Has a VPN's No-Logs Claim Ever Been Tested in Court?
Yes — a few no-logs claims have been tested by real legal demands, and in every documented case the provider produced nothing, because it had nothing to produce. That is genuinely reassuring, but it comes with an important caveat: there are only a handful of these cases, so “court-proven” is a phrase to examine, not to accept as a category-wide badge. Below are the documented examples, with dates and sources, and an honest read of what each one does and does not prove.
ExpressVPN — Turkey, 2017
The clearest server-seizure case involved ExpressVPN. In January 2017, Turkish investigators seized one of the company's servers as part of the inquiry into the December 2016 assassination of the Russian ambassador to Turkey, Andrei Karlov. According to reporting at the time by TorrentFreak and others, investigators were trying to recover data about who had wiped digital traces from a device — and the server yielded no activity or connection logs that could help. ExpressVPN's no-logs design meant there was simply nothing on the machine to find.
There is a revealing footnote. After the seizure, ExpressVPN moved away from physical servers in Turkey and began offering a Turkish IP address through virtual servers physically located in the Netherlands. The lesson the company drew was not just “keep no logs” but “reduce what can be physically seized in a risky jurisdiction at all”.
Private Internet Access — 2016 and 2018
Private Internet Access has been tested twice in US courts, which is more than almost any other provider. In 2016, the FBI sought records relating to a PIA user in a hoax bomb-threat case; the only thing PIA could supply was a cluster of shared VPN IP addresses that many customers used at once — not an individual's activity. In June 2018, US authorities again subpoenaed PIA in a criminal matter, and once again, as reported by TorrentFreak, the company had no user data to hand over.
Two separate legal demands, years apart, both producing nothing, is a strong pattern — and PIA has since backed it with independent Deloitte audits, which is exactly the combination we look for in our comparison of audited no-logs providers. A court test plus a named audit is more convincing than either on its own.
Mullvad — the 2023 police raid
The most vivid case is not a court subpoena but a physical raid. In April 2023, Swedish police arrived at Mullvad's office in Gothenburg with a search warrant, intending to seize computers holding customer data. According to Mullvad's own account and reporting by TechRadar and others, the company's staff explained that no such data exists — Mullvad stores no activity logs and its infrastructure keeps nothing that maps a user to a session. After consulting with prosecutors, the police left with nothing. It is the closest thing to a live demonstration of a no-logs claim the industry has.
What these cases prove — and what they don't
Each case proves something specific: that on a particular date, for a particular server or account, the provider had no useful data to give. That is exactly what a no-logs claim should look like under pressure. What the cases do not prove is that the same provider keeps nothing forever, or that a different server in a different country would behave identically. Infrastructure changes, ownership changes, and a claim tested in 2017 is not automatically true in 2026. Treat a court test as powerful evidence for the moment it describes, and keep looking for a recent audit to cover the present.
Be wary of “court-proven no-logs” used as a generic marketing line. Ask which case, which year, and what was actually requested. A provider that can answer those questions precisely is far more credible than one waving the phrase around without a citation.
Why there are so few cases
A handful of public cases across an industry with hundreds of providers is not many, and the reasons are mundane. Most legal demands are sealed or never made public, so we only learn about the cases a provider chooses to disclose. Many providers have never been meaningfully tested at all. And some jurisdictions issue gag orders that legally forbid a company from even saying it received a request — which is the entire reason warrant canaries exist. The small number of public cases is a reason to rely on audits as the everyday standard and to treat a genuine court test as a valuable bonus.
How to use this when choosing a VPN
When you shortlist a VPN, treat a documented court test as a strong point in its favour, but do not require one — most trustworthy providers simply have not been tested publicly. Combine three signals instead: a recent named audit, RAM-only servers so there is nothing to seize, and, where it exists, a real legal test or a maintained transparency report. If a provider has none of those and only a slogan, that is your answer. For more on the disclosure side of this, see how a VPN warrant canary is supposed to work.
The cases that go the other way
Honesty means acknowledging that not every VPN has passed this test — some have failed it badly, and those failures are just as instructive. Over the years, several providers that loudly advertised “no-logs” were later shown, in court filings or security incidents, to have handed over user data or to have been keeping records they claimed not to keep. The details vary, but the pattern is consistent: the provider had never published a meaningful independent audit, so its no-logs claim rested on nothing but its own word, and that word did not survive contact with a subpoena. This is the single strongest argument for the approach we take across this site. A court test that goes the right way is powerful, but you cannot count on your provider ever being tested; what you can check, today, is whether an outside firm has inspected its systems and whether its infrastructure is designed to keep nothing. The providers that have both an audit and a clean legal record are rare, and they are rare for a reason — most of the industry has one, the other, or neither.
No-logs and the courts
Which VPN has proven its no-logs claim in court?
Does a court test guarantee a VPN keeps no logs today?
Why haven't more VPNs been tested in court?
Is “court-proven no-logs” a reliable marketing claim?
The through-line to everything here: a VPN shifts trust to its provider. See which no-logs claims are actually audited, or read the honest threat model.