Can Your Ship's IT See Through a VPN? More Than You Think
Some links on this page are affiliate links. If you buy through them we may earn a commission at no extra cost to you — it never changes which product we recommend.
Can your ship's IT department see what you do through a VPN? On your own phone with your own VPN, they can usually see that you logged in, when you were online, how much data you used and that a VPN was running, while the sites and apps stay hidden. On a company laptop, a VPN hides very little, because software on the machine sees your activity before anything gets encrypted.
Plenty of crew switch on a VPN and assume the ETO, the master and the shore IT team are now blind. That assumption is right in some setups and badly wrong in others. This page goes through each setup you are likely to meet onboard, what leaks in each one, and how to check which one you are actually in.
The short answer depends on whose device and whose VPN
Whether ship IT can see through your VPN comes down to two questions: who owns the device, and who runs the VPN. Everything else is detail.
A VPN builds an encrypted tunnel from your device to a VPN server somewhere ashore. Anyone sitting on the network path between those two points, such as the crew WiFi controller, the ship's firewall or the satellite provider, sees scrambled traffic heading to one server address. They cannot read what is inside.
That protection covers the path only. It does nothing about the two ends of the tunnel. If the company owns the end where your device sits, through monitoring software or a managed profile, it sees your activity before encryption. If the company owns the far end, because it runs the VPN server itself, it sees your traffic after decryption.
So a personal VPN on a personal phone puts both ends outside the company's reach. A company VPN, or a company laptop, puts at least one end inside it.
What your ship's IT department can see through a VPN, setup by setup
The table below is the quick reference. Each row is explained in more detail underneath.
| Your setup | What ship IT can usually see | What the VPN hides from them | What the VPN never hides |
|---|---|---|---|
| Own phone or laptop, no VPN | Your device on the crew network, your login, the domain names you visit, timing and data used | Nothing, there is no tunnel | Everything in the left column |
| Own device, personal VPN | That you connected to a VPN server, when, and how much data moved | Sites, apps and DNS lookups, if DNS runs inside the tunnel | Your login, timing, data volume and the fact a VPN is in use |
| Own device, VPN run by the company | Traffic arriving at the company's VPN gateway, and possibly its contents after decryption, depending on how it is configured | Your traffic from the crew WiFi equipment itself | Whatever the company gateway logs |
| Company laptop, personal VPN | Whatever monitoring software on the laptop records | Traffic from the network path only | All on-device monitoring |
| Company laptop, company VPN | On-device monitoring plus the gateway view | Very little from the company | Almost everything |
| Own phone with a managed work profile | Activity inside the work profile, as far as the policy allows | Personal-side traffic on the network, if your personal VPN covers it | Whatever the work profile's policy collects |
Your own phone or laptop with no VPN
Without a VPN, the crew network sees the most metadata. Most apps and websites use HTTPS, so the contents of your banking session or your messages are encrypted anyway. What stays visible is the domain name of each site or service, the time you connected and how much you downloaded. On a ship where the crew WiFi runs through a voucher or login system, all of that is tied to your name.
Your own device with a personal VPN
This is the setup where a VPN does what most crew expect. The ship's network sees an encrypted stream to a single server address. It cannot tell whether you are on a news site, a dating app or a video call.
It still sees plenty around the edges. Your crew login or voucher still identifies you. The volume of traffic still counts against your quota. The timing of your sessions is still recorded. And the server address you connect to usually belongs to a known VPN provider, so the network can tell a VPN is in use even when it cannot see through it.
Your own device on a company-run VPN
Some operators route crew devices through their own VPN, often for security or to filter content. In that case the crew WiFi hardware sees a tunnel, and the company sees everything that comes out of the other end at its gateway. What it logs, keeps and inspects there is a decision made by the company's IT team and its VPN configuration. You will rarely be told the details, and none of the public sources gathered for this page document any ship operator's logging policy.
A company laptop, with any VPN
On a company-owned laptop, the VPN is close to irrelevant for privacy from your employer. A blog post on employer monitoring published by Fexyn says that monitoring agents on a company device can see typed input, screen content, file activity and network destinations, even with a VPN installed. The same post says a VPN on a company device does not bypass endpoint monitoring, browser extensions, DNS controls or screen recording. That source is a blog, not a regulator or a ship operator's policy, but the mechanism it describes is simple: the software sits on the machine, ahead of the tunnel.
Your own phone with a managed work profile
If you enrolled your personal phone in company device management to get work email or a crew app, part of that phone now belongs to the company's policy. What the profile can see depends on what the company switched on. Your phone's settings will usually show a device management or work profile entry, and that entry lists what the organisation can access. Read it before assuming anything.
Why a VPN cannot hide anything from software on the device
A VPN encrypts data as it leaves the device, so anything that reads the data earlier in the chain sees it in plain form. Monitoring software, a managed browser, a browser extension pushed by the company or a screen recorder all work at that earlier stage.
Think of it like a sealed envelope. The VPN seals the envelope before it goes to the post room. If someone is standing behind you while you write the letter, the envelope does not help.
This is why the question "can my ship's IT department see what I do through a VPN" has no single answer. On a laptop the company issued for the engine room planned maintenance system or the ship's office work, you should assume the answer is yes for anything you do on that machine. On your own phone with nothing installed by the company, the answer is mostly no for content and yes for metadata.
Can ship IT see your VPN traffic when the company runs the VPN?
Yes, when the company runs the VPN, its gateway is the far end of your tunnel, and that gateway sees your traffic once it is decrypted. How much it records is up to the company.
Business VPN and secure access products are cheap enough that any shipping company can deploy them across a fleet. NordLayer's own pricing page listed its Lite plan at $8, Core at $11 and Premium at $14 per user per month on annual billing, as checked on 6 October 2026; prices change, so re-check before relying on these figures. Tailscale's pricing page listed paid business tiers at $8 and $18 per user per month with a 14-day free trial, also as checked on 6 October 2026, and those figures need re-checking too.
NordLayer's own business VPN page also lists a dedicated server add-on at $40 per month, a figure repeated in Cloudwards' review of business VPNs. A third-party pricing tracker, CheckThat, claims Tailscale moved from monthly active-user billing to assigned-seat billing on 8 April 2026 and now caps free tagged resources at 50 before extra tagged resources cost more; Tailscale's own pricing page does not confirm this change, so treat it as unverified. Perimeter 81, a comparable product, is priced separately again: Cloudwards' review lists Essentials at $8, Premium at $12 and Premium Plus at $16 per user per month on annual billing, while ZDNET's review lists different monthly prices and a minimum of 10 users on its entry-level plan. Which of those Perimeter 81 figures is current is not established from the sources gathered, so treat that pricing as unverified too.
These products are built to give a company control over who reaches its systems and how. That is a legitimate job, especially since ship networks now fall under class and flag cyber requirements, which our piece on the ClassNK cyber resilience guide and what crew must do covers. For you, the practical point is simple. If a VPN profile appeared on your device because the company told you to install it, treat everything that passes through it as visible to the company.
What a personal VPN still leaks on crew WiFi
A personal VPN on your own device hides content and destinations, but several things still reach the ship's network. Knowing them stops you overestimating your privacy.
- Your identity on the network. The crew WiFi login, voucher code or device registration ties every session to you, VPN or not.
- Timing and volume. The network records when you were online and how much data moved, since it has to count that against your allowance.
- The fact that you use a VPN. Connections to known VPN server addresses are easy to recognise, even when their contents are unreadable.
- DNS lookups, if the VPN leaks them. Some VPN apps send domain lookups outside the tunnel under certain settings. When that happens, the network sees every site name you look up.
- Apps outside the tunnel. Split tunnelling, or a VPN that drops and reconnects on a slow satellite link, can send some traffic in the open for a while.
- Anything before the VPN connects. The captive portal login and any app traffic in the moments before the tunnel comes up travel unprotected.
The same habits that protect you in port apply here, and our guide to port WiFi security and how not to get hacked walks through them.
How crew WiFi is usually built, and why it matters
On most modern ships, crew WiFi sits on its own network, kept apart from the bridge, engine control and office systems. Our explainer on how separating crew WiFi from the ship network works covers the design in detail.
That separation cuts both ways. It means your personal phone has no business reaching the ship's operational systems, which is good for everyone's safety. It also means the crew network usually has its own firewall, its own login system and often a shore-based management service, all of which can record metadata. The person who can see those logs might be the ETO, the master, the fleet IT desk ashore or the connectivity provider, depending on the contract. Nobody onboard may know exactly who has access, and that is a reason to assume metadata is visible.
Honest pros and cons of a personal VPN on ship WiFi
A personal VPN on your own device is a sound privacy tool against the crew network, with clear limits.
Pros
- It hides your destinations from the crew WiFi equipment and anyone else on the network path.
- It protects you on shared networks, which matters when dozens of people share one access point and not all of them are careful.
- It keeps working the same way in port, where you switch between hotel WiFi, terminal WiFi and eSIM data.
Cons
- It does nothing against monitoring on a company device, according to the employer monitoring blog cited above, and the logic of how monitoring software works backs that up.
- It announces itself. The network can see you use a VPN, which may break the crew internet policy you signed.
- It adds overhead and can slow things down on a link that is already shared and high latency, so pages and calls may feel worse.
- It still counts against your quota, since encryption adds a little extra data on top of what you actually use.
- It can be blocked. Some ships filter VPN protocols on crew WiFi, and a blocked tunnel leaves you either offline or exposed.
If you do run a consumer VPN on your own phone, such as NordVPN or Surfshark, the second row of the table above is the one that applies to you. For a ranked look at options for crew, see our guide to the best VPN for cruise ship crew.
Who should not rely on a VPN for privacy onboard
Some crew get almost nothing from a VPN in terms of privacy from the company, and they should know it before they rely on one.
- Anyone using a company laptop for personal browsing. Treat that machine as fully visible.
- Anyone with a work profile or device management on their phone. Part of that phone reports to the company.
- Anyone whose VPN was installed by the company. The company holds the far end of the tunnel.
- Anyone on a ship that bans VPNs in its crew internet policy. The network will show a VPN in use, and the consequences are a matter for your contract.
How to check which setup you are actually in
You can work out your real position in a few minutes with the device in your hand.
- Check who owns the device. If the company issued it, assume monitoring.
- Look for device management. In your phone settings, search for "device management", "profiles" or "work profile". If an organisation is listed, open it and read what it can access.
- Check the VPN entries. In your network settings, look at every VPN configuration. Delete nothing that is company-required, but know which ones you did not install yourself.
- Read the crew internet policy. It usually says whether VPNs are allowed and who manages the network.
- Run a DNS leak test with your VPN on. Any leak test site will show which DNS servers answer your lookups. If they belong to the ship's provider, your site names are leaking.
- Keep personal life on personal devices. This is the single change that gives you the most privacy for the least effort.
FAQ
Can the ship see which websites I visit if I use a VPN?
On your own device with a personal VPN that handles DNS properly, the ship's network sees only an encrypted connection to the VPN server. It cannot tell which sites you open. On a company device or through a company-run VPN, assume it can.
Can ship IT read my messages if I don't use a VPN?
Most messaging, banking and email apps encrypt their own traffic, so the crew network generally cannot read message contents even without a VPN. What it can see is which services you connect to, when and how much data you use. A VPN hides those destinations as well.
Will ship IT know I am using a VPN?
Usually yes. Connections to VPN servers are easy to spot by their addresses and traffic patterns, even when the contents stay unreadable. If your crew internet policy forbids VPNs, assume the network can tell.
Does a VPN hide my data usage from the crew WiFi quota?
No. Every byte still passes through the ship's connection and counts against your allowance. The encryption adds a little extra data, so a VPN slightly increases what you use.
Is it against the rules to use a VPN on ship WiFi?
That depends entirely on your company. Some operators allow personal VPNs on crew WiFi, others block or ban them. The crew internet policy you signed on joining is the place to check, and the master or ETO can confirm it.
Verdict
A personal VPN on your own phone or laptop does a real job: it hides where you go online from the crew network. It does nothing against software the company put on a device, and it does nothing against a VPN the company operates itself, for the same reason explained above: the company's own gateway sits at the far end of that tunnel and can see traffic once it decrypts there. Decide which setup you are in first, and keep anything private on hardware the company has never touched.
Related reading
- How to set up a VPN on a ship's router without admin access
- Why a VPN keeps disconnecting on ship WiFi and how to fix it
- Why a VPN makes an already slow ship connection even slower
About the author
This guide was written by the Sea Current Tech editor, a working marine engineer who has lived on crew WiFi through long contracts. They have shared a ship's connection with the rest of the crew and know the real trade-off between staying connected and keeping some privacy. The guide sticks to how VPNs and device monitoring actually work, names its sources, and leaves out what nobody has publicly documented about specific ships. That is the honest way to answer the question: can your ship's IT department see what you do through a VPN?
What we checked, and what is the vendor's word
- Endpoint monitoring software: A blog on employer monitoring says a VPN on a company-owned device does not bypass endpoint monitoring, browser extensions, DNS controls or screen recording. Not verified by us, taken from a third-party page (6 October 2026, source).
- Endpoint monitoring software: The same blog says monitoring agents on a company device can see typed input, screen content, file activity and network destinations even when a VPN is installed. Not verified by us, taken from a third-party page (6 October 2026, source).
- NordLayer: NordLayer's pricing page lists the Lite plan at $8 per user per month when paid annually. Vendor's claim, not verified by us (6 October 2026, source).
- NordLayer: NordLayer's pricing page lists the Core plan at $11 and the Premium plan at $14 per user per month when paid annually. Vendor's claim, not verified by us (6 October 2026, source).
- Tailscale: Tailscale's pricing page lists paid business tiers at $8 and $18 per user per month. Vendor's claim, not verified by us (6 October 2026, source).
- Tailscale: Tailscale's pricing page offers a 14-day free trial on its business plans. Vendor's claim, not verified by us (6 October 2026, source).
- NordLayer: NordLayer's business VPN page lists a dedicated server add-on priced at $40 per month, a figure also repeated in Cloudwards' review of business VPNs. Not verified by us, taken from a third-party page (6 October 2026, source).
- Perimeter 81: Cloudwards' review of business VPNs lists Perimeter 81 at $8 per user per month for Essentials, $12 for Premium and $16 for Premium Plus on annual billing. Not verified by us, taken from a third-party page (6 October 2026, source).
- Perimeter 81: ZDNET's review of business VPNs lists different Perimeter 81 monthly prices and a minimum of 10 users on its entry-level plan. Not verified by us, taken from a third-party page (6 October 2026, source).
- Tailscale: CheckThat's pricing tracker claims Tailscale switched from monthly active-user billing to assigned-seat billing on 8 April 2026 and caps free tagged resources at 50, a change not confirmed on Tailscale's own pricing page. Not verified by us, taken from a third-party page (6 October 2026, source).
Prices and limits move. Each line above says the date we last saw it on the source page.