What ‘no-logs’ actually claims
A ‘no-logs’ VPN policy is a claim that the provider does not store records that could tie your online activity back to your account or identity — typically meaning no logs of the websites or services you connect to, no logs of your originating IP address alongside your VPN session, and no logs of DNS queries made through their resolver. It’s a claim about policy and configuration, not a technical guarantee enforced by the protocol itself: nothing about WireGuard, OpenVPN or IKEv2 prevents a server operator from logging if they choose to. That’s precisely why the claim is unverifiable from the outside without some form of independent check.
It’s also worth being precise about what ‘no-logs’ doesn’t cover even when true: most providers still process payment information, account email addresses, and some aggregate, non-identifying metrics (like total bandwidth used platform-wide) for billing and service operation. Read a specific provider’s actual privacy policy, not just their marketing page, to see what is and isn’t excluded.
What an independent audit actually checks
Audits of VPN providers generally fall into two different categories, and it matters which one you’re looking at:
- Operational/assurance audits (typically run by accounting firms like Deloitte, PwC or KPMG) examine server configurations, infrastructure access logs, and internal processes at a point in time to assess whether the provider’s technical setup is consistent with its stated no-logs policy. These are attestations about what auditors observed during the engagement window, not a permanent guarantee about every server going forward.
- Technical security audits (commonly run by firms like Cure53, Securitum, or Assured AB) are penetration tests and code reviews of the VPN apps and/or server infrastructure, looking for vulnerabilities, misconfigurations, or logging code paths that shouldn’t be there. These say more about security posture and code quality than about business-level data-handling claims.
Neither type is a permanent guarantee. A provider can commission a rigorous audit and then change server configurations the next day; recurring, published annual audits are a meaningfully stronger signal than a single one-off engagement precisely because they show a pattern rather than a snapshot.
Real, verifiable examples
Rather than repeat provider marketing claims, here are specific audits that are independently documented and publicly available from the providers’ own disclosures:
- Proton VPN has published annual no-logs audits conducted by Securitum since 2022, with the most recent (2026) engagement finding no technical evidence that Proton VPN’s examined server infrastructure logs users’ browsing activity, DNS queries, or user-identifiable connection metadata, according to Proton’s own published summary.
- NordVPN has commissioned recurring no-logs assurance engagements from Deloitte Audit Lithuania, with NordVPN’s blog documenting engagements going back to 2022 and a sixth consecutive one published in 2025; NordVPN’s servers have also separately been reviewed by PwC.
- ExpressVPN had its TrustedServer infrastructure and privacy-policy compliance audited by PwC Switzerland in June 2019, and its Lightway protocol code independently audited by Cure53, with reports published via ExpressVPN’s own Trust Center.
- Mullvad has undergone multiple infrastructure and app security audits by Cure53, including a fourth infrastructure audit completed in June 2024, with reports published directly on Mullvad’s own blog.
This is a representative, not exhaustive, list — other providers have also commissioned audits. The point of naming specific ones is that you can go read the actual published report rather than take a marketing page’s word for it; if a provider claims to be audited but doesn’t link to a report you can actually read, that claim is worth less than one that does.
What to actually check before trusting a claim
- Is the audit report itself published and readable, or only referenced?
- Which firm conducted it, and is that firm one that does recognized security or assurance work generally (not a firm you can’t find any other track record for)?
- Is it a one-off or a recurring, dated engagement? Recurring is a stronger signal.
- Does the audit’s actual scope match the claim being made — a code security audit of the mobile app isn’t the same evidence as a server infrastructure logging audit.
FAQ
Does an audit prove a VPN can never log anything?
No. It’s evidence about a specific, examined window of time and infrastructure, ideally repeated regularly. It’s meaningfully better evidence than an unverified claim, but it isn’t a mathematical guarantee.
Why do some well-known VPNs have no published audits at all?
Cost and willingness vary, and audits aren’t legally required. Absence of a published audit isn’t proof of bad practice, but it does mean the no-logs claim rests entirely on trust in the company rather than independent verification.
Is jurisdiction (where a VPN company is based) as important as audits?
It’s a related but separate factor — jurisdiction affects what a government can legally compel a provider to hand over, while an audit addresses what the provider’s own systems actually store. Both matter for a full picture.
Compare VPN providers side by side