Audited no-logs providers · verified Sep 2026
No-logs VPNs: which claims are actually audited
“No-logs” is the most repeated promise in the VPN industry and the least examined. A no-logs policy only means something when an independent auditor has inspected the servers and published a dated report — so here is who has, when, and what the audit actually covered.
On this page
A no-logs VPN is one that keeps no record of what you do online — no browsing history, no DNS queries, and as little connection metadata as the service can function on. The problem is that every VPN says this, so the words on their own are worthless. What separates a real no-logs provider from a marketing slogan is evidence: an independent audit that names a firm and a date, and, in a handful of cases, a court order or police seizure that produced nothing. This page is built entirely around that evidence.
Before you trust any of it, keep the honest frame in mind: a VPN moves your trust from your internet provider to the VPN company. It does not make you anonymous. If you want the full picture of what a VPN does and does not protect, read the honest threat model. If you already understand the trade, read on.
What “no-logs” actually means
There are two kinds of logs, and “no-logs” only counts if a provider keeps neither. Activity logs are the sites you visit, the DNS lookups you make and the content of your traffic — the truly sensitive record. Connection (metadata) logs are timestamps, session length, bandwidth used, the server you picked and your real source IP. A genuine no-logs service keeps no activity logs and minimises connection logs to nothing that can identify a session after it ends.
The trick many providers play is to say “no-logs” while quietly keeping connection metadata — the kind of data that, combined with a timestamp from a website, can still tie an account to an action. That is why the wording of a policy matters less than the scope of its audit: did the auditor read the written policy, or did they inspect the live servers and the code that runs them?
There is a legitimate grey area worth naming honestly. Some providers keep temporary, aggregated figures — the total number of active connections on a server, or bandwidth totals — for capacity planning, and wipe them constantly. That is not the same as logging your activity, and a good audit will say exactly what is retained and for how long. The line that matters is whether anything kept could ever be traced back to a specific person and a specific session. When a report cannot answer that plainly, treat the claim as unproven rather than false — and look for a provider whose report can.
Why an audit is the only thing that makes it credible
An independent audit is the only reason to believe a no-logs claim, because it replaces the company's word with an outside expert's. The firms doing this work are named and reputable: the Big Four accountancy firms Deloitte and KPMG, and specialist security labs such as Cure53, Securitum and Assured. When one of them signs a report, they are staking their own name on it.
An audit is a snapshot, not a warranty. Most no-logs audits are “reasonable assurance” engagements (ISAE 3000) that verify the setup at one moment in time, within a scope the provider agreed to. A report from 2024 does not prove anything about a server rebuilt in 2026, and a policy-only review proves far less than a live server inspection. Always check the date and read what the audit says it examined.
We unpack how to read one of these reports — and the words that should make you suspicious — in what a no-logs policy really means.
The audited no-logs providers, compared
The table below is ordered by how well-verified each provider's no-logs claim is — most-tested first — not by “best VPN overall”. Every audit date was checked on 10 September 2026; audits run on an annual cadence, so treat these as “latest known” and click through to each provider's own report before relying on it. The final column is the one most review sites hide: whether the provider pays us anything.
| Provider | Latest independent audit | What it covered | RAM-only | Court / seizure test | Pays us? |
|---|---|---|---|---|---|
| Mullvad | Assured AB, 2025 (+ Cure53 apps) | Infrastructure + apps | Yes | 2023 police raid — nothing to seize | No program |
| IVPN | Cure53, 2025 (7th annual) | Apps + infrastructure | Yes | — | No program |
| Proton VPN | Securitum, 2025 (4th) | No-logs; apps open-source | Partial | — | Yes (disclosed) |
| NordVPN | Deloitte, 2026 (annual) | No-logs audit | Yes | — | Yes (disclosed) |
| Private Internet Access | Deloitte, 2024–25 | No-logs; apps open-source | Yes | 2016 & 2018 subpoenas — nothing | Yes (disclosed) |
| ExpressVPN | KPMG 2023; Cure53 | TrustedServer no-logs | Yes | 2017 Turkey seizure — no logs | Yes (disclosed) |
| Surfshark | Deloitte, 2025 | No-logs audit | Yes | — | Yes (disclosed) |
| CyberGhost | Deloitte, 2025 (3rd) | No-logs audit | Yes | — | Yes (disclosed) |
| TunnelBear | Cure53, annual since 2017 | Apps + backend | — | — | Yes (disclosed) |
A note on ownership, because it is a trust issue in this niche: NordVPN and Surfshark share one parent (Nord Security); ExpressVPN, CyberGhost and Private Internet Access are all owned by Kape Technologies, which also owns several “independent” VPN review sites. That does not make their audits fake — the reports are real — but it is why we lean on named auditors and court records rather than editorial badges.
When a no-logs claim was actually tested
A no-logs claim is strongest when it has survived a real demand for data, and this has happened only a handful of times. In January 2017, Turkish investigators seized an ExpressVPN server during the inquiry into the assassination of Russian ambassador Andrei Karlov and found no activity or connection logs on it. Private Internet Access was subpoenaed by US authorities in 2016 and again in June 2018 and had nothing to hand over both times. In April 2023 Swedish police raided Mullvad's Gothenburg office intending to seize customer data and left with none, because none exists.
These three cases are the closest thing the industry has to proof, and they matter far more than any marketing. We lay out each one — who, when and what happened — in the no-logs court cases, in detail. Note how few there are: “court-proven” is a phrase to check, not to take on faith.
RAM-only servers: why they matter
RAM-only servers run the entire operating system in volatile memory, so a reboot or power cut erases everything — there is no hard drive to seize or subpoena. ExpressVPN pioneered the approach with its TrustedServer design in 2019, and NordVPN, Surfshark, Private Internet Access, CyberGhost and Mullvad have all moved to diskless infrastructure since. It is a genuine improvement over storing data on disk, but it is not magic: a server that is compromised while it is running can still be watched live. We explain the limits in how RAM-only VPN servers work.
Jurisdiction, warrant canaries and the fine print
Where a company is based decides which governments can compel it and gag it, which is why the 5, 9 and 14 Eyes alliances come up so often. But jurisdiction is a weaker signal than people think: an audited no-logs provider has nothing to compel no matter where it sits, while a “privacy-friendly country” that quietly logs is worse than a US company that does not. A warrant canary — a routinely updated statement that no secret order has arrived — is a nice-to-have, but its legal force is untested. A plain transparency report is more useful.
How to choose a no-logs VPN
Run any provider through this checklist before you trust it:
- There is a named independent audit — with a firm and a date you can find, not a vague “independently audited” line.
- The audit inspected servers or infrastructure, not only the written policy.
- The most recent report is within the last year or two, since audits are point-in-time.
- The infrastructure is RAM-only, so there is nothing persistent to seize.
- Bonus points for open-source apps and a real transparency report — and for a claim that has actually been tested by a court or a seizure.
Our picks — including the ones that pay us nothing
For privacy above all else we recommend Mullvad and IVPN. Both collect almost nothing, run audited diskless infrastructure, accept anonymous payment, and neither runs an affiliate programme — so we earn exactly nothing by naming them. That is the point: when a recommendation cannot make us money, you can be more confident it is honest. Mullvad's flat account-number sign-up (no email required) and its 2023 police-raid record make it the clearest example of no-logs done properly.
If you want an audited provider with a usable free tier, Proton VPN is the pick — four Securitum no-logs audits (the latest in 2025), open-source apps, and a Swiss company transparent enough that it publicly moved infrastructure to Germany and Norway when Swiss surveillance law tightened. That link is an affiliate link; Proton pays us a commission and it does not change where it sits on this page. Check current pricing before you buy, since VPN prices are region- and term-specific and change often.
Among the large mainstream providers, NordVPN (annual Deloitte audits, diskless servers) and Private Internet Access (audited, open-source, and subpoenaed twice with nothing to give) are the most defensible on the evidence. Both links are affiliate links, disclosed. What none of these providers can offer — and what no VPN can — is anonymity; they can only offer a well-audited promise to keep nothing.
The rest of the audited field is fine, with caveats. Surfshark and CyberGhost both publish recent Deloitte no-logs audits, and TunnelBear has the longest unbroken audit history of anyone — a Cure53 report every year since 2017. The caveat is ownership: Surfshark shares a parent with NordVPN, CyberGhost is a Kape brand alongside ExpressVPN and PIA, and TunnelBear belongs to McAfee. None of that voids their audits, but it is the reason we keep pointing you back to the named report and the court record rather than to a star rating. Read the audit; do not read the adjectives.