Two trust signals with different limits
VPN providers often publish a transparency report, a warrant canary, or both, as evidence of how they handle legal requests. They are useful signals, but they are not audits. This article explains what each is, using the Electronic Frontier Foundation’s explainer on warrant canaries, which is written about United States law, and Proton VPN’s published report as a worked example of a provider’s own claims. It separates what a provider says from what has been independently verified.
What a warrant canary is
The EFF defines a warrant canary as a colloquial term for a regularly published statement that a service provider has not received legal process it would be prohibited from saying it had received. Once the provider receives such process, the speech prohibition applies and the canary statement is removed. Readers may infer from the silence that the provider has now been served. Warrant canaries are often published alongside a transparency report listing the legal process the provider can publicly say it received in a period.
The EFF’s legal theory is that the First Amendment protects against compelled speech: the government might be able to compel silence through a gag order, but may not be able to compel a provider to lie by falsely stating it has not received legal process. It says courts have rarely upheld compelled speech, and have not upheld compelled false speech. Crucially, when it wrote its FAQ in 2014, it said there were no cases upholding warrant canaries. It states its belief that they are legal, but adds that no one can guarantee success in litigation. So on the sources cited, the legal status of a canary was untested as of 2014, and this is a US-specific analysis rather than a statement about the UK or EU.
What a transparency report is
A transparency report is a provider’s own summary of the legal requests it received and how it responded. Proton VPN’s page is a useful example because it publishes counts. It says that since Proton VPN launched in 2017 it has received 458 legally binding orders approved by Swiss authorities, and that in every case the authorities wanted help identifying who was connected to a specific VPN server at a specific time. It reports that all of them were denied because the service does not keep the logs that would make such identification possible.
Its year-by-year table lists 1 order in 2019, 37 in 2020, 121 in 2021, 80 in 2022, 60 in 2023, 53 in 2024, 59 in 2025 and 47 through June 2026, with every order denied in every year. Those numbers add up to the 458 total.
Jurisdiction and canaries
Proton makes an interesting point about canaries: it states that a warrant canary is not meaningful in Switzerland, because Swiss law requires the target of a surveillance or data request eventually to be notified so they can contest it. It also says it is based in Switzerland, will only comply with requests approved by the Swiss court system, and is legally prohibited from honouring foreign requests without such approval by Section 271 of the Swiss Criminal Code. These are the provider’s statements about Swiss law, which this guide has not checked against the legislation.
The takeaway is that the presence or absence of a canary depends on the legal system. A missing canary is not automatically a red flag, and a present one is only meaningful where a gag order regime of the kind the EFF describes applies.
What these documents cannot prove
A transparency report is self-reported. Readers cannot independently confirm that it is complete, and a report that shows every request denied is consistent with a no-logs design, but it is also simply the provider’s account. Proton says its no-logs policy has been validated by multiple audits. This guide has not examined those audits, so that claim stands as the provider’s statement here. A canary, for its part, only shows the provider did not remove a sentence, and the EFF’s own FAQ notes that a reader has to infer from silence.
The reports also say nothing about requests the provider is barred from disclosing, other than through the canary mechanism where it applies. Neither device tells you what happens to your data in a breach, whether the app leaks, or whether a provider changes ownership.
How to use them sensibly
Use transparency reports as one piece of evidence among several. Check that the report is dated, regularly updated and specific about the number and type of requests. Compare what the provider says about its logging with independent audits, where they exist, and read the audit scope. Ask whether a canary is meaningful in the provider’s jurisdiction. And do not treat a clean report as proof that a provider could never be compelled to produce anything, since a report describes the past, not a guarantee.
The bottom line
A warrant canary is a signal that works only where gagged legal process exists, and per the EFF’s 2014 US-law FAQ its legal status was untested. A transparency report is a provider’s own account, such as Proton’s report of 458 Swiss orders since 2017 with no user data disclosed. Both are useful, neither is independent verification, and neither replaces a well-scoped third-party audit.