independently audited by VerSprite in 2020. The service also ships a kill switch and offers a 30-day money-back window. So the modern posture is a no-logs claim backed by a third-party audit — a meaningful upgrade from the 2011 situation — but the audit is now several years old, and no current raw server count is published, which we mark as unverified.
On pricing, we have no plans verified in our data yet. We will not quote figures we cannot source, so treat cost as unverified until we confirm official numbers.
One honesty note: we do not run a lab, so this profile contains no speed benchmarks or throughput claims from us. Our Scout Score reflects documented evidence — policies, audits and public records — under our published methodology, not stopwatch testing.
Who it fits: users who want a long-established, audited mainstream VPN for streaming and everyday privacy, and who are comfortable with a Five Eyes provider. Who should skip it: anyone whose threat model includes state-level legal compulsion, journalists, activists, or privacy maximalists — for them, the UK jurisdiction and the 2011 log-handover history are disqualifying regardless of the newer policy.
Profile by Tomas, Scout VPN Team — built from documented evidence.
Pros
- No-logs policy (audited)
- Kill switch included
Cons
- Limited to 5 simultaneous devices
- No port forwarding
- No phone support