Play Store adds new badge to signal which Android VPN apps pass a security audit

Google Play store on an Android device
(Image credit: Rafapress/Shutterstock)

To give users more peace of mind and show that it's taking concerns about Android cybersecurity seriously, Google's rolling out an Independent Security Review badge to highlight which Android VPN apps have gone through an independent security audit. 

Last year, the App Defense Alliance, a collaboration between Google, ESET, Lookout, and Zimperium launched in 2019 to solve the Play Store's persistent malware problem, introduced the Mobile Application Security Assessment (MASA) audit. This process enables software developers to have their apps independently validated against a global security standard as a way to signal to users that what they're downloading on their phones has been designed to meet industry mobile security and privacy minimum best practices. The logic is that if developers go the extra mile on their end to mitigate security vulnerabilities and users can make more informed decisions prior to downloading new apps, hackers will have a harder time breaking into users' devices, thus improving the app quality across the ecosystem as a whole if you have one of the best Android phones.

Apps that receive a badge have successfully undergone a MASA audit. To maintain the badge year over year, app developers will need to undergo another independent audit annually. 

“While certification to baseline security standards does not imply that a product is free of vulnerabilities, the badge associated with these validated apps helps users see at-a-glance that a developer has prioritized security and privacy practices and committed to user safety,” Nataliya Stanetsky of the Android Security and Privacy Team said in a Google Security Blog post this week.

Now when you search for the best VPN apps in the Play Store, you should see a banner at the top that points you to the Data Safety Section to better understand what the new badge means. If you click the option to Learn More, it redirects you to the App Validation Directory, "a centralized place to view all VPN apps that have been independently security reviewed."

"We've launched this banner beginning with VPN apps due to the sensitive and significant amount of user data these apps handle," Stanetsky explained.

"VPN providers such as NordVPN, Google One, ExpressVPN, and others have already undergone independent security testing and publicly declared the badge showing their good standing with the MASA program," she added. 

It's all part of Google's broader push to make the Data Safety Section a one-stop shop for understanding cybersecurity practices in the Play Store. There you can also find details about what kind of data apps are collecting from you, for what purpose, and whether it's being shared with third parties. 

How to stay safe from adware and malicious apps

While keeping an eye out for the Independent Security Review badge is a start, there are plenty of other ways you can better insulate your phone from malware attacks. In addition to limiting how many apps you have installed, consider using one of the best Android antivirus apps for extra protection. 

If you’re on a tight budget though, Google Play Protect is good in a pinch, as it scans both your existing apps and any new ones you download for malicious code. Google Play Protect recently added real-time scanning so that whenever you go to install a new app, you're prompted by Android's built-in antivirus software to perform an app scan to check if it's safe. If something dangerous is uncovered, Google Play Protect will block the app and prevent you from installing it.

More from Tom's Guide

Alyse Stanley
News Editor

Alyse Stanley is a news editor at Tom’s Guide overseeing weekend coverage and writing about the latest in tech, gaming, and entertainment.Prior to joining Tom’s Guide, Alyse worked as an editor for the Washington Post’s sunsetted video game section, Launcher. She previously led Gizmodo’s weekend news desk and has written game reviews and features for outlets like Polygon, Unwinnable, and Rock, Paper, Shotgun. She’s a big fan of horror movies, cartoons, and roller skating.

Read more
Smartphone displaying Google Play Store logo
Are fake VPNs a thing of the past? Google Play will now verify safe VPN apps
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
An image of a Google Android robot
Google blocked over 2.5 million suspicious Android apps from the Play Store last year
Best Android antivirus
The best Android antivirus apps in 2025
Facebook, Instagram, YouTube, Pinterest, X, LinkedIn, Reddit, TikTok, Threads apps on an iPhone
Why you need to review your app permissions now
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Latest in VPNs
NordVPN logo on a blue background
NordVPN drops to its lowest price this year – here's what you need to know
ExpressVPN logo above mobile devices
ExpressVPN lays off undisclosed number of employees
The outline of a hand holding a phone, wrapped in barbed wire to indicate censorship
What are anti-censorship features and how is Proton VPN leading the way?
Hacker typing on laptop in darkened room
Hackers create "BRUTED" tool to attack VPNs – how to stay safe
NordProtect logo on black background
NordVPN's NordProtect cyber insurance goes solo – and adds a key new feature
Proton VPN logo and in-app screenshots
"If you control online, you control everything" – Proton is taking the fight to internet censorship
Latest in News
Google Pixel 9a hands-on.
Pixel 9a’s on-device AI isn’t as good as the Pixel 9 — here’s what’s different
Siri in iOS 18 on iPhone
Users complain that Siri can’t answer even the most basic questions — here’s what we know
Sony Xperia 1 VI
Sony Xperia 1 VII could get a 200MP main camera to challenge Galaxy S25 Ultra
iPhone 16 next to samsung galaxy watch 7 and bose wireless earbuds on a composite image
Apple's walled garden is crashing down — EU orders iOS to open up to third-party devices
Sourdough Sidekick
Feeding your sourdough starter just got a lot easier with this new smart gadget
Qobuz
Qobuz reveals artist payouts for the first ever — here’s how much it pays artists per stream