Skip to content
Clearward

RAM-Only VPN Servers: What They Are and Why They Matter

Published Jul 15, 2026✓ Fact-checked Aug 20, 2026

A RAM-only VPN server — also called a diskless server — runs its entire operating system and software in volatile memory instead of on a hard drive. Because RAM loses everything the moment it powers down, a reboot wipes the server clean, and there is no persistent disk for anyone to seize, image or subpoena. It is one of the more meaningful privacy features a provider can adopt, and unlike a lot of VPN marketing, it describes a real engineering decision rather than a slogan.

What a RAM-only server actually is

A normal server keeps its operating system on a hard drive or SSD, which persists across reboots and can accumulate files, caches and logs over time. A RAM-only server has no such drive for its working data: the whole system is loaded fresh into memory from a trusted, read-only image each time it starts. Nothing is written to permanent storage during operation, so the moment the machine is switched off or restarted, everything it held is gone. Providers typically re-image every server on a regular schedule, which means each one is periodically returned to a known-clean state.

Why it helps your privacy

The benefit is about data at rest. If a server is physically seized — as happened to ExpressVPN in Turkey in 2017 — there is no drive that could still hold logs, configuration secrets or user traces after a power-off. It also limits the damage from an attacker who gains a foothold, because there is no long-lived storage for them to quietly plant something in that survives a reboot. Combined with a genuine no-logs policy, RAM-only infrastructure makes the claim “we have nothing to hand over” much easier to believe, because the architecture itself resists keeping data around.

Who runs RAM-only servers

ExpressVPN pioneered the approach for consumer VPNs with its TrustedServer design in 2019, running every server from a read-only image loaded into RAM. NordVPN moved its fleet to diskless, colocated servers in 2020, and Surfshark, Private Internet Access, CyberGhost and Mullvad have all adopted RAM-only or system-transient infrastructure since. It is now close to table stakes among serious providers, which is why we treat its absence as a mark against a VPN rather than its presence as a bonus. Our audited no-logs comparison notes which providers run diskless alongside their audit dates.

The limits — what RAM-only does not do

RAM-only is not magic, and honest coverage has to say so. It protects data at rest, but a server that is compromised or lawfully accessed while it is still running can have its live memory read — RAM-only does not stop a real-time interception on an active machine. It also does nothing about what the provider chooses to send off the server to a central system; if a VPN streams connection metadata to a logging database elsewhere, the fact that the edge server is diskless is irrelevant. And a read-only image is only as trustworthy as the process that builds and signs it. RAM-only removes one specific risk cleanly; it does not remove the need to trust the operator.

Think of RAM-only as “nothing to seize after the fact,” not “nothing can ever be observed.” It is a strong answer to the seizure and stolen-drive threat, and a weak one to a live, targeted interception. Both statements are true at the same time.

How it fits with no-logs and audits

These features are strongest together. A no-logs policy is the promise not to keep your activity; RAM-only is the architecture that makes accidental or leftover storage unlikely; and an independent audit is the outside verification that both are actually implemented. A provider with all three — an audited no-logs policy running on diskless servers — has a coherent story where each part reinforces the others. A provider with only one, especially only the slogan, is asking you to fill in the rest on faith.

Does it matter for you?

For everyday privacy, RAM-only is a reassuring sign that a provider takes its infrastructure seriously, and you should prefer it. For anyone whose threat model includes the physical seizure of a server — journalists, activists, people in hostile jurisdictions — it moves from nice-to-have to important. Either way, treat it as one item on the checklist rather than the whole answer, and read how these protections held up when they were actually tested in the no-logs court cases.

How to tell if a provider really runs diskless

“RAM-only” is easy to claim and harder to verify, so look for evidence rather than the phrase alone. The strongest sign is an independent infrastructure audit that specifically examined how servers are provisioned and confirmed there is no persistent user storage — this is exactly the kind of thing a Cure53 or Deloitte infrastructure review covers, which is why the auditor and scope matter more than the marketing page. A provider that describes its diskless design in technical detail, names the read-only image and re-imaging process, and backs it with a dated report is far more credible than one that simply lists “RAM-only servers” as a feature bullet. Be especially cautious with providers that rent servers from third-party data centres without controlling the hardware, since the diskless guarantee is only as good as the operator's control over the machine. None of this means you need to become a network engineer; it means you should treat “RAM-only” the same way we treat “no-logs” across this site — as a claim that is worth believing when an outside expert has checked it, and worth discounting when the only source is the company selling you the subscription. In short, diskless infrastructure is genuinely valuable, but its value to you depends entirely on whether it has been verified by someone with no reason to flatter the provider.

RAM-only servers, answered

What does RAM-only or diskless mean for a VPN?
It means each server runs its operating system entirely in volatile memory, loaded from a read-only image, with no hard drive holding working data. When the server reboots or powers off, everything is wiped, so there is no persistent storage to seize or subpoena.
Does a RAM-only server mean the VPN keeps no logs?
Not by itself. RAM-only makes leftover on-disk data unlikely, but a provider could still stream connection metadata to a central database elsewhere. RAM-only supports a no-logs claim; it does not replace an independent audit that verifies what is actually kept.
Which VPNs use RAM-only servers?
ExpressVPN introduced the approach with TrustedServer in 2019, and NordVPN, Surfshark, Private Internet Access, CyberGhost and Mullvad now run diskless or system-transient infrastructure. It is close to standard among serious providers, so its absence is worth questioning.
Can data still be recovered from a RAM-only server?
Only while it is running. RAM-only defeats attempts to recover data after a power-off or from a seized drive, but a server accessed live can still have its memory read. It is a strong protection against seizure, not against real-time interception of an active machine.

The through-line to everything here: a VPN shifts trust to its provider. See which no-logs claims are actually audited, or read the honest threat model.