Yeah, agreed. Most VPNs just move the trust boundary from your ISP to another opaque network and call it privacy. There’s no way to verify what’s running, who controls it, or what happens to your data once it leaves your machine.
We solve this with vp.net, by making the service verifiable. The code can be reviewed, the builds are reproducible, and each node can prove what software it’s running and where your traffic actually goes [1].
It doesn’t turn a VPN into an anonymity tool, but it makes trust measurable instead of blind. That’s the part the industry should have fixed a long time ago.