Skip to content
Field note

The Digital Privacy Toolkit: A Licensed Investigator’s Guide to Cyber Safety

Five moves do most of the work: a VPN from a provider that can prove it keeps no logs (Proton VPN or Mullvad), sensitive correspondence on Proton Mail, a password manager doing the remembering (KeePassXC offline, or Proton Pass), one deliberate pass through your phone’s privacy settings, and automatic updates on everything you own. The rest of this guide is the field manual: what each tool does, what it refuses to do, and when to stop doing it yourself.

Short answer: you do not need twenty tools. You need five habits with the right tool behind each one. Put a VPN you can actually trust on the devices that leave the house: Proton VPN or Mullvad, and nothing else. Move the email that matters to Proton Mail. Let a password manager remember a long, unique password for every account: KeePassXC if you want the vault offline in your own hands, Proton Pass if you want it synced for you. Sit down with your phone’s privacy settings once, deliberately, for twenty minutes. And turn on automatic updates everywhere, then retire hardware that no longer receives them. That is the toolkit. Everything below is the field manual for it: what we recommend to clients, what each tool actually does, and the point at which a privacy problem stops being do-it-yourself and becomes casework.

Why is an investigation firm handing out privacy advice?

This article exists because readers asked for it. After our personal security checklist ran, the follow-up questions were nearly all the same shape: fine, but which VPN? Which email provider? Which password manager, exactly? This is the answer, in one place, with the reasoning shown.

A word on why the recommendations carry any weight. Privacy is operating procedure at this firm, not a side interest: people write to an investigation firm about the worst weeks of their lives, and protecting what they tell us is part of the job. The same open-source research methods we use to locate people and assets show us, every working day, what leaks and from where. When we recommend a tool, it is because it holds up in practice, or because we keep meeting the consequences for people who relied on something that did not.

One more thing: nothing in this article is sponsored. There are no affiliate links and no referral codes, and none of these companies know they are being written about. Every product link below goes to the maker’s own site, marked so that it earns us nothing.

Which VPN should you actually use?

A VPN encrypts the traffic between your device and the provider’s server, then sends it on from there. Two useful things follow. The network you are sitting on (the café Wi-Fi, the hotel, the airport lounge) can no longer read or tamper with what you do. And the sites you visit see the VPN’s address instead of yours. That is the whole trick. A VPN does not make you invisible; it moves your trust from the local network to the VPN company.

So the only question that matters is whether that company deserves the trust. Our bar: a no-logs policy that has survived independent auditing, a business model that does not depend on your data, and modern protocols, which today means WireGuard. Two providers clear that bar comfortably: Proton VPN and Mullvad. They are the two we recommend to clients, and the only two this article will recommend.

Proton VPN comes from Proton, the Swiss company behind Proton Mail, and its free tier is the reason it tops our list for most people: Proton describes it as the only free VPN with no ads, no data limits and a strict no-logs policy. Unusually for the industry, the policy is audited rather than promised. Securitum, a European security auditing firm, ran the fifth consecutive annual audit in May 2026, on-site at Proton’s Zurich infrastructure. The auditors reported no evidence that the examined servers log browsing activity, DNS queries, destination services or user-identifiable connection metadata, and no persistent records that would let Proton tie a user to activity on a reviewed server. An audit is a point-in-time sample of servers, not a review of every line of source code, so treat it as strong evidence rather than proof. It is still far more than most of the industry offers. Protocols are WireGuard and OpenVPN.

Mullvad is the choice when you want the provider itself to know as little about you as possible. There is no email address and no username: one click generates a numbered account, and that number is the whole relationship. The price is a flat EUR 5 a month and has stayed there for years. If you want to go further, Mullvad accepts cash: banknotes and a generated payment token in an envelope, by post. The company commissions independent audits of its apps and infrastructure, and it treats WireGuard as the house protocol: the default on macOS and Linux, always active in its Android and iOS apps, and available on Windows with manual activation.

Choosing between them is simple. Proton VPN if you want a free starting point, or one subscription that also covers encrypted mail, passwords and storage. Mullvad if the goal is a provider that holds almost nothing about you. There is no wrong answer between those two; there are plenty of wrong answers outside them.

What a VPN does not do

The VPN industry sells itself as a privacy cure. The gaps matter as much as the pitch.

  • It does not make you anonymous. Your accounts still identify you. Sign in to Google through a VPN and Google still knows exactly who you are; it simply sees a different network address doing it.
  • It does not stop tracking that rides above the connection: cookies, browser fingerprinting, and the analytics baked into apps all work through a VPN untouched.
  • It does not fix weak or reused passwords, and it does not stop you clicking a convincing phishing link.
  • It does not find or remove malware. An infected device on a VPN is an infected device with better transport.
  • It does not protect you from the provider itself. Routing everything through a company that logs is worse than routing nothing. This is the problem with the free-VPN economy: servers cost money, and an unaudited free provider is usually paying for them with your traffic.

The rule of thumb: a VPN changes who can watch your connection. Choose it the way you would choose who is allowed to watch. The two providers above are close enough in quality that the full head-to-head, apps, speeds and edge cases included, deserves an article of its own, and one is planned for this desk.

What should carry your sensitive email?

Email is the master key to your life. Whoever holds your inbox can reset nearly every password you own, read years of correspondence, and impersonate you convincingly. It deserves more care than it usually gets, and the mainstream free providers, whose business runs on knowing you, are not where sensitive correspondence belongs.

Our recommendation is Proton Mail, and it is the easiest recommendation in this article to make. It stores mail with zero-access encryption: Proton itself cannot read what sits on its servers, so a breach of Proton does not become a breach of your mailbox. And it speaks OpenPGP, the open standard for end-to-end encrypted mail, rather than something proprietary. Mail between Proton users is end-to-end encrypted automatically, and mail to anyone else running PGP works too. If you want to understand the machinery, our practical guide to PGP encryption walks through it without assuming a technical background.

Start free. Proton Mail’s free tier gives you one address and 1 GB of storage: enough to test the workflow, or to run a dedicated inbox for the few correspondents who genuinely need protecting. It is not a daily driver; anyone consolidating several addresses or receiving attachments in volume will hit the ceiling quickly.

When you outgrow it, the paid tiers come in two shapes. Mail Plus is the single-mailbox upgrade: 15 GB of storage, ten extra email addresses, support for one custom domain, and ten hide-my-email aliases. Proton Unlimited is the ecosystem plan: 500 GB, fifteen extra addresses, three custom domains, unlimited aliases, and the rest of Proton’s suite bundled in, including Proton VPN, Proton Pass, Proton Drive and Proton Calendar. If you intend to adopt the VPN and the password manager anyway, Unlimited is usually the tidier answer. Prices move; check Proton’s site and decide by what you will actually use.

Which password manager should you trust?

Passwords fail in one dominant way: reuse. Some forum you joined years ago gets breached, your email address and password land in a dump, and automated tooling tries that pair against banks, mailboxes and marketplaces within hours. The defence is unglamorous: a long, unique password for every account, which is only practical when software does the remembering. Almost any reputable password manager beats none. The real choice is between two philosophies.

Offline, where the vault is a file you control: KeePassXC. It is free, open source, and natively cross-platform on Windows, macOS and Linux. The offline model’s appeal is custody: the vault is a local encrypted file that never touches anyone’s cloud unless you put it there. The cost is logistics: syncing it between devices and backing it up are your job.

A note on the name, because the two get confused. The original KeePass is a Windows-first application that runs on a Mac or on Linux only through a compatibility layer; KeePassXC is its actively developed, natively cross-platform descendant. On Windows either will serve. Everywhere else, KeePassXC is the one to install.

Online, where a service syncs the vault for you: Proton Pass. Everything arrives on every device with no ceremony, which for most households is the difference between a password manager that gets used and one that gets abandoned. It has a free tier, so trying it costs nothing, and it is included in Proton Unlimited. One feature is worth knowing by name: Dark Web Monitoring, which watches breach data for your addresses and alerts you when something surfaces. That one belongs to the paid plans (Pass Plus, or the Unlimited bundle), not the free tier.

Choose by temperament: KeePassXC if custody matters most and logistics do not scare you, Proton Pass if convenience is what will keep you consistent. Then find out what is already loose. Have I Been Pwned checks any email address against known breach data for free, and its Notify Me signup emails you when your address appears in a future breach. Two rules while you are there: enter email addresses only, never a password you use, and treat every hit as an instruction to change that account’s password today.

The one password you still have to remember, the master password, should be a passphrase: four or five genuinely random words. Length beats cleverness, and a five-word phrase you can type without thinking outperforms any eight-character contortion of symbols you will forget. For the accounts that guard everything else, your email and the vault itself, add a hardware security key on top; our personal security checklist makes the case for hardware keys.

What should you change on your phone this week?

Your phone knows where you sleep, what you read, and who you talk to. It is the most personal computer you own, and its defaults lean toward data collection because collection is what funds the ecosystem. Below are the settings we would walk a client through first. Paths are current as of iOS 26 and Android 17; menu names drift between versions and manufacturers, so if a path does not match your screen, search the Settings app for the feature name rather than giving up.

If you carry an iPhone

  • Turn off tracking requests. Settings > Privacy & Security > Tracking: switch off Allow Apps to Request to Track. Apps stop asking to follow you across other companies’ apps and websites; the answer becomes a standing no.
  • Turn off Apple’s ad personalization. Settings > Privacy & Security > Apple Advertising: switch off Personalized Ads.
  • Turn on the App Privacy Report. Settings > Privacy & Security > App Privacy Report. From then on the phone keeps a ledger of which apps touched your location, camera, microphone and contacts, and which domains they talked to. Read it monthly; it is the best argument for the app diet below.
  • Audit location access app by app. Settings > Privacy & Security > Location Services. While Using is enough for most apps, and anything that only needs a rough area (weather, news) should have Precise Location switched off, so it gets the neighbourhood rather than the doorstep. Leave precision on for apps that earn it, like Maps and Find My.
  • Turn on Mail Privacy Protection. Settings > Apps > Mail > Privacy Protection: turn on Protect Mail Activity. It blunts the tracking pixels that tell senders when and where you opened a message.
  • Leave Safari’s tracking protection alone. Settings > Apps > Safari: Prevent Cross-Site Tracking is on by default; just confirm nobody switched it off.
  • Know that Lockdown Mode exists. Settings > Privacy & Security > Lockdown Mode. Apple built it as an optional, extreme protection for the very few people who may be personally targeted by sophisticated attacks, and it trades real functionality for that hardening. Most readers should leave it off; people facing a serious, specific threat should know where it is.

If you carry an Android phone

Android varies by manufacturer more than iOS varies by version; Samsung, Xiaomi and others rename and relocate menus. The paths below are stock Android as Google ships it; on other brands, search Settings for the feature name.

  • Read the Privacy Dashboard. Settings > Security & Privacy > Privacy dashboard: a timeline of which apps recently used your location, camera and microphone. Anything surprising in that list is your first lead.
  • Work through the Permission manager. Settings > Security & Privacy > Privacy > Permission manager. Permissions are grouped by type; strip camera, microphone, location and contacts from anything without an obvious, current need.
  • Turn down ad personalization, in both places. The device-level controls live at Settings > Google > All services, then under Privacy & security tap Ads > Ads privacy: switch off Ad topics, App-suggested ads and Ad measurement. Your Google account keeps its own ad profile separately: Settings > Google > Manage your Google Account > Data & privacy > My Ad Center, where personalization can be turned off account-wide.
  • Confirm Play Protect is scanning. Open the Play Store, tap your profile icon, tap Play Protect, and check under its settings gear that Scan apps with Play Protect is on. It is on by default; make sure it stayed that way.
  • Know where Private DNS lives. Settings > Network & internet > Private DNS. If you decide to encrypt your DNS lookups (the directory queries that reveal which sites you visit), this is the switch.

Hygiene that outlasts any setting

  • Delete apps you have not opened in three months. Every app is a standing permission to run code on the device that knows you best; unused ones are pure downside.
  • Repeat the permission audit quarterly. Apps re-ask, updates re-default, and the list quietly grows back.
  • Keep automatic system and app updates on. More on this below, because it is the whole game.
  • Use a real passcode. Six digits at minimum, alphanumeric if you can bear it. Biometrics are fine for day-to-day unlocking; the passcode underneath is what everything rests on.
  • Be slow to install apps from outside the official store. Sideloading skips a review layer, and most people have no reason to.

Carrier-level settings matter more than people expect. Set a SIM PIN, so a thief who pulls the SIM from your phone cannot drop it into another handset and start receiving your calls and codes. One caution: SIMs ship with a carrier-default PIN, so look up your carrier’s default before changing it, and type carefully: three wrong entries lock the SIM until the carrier issues you an unlock code called a PUK. Then ask your carrier what port-out or SIM-swap protection it offers, and turn on whatever exists. The reason is the same in both cases: your phone number has become an identity credential, and hijacking it is how attackers defeat SMS-based two-factor codes. Why SMS codes are the weak link, and what to use instead, is covered in the SMS two-factor section of our personal security checklist.

Finally, the setting no menu offers: when a phone stops receiving security updates, stop trusting it. An unpatched phone accumulates publicly known, permanently open flaws, and no configuration compensates for that. Retire it, or demote it to duties that never touch your accounts. There is more to say about phones than one section can carry; a dedicated mobile-security deep dive is planned for this desk.

When did you last look at your router?

Every byte your household sends or receives crosses one box that most people have never logged in to. The router is the least-patched, least-examined computer in the house, and because it sits between all your devices and the internet, compromising it pays better than compromising any single laptop. Router hardening is a discipline of its own, so treat this list as an introduction: the eight moves that close the common doors, not the full manual.

  • Change the router’s admin password. Not the Wi-Fi password: the one that opens the settings screen. Factory defaults are printed on labels and catalogued online, and they are the first thing an automated scan will try.
  • Update the firmware, then make it automatic. Log in to the admin screen, apply whatever update is pending, and enable automatic updates if the router offers them. Routers accumulate known flaws like any computer; unlike your phone, nobody reminds you.
  • Use WPA3 with a long passphrase. WPA3 where the hardware supports it, WPA2 otherwise. If the router cannot manage at least WPA2, it belongs in electronics recycling, not on your wall.
  • Rename the network to say nothing about you. The network name is broadcast to everyone in range. It should not carry your surname, your unit number, or the router’s model name. Make it boring.
  • Turn off WPS. The push-button pairing feature is a long-standing weak point, and almost nobody actually needs it.
  • Turn off remote administration. The settings screen should be reachable only from inside your own network. If you did not knowingly set up remote management, confirm it is off.
  • Give guests and gadgets their own network. Most routers can run a guest network. Put visitors on it, and put the smart TV, the doorbell and the rest of the connected gadgets there too, so the least-trustworthy hardware in the house cannot see your laptops.
  • Replace a router that no longer receives firmware updates. An end-of-life router is a permanent, unfixable vulnerability with an antenna. If yours is rented from your internet provider, ask whether it still receives updates, and push for a swap if it does not.

Eight items, one evening, once. After that, a firmware check joins the quarterly routine and the box goes back to being boring, which is what you want from infrastructure.

Why are updates the cheapest defence you own?

The blunt version: most real-world compromises do not use exotic, undiscovered flaws. They use known ones, catalogued and patched long before, against machines that never installed the patch. Attackers automate the search, and unpatched machines volunteer themselves.

Updates are the cheapest, most effective security control you have, and they cost one decision: turn on automatic updates for the operating system, the browser, the apps and the router firmware, on every device you own, and let the machines look after it. If you do nothing else this article suggests, do this.

The same logic has a hard edge. End of life means end of trust: a device that no longer receives security updates (a phone, a laptop, a router, a smart camera) does not plateau at its current safety, because every flaw discovered from that day on stays open in it forever. Plan replacements while hardware is still supported, not after.

What else earns a place in the toolkit?

A handful of smaller tools and habits round out the kit. None of them takes more than an evening; several have saved our clients real grief.

The browser, plus exactly one extension

Modern mainstream browsers ship with meaningful tracking protection; keeping yours updated does more for you than chasing exotic alternatives. The one addition we recommend without hesitation is uBlock Origin, a free, open-source content blocker. It removes ads and, more to the point, the tracking machinery that travels with them, and it shrinks your attack surface, because malicious ads remain a live delivery channel for scams and malware. Beyond that, stay stingy with extensions: each one is code you are trusting with everything you do in a browser.

Give every service a different email address

An alias is an address that forwards to your real inbox. Hand every shop and service its own, and two things happen: a leaked address tells you exactly who leaked it, and killing the alias kills the spam without disturbing your real address. Proton’s hide-my-email aliases come with the paid mail tiers, ten on Mail Plus and unlimited on Proton Unlimited, and aliasing is one of those quiet features that ends up mattering more than the headline ones.

Messaging that is actually private

For conversations that deserve an envelope rather than a postcard, Signal is the default recommendation. You do not switch encryption on; every message and every call is end-to-end encrypted as a matter of course, and the organization behind the app is a nonprofit rather than an advertising business.

Session answers a different question. It needs no phone number or email at all, identifies you by a generated Account ID, and routes traffic through an onion network to keep metadata thin. That makes it the tool for when the link between your identity and the conversation is itself the sensitive part. It is one of the channels we keep open for discreet first contact, alongside PGP; our Secure Communications service explains how.

Checking a suspicious file without burning yourself

VirusTotal scans files and links with a battery of security engines, free for non-commercial use, and it is the right reflex the day an invoice attachment feels off. But understand the deal before you upload: submissions are shared with the security community, and the contents of submitted files can be examined by VirusTotal’s partners and premium customers. It is a public examination table, not a private lab. Never upload anything sensitive: contracts, identity documents, medical records, anything carrying a client’s or a family member’s details. For files like that, use the hash search instead: compute the file’s fingerprint (its SHA-256; MD5 and SHA-1 also work) and paste that into the VirusTotal search box. If the file has been seen before, you get the verdict without the file ever leaving your machine.

Getting out of the people-search sites

A professional admission: aggregated data-broker profiles are often the first stop in lawful skip tracing. When we locate someone, the trail frequently starts with the same people-search sites anyone can query in a minute. That is why removing yourself is worth the tedium: it thins the file that any stranger, marketer, or obsessive can pull on you. Search your own name and city, note which people-search sites hold a profile on you, and work through each one’s opt-out or removal page. Most of the big brokers are American, but they hold Canadian records too, so do not assume you are exempt. For organizations operating in Canada, privacy law adds leverage: you are entitled to ask what personal information a company holds about you, to ask for it to be corrected, and to withdraw your consent to its further use. Then put a repeat sweep in the calendar, because profiles regrow as fresh data flows in.

Encrypt the whole disk

Full-disk encryption turns a lost or stolen computer from a data breach into a hardware expense. It is built in and free: FileVault on a Mac, BitLocker or Device Encryption on Windows, and phones encrypt themselves once a passcode is set. Turn it on before you need it, and store the recovery key somewhere that is not the laptop bag.

Back up like you expect ransomware

The 3-2-1 rule has survived because it works: three copies of anything that matters, on two different kinds of storage, with one copy off-site or offline. The offline copy is the one ransomware cannot reach; the off-site copy is the one a burglary or a house fire cannot. And a backup you have never test-restored is a hope, not a backup. Rehearse the restore twice a year.

Social media, the compressed version

Our checklist covers this ground in depth. The short form:

  • Set accounts private, and audit who already follows you.
  • Post travel after you are home, never while you are away.
  • Turn off location tagging in the camera, and strip photo metadata before sharing outside your circle.
  • Review what you are tagged in; other people’s sharing habits are part of your footprint.
  • Assume anything public will eventually be read by the least friendly possible reader. In our case files, it usually has been.

When is a problem past do-it-yourself?

Everything above assumes a general adversary: automated crime, data brokers, opportunists working at scale. Tools handle that tier well. They stop helping when the adversary is one particular person with a particular interest in you.

The signs are usually behavioural before they are technical. Someone repeats details from conversations that happened behind closed doors. An ex turns up at places they had no way to know about. A device keeps misbehaving after a competent cleanup: settings that change themselves, accounts that show sign-ins you did not make. None of these proves surveillance on its own; together, in a pattern, they justify a professional look.

Two of our services exist for that line. A technical surveillance countermeasures sweep examines a home, office or vehicle for listening devices, hidden cameras and trackers using purpose-built equipment, and produces a documented finding either way; knowing a space is clean has ended more than one spiral of doubt. Digital forensics examines phones and computers properly: not just spotting spyware but preserving how it got there and what it did, in a form that stays usable if the matter ends up before a court or tribunal. If this section describes your situation, talk to a professional before you wipe, delete or confront, so the evidence survives the cleanup.

General guidance

This article is general security guidance for people at ordinary risk, not advice tailored to your situation, and it describes products, plans and menu paths as they stood at publication; software changes faster than articles do. No tool on this page replaces judgment about your own circumstances. If you believe a specific person is monitoring or following you, do not stop at settings: get professional help.

Frequently asked questions

Are free VPNs safe to use?

Mostly no. Running a VPN network costs real money, and a free provider that is vague about how it covers that cost is usually covering it with your browsing data. The exception worth naming is Proton VPN’s free tier: no ads, no data limits, and the same audited no-logs policy as the paid plans, funded by Proton’s paying subscribers rather than by you. If free is the requirement, use that one, and treat every other free VPN as a risk rather than a saving.

Should I pick Proton VPN or Mullvad?

Both clear the bar that matters: independently audited no-logs practice, modern protocols like WireGuard, and a business model that does not feed on your data. Pick Proton VPN if you want a free tier to start with, or one subscription that also covers encrypted email, a password manager and storage. Pick Mullvad if you want the provider itself to hold almost nothing about you: it identifies you by a generated account number, asks for no email address, and accepts cash. You are choosing between two good answers.

Do I still need to buy antivirus software?

For most people, no. The protection built into current systems, Microsoft Defender on Windows, the safeguards built into macOS, and Play Protect on Android, is competent and always on. Keep it enabled, keep the system updated, and use VirusTotal to check a suspicious file before opening it, remembering that uploads are shared with the security community, so sensitive documents should be checked by hash search instead of uploaded.

Is an iPhone or an Android phone better for privacy?

Configured properly, either is fine, and this guide walks both. iPhones ship with tighter defaults and one consistent settings layout; Android offers more visibility and control but varies by manufacturer and asks a little more of you. The honest answer is that the owner matters more than the logo: a maintained, updated, deliberately configured phone of either kind beats a neglected phone of either kind.

Do I need to pay for Proton for any of this to work?

No. The free tiers are a real starting point: Proton VPN free has no data limits, Proton Mail free gives you an encrypted mailbox for the correspondence that matters, and Proton Pass has a free tier for passwords. Pay when you hit a real limit: more storage, extra addresses, custom domains, unlimited aliases, or Dark Web Monitoring. Start free, prove the workflow to yourself, then decide.

How often should I revisit all this?

Quarterly, and it takes an evening each time. Re-run the app permission audits, delete apps you stopped using, confirm updates are still automatic, check your breach alerts, glance at the router for pending firmware, and repeat the people-search removals, since profiles have a way of growing back. Privacy maintenance works far better as a routine than as a resolution.

Share this note
X Facebook LinkedIn Email

End of note

Articles are general. Your case isn’t.

Every case starts with a free, confidential consultation and a written scope before any work begins.