Skip to content
Clearward

Audited no-logs providers · verified Sep 2026

No-logs VPNs: which claims are actually audited

“No-logs” is the most repeated promise in the VPN industry and the least examined. A no-logs policy only means something when an independent auditor has inspected the servers and published a dated report — so here is who has, when, and what the audit actually covered.

On this page

A no-logs VPN is one that keeps no record of what you do online — no browsing history, no DNS queries, and as little connection metadata as the service can function on. The problem is that every VPN says this, so the words on their own are worthless. What separates a real no-logs provider from a marketing slogan is evidence: an independent audit that names a firm and a date, and, in a handful of cases, a court order or police seizure that produced nothing. This page is built entirely around that evidence.

Before you trust any of it, keep the honest frame in mind: a VPN moves your trust from your internet provider to the VPN company. It does not make you anonymous. If you want the full picture of what a VPN does and does not protect, read the honest threat model. If you already understand the trade, read on.

What “no-logs” actually means

There are two kinds of logs, and “no-logs” only counts if a provider keeps neither. Activity logs are the sites you visit, the DNS lookups you make and the content of your traffic — the truly sensitive record. Connection (metadata) logs are timestamps, session length, bandwidth used, the server you picked and your real source IP. A genuine no-logs service keeps no activity logs and minimises connection logs to nothing that can identify a session after it ends.

The trick many providers play is to say “no-logs” while quietly keeping connection metadata — the kind of data that, combined with a timestamp from a website, can still tie an account to an action. That is why the wording of a policy matters less than the scope of its audit: did the auditor read the written policy, or did they inspect the live servers and the code that runs them?

There is a legitimate grey area worth naming honestly. Some providers keep temporary, aggregated figures — the total number of active connections on a server, or bandwidth totals — for capacity planning, and wipe them constantly. That is not the same as logging your activity, and a good audit will say exactly what is retained and for how long. The line that matters is whether anything kept could ever be traced back to a specific person and a specific session. When a report cannot answer that plainly, treat the claim as unproven rather than false — and look for a provider whose report can.

Why an audit is the only thing that makes it credible

An independent audit is the only reason to believe a no-logs claim, because it replaces the company's word with an outside expert's. The firms doing this work are named and reputable: the Big Four accountancy firms Deloitte and KPMG, and specialist security labs such as Cure53, Securitum and Assured. When one of them signs a report, they are staking their own name on it.

An audit is a snapshot, not a warranty. Most no-logs audits are “reasonable assurance” engagements (ISAE 3000) that verify the setup at one moment in time, within a scope the provider agreed to. A report from 2024 does not prove anything about a server rebuilt in 2026, and a policy-only review proves far less than a live server inspection. Always check the date and read what the audit says it examined.

We unpack how to read one of these reports — and the words that should make you suspicious — in what a no-logs policy really means.

The audited no-logs providers, compared

The table below is ordered by how well-verified each provider's no-logs claim is — most-tested first — not by “best VPN overall”. Every audit date was checked on 10 September 2026; audits run on an annual cadence, so treat these as “latest known” and click through to each provider's own report before relying on it. The final column is the one most review sites hide: whether the provider pays us anything.

Audited no-logs VPNs — auditor, date and scope (verified 2026-09-10)
ProviderLatest independent auditWhat it coveredRAM-onlyCourt / seizure testPays us?
MullvadAssured AB, 2025 (+ Cure53 apps)Infrastructure + appsYes2023 police raid — nothing to seizeNo program
IVPNCure53, 2025 (7th annual)Apps + infrastructureYes—No program
Proton VPNSecuritum, 2025 (4th)No-logs; apps open-sourcePartial—Yes (disclosed)
NordVPNDeloitte, 2026 (annual)No-logs auditYes—Yes (disclosed)
Private Internet AccessDeloitte, 2024–25No-logs; apps open-sourceYes2016 & 2018 subpoenas — nothingYes (disclosed)
ExpressVPNKPMG 2023; Cure53TrustedServer no-logsYes2017 Turkey seizure — no logsYes (disclosed)
SurfsharkDeloitte, 2025No-logs auditYes—Yes (disclosed)
CyberGhostDeloitte, 2025 (3rd)No-logs auditYes—Yes (disclosed)
TunnelBearCure53, annual since 2017Apps + backend——Yes (disclosed)

A note on ownership, because it is a trust issue in this niche: NordVPN and Surfshark share one parent (Nord Security); ExpressVPN, CyberGhost and Private Internet Access are all owned by Kape Technologies, which also owns several “independent” VPN review sites. That does not make their audits fake — the reports are real — but it is why we lean on named auditors and court records rather than editorial badges.

When a no-logs claim was actually tested

A no-logs claim is strongest when it has survived a real demand for data, and this has happened only a handful of times. In January 2017, Turkish investigators seized an ExpressVPN server during the inquiry into the assassination of Russian ambassador Andrei Karlov and found no activity or connection logs on it. Private Internet Access was subpoenaed by US authorities in 2016 and again in June 2018 and had nothing to hand over both times. In April 2023 Swedish police raided Mullvad's Gothenburg office intending to seize customer data and left with none, because none exists.

These three cases are the closest thing the industry has to proof, and they matter far more than any marketing. We lay out each one — who, when and what happened — in the no-logs court cases, in detail. Note how few there are: “court-proven” is a phrase to check, not to take on faith.

RAM-only servers: why they matter

RAM-only servers run the entire operating system in volatile memory, so a reboot or power cut erases everything — there is no hard drive to seize or subpoena. ExpressVPN pioneered the approach with its TrustedServer design in 2019, and NordVPN, Surfshark, Private Internet Access, CyberGhost and Mullvad have all moved to diskless infrastructure since. It is a genuine improvement over storing data on disk, but it is not magic: a server that is compromised while it is running can still be watched live. We explain the limits in how RAM-only VPN servers work.

Jurisdiction, warrant canaries and the fine print

Where a company is based decides which governments can compel it and gag it, which is why the 5, 9 and 14 Eyes alliances come up so often. But jurisdiction is a weaker signal than people think: an audited no-logs provider has nothing to compel no matter where it sits, while a “privacy-friendly country” that quietly logs is worse than a US company that does not. A warrant canary — a routinely updated statement that no secret order has arrived — is a nice-to-have, but its legal force is untested. A plain transparency report is more useful.

How to choose a no-logs VPN

Run any provider through this checklist before you trust it:

  1. There is a named independent audit — with a firm and a date you can find, not a vague “independently audited” line.
  2. The audit inspected servers or infrastructure, not only the written policy.
  3. The most recent report is within the last year or two, since audits are point-in-time.
  4. The infrastructure is RAM-only, so there is nothing persistent to seize.
  5. Bonus points for open-source apps and a real transparency report — and for a claim that has actually been tested by a court or a seizure.

Our picks — including the ones that pay us nothing

For privacy above all else we recommend Mullvad and IVPN. Both collect almost nothing, run audited diskless infrastructure, accept anonymous payment, and neither runs an affiliate programme — so we earn exactly nothing by naming them. That is the point: when a recommendation cannot make us money, you can be more confident it is honest. Mullvad's flat account-number sign-up (no email required) and its 2023 police-raid record make it the clearest example of no-logs done properly.

If you want an audited provider with a usable free tier, Proton VPN is the pick — four Securitum no-logs audits (the latest in 2025), open-source apps, and a Swiss company transparent enough that it publicly moved infrastructure to Germany and Norway when Swiss surveillance law tightened. That link is an affiliate link; Proton pays us a commission and it does not change where it sits on this page. Check current pricing before you buy, since VPN prices are region- and term-specific and change often.

Among the large mainstream providers, NordVPN (annual Deloitte audits, diskless servers) and Private Internet Access (audited, open-source, and subpoenaed twice with nothing to give) are the most defensible on the evidence. Both links are affiliate links, disclosed. What none of these providers can offer — and what no VPN can — is anonymity; they can only offer a well-audited promise to keep nothing.

The rest of the audited field is fine, with caveats. Surfshark and CyberGhost both publish recent Deloitte no-logs audits, and TunnelBear has the longest unbroken audit history of anyone — a Cure53 report every year since 2017. The caveat is ownership: Surfshark shares a parent with NordVPN, CyberGhost is a Kape brand alongside ExpressVPN and PIA, and TunnelBear belongs to McAfee. None of that voids their audits, but it is the reason we keep pointing you back to the named report and the court record rather than to a star rating. Read the audit; do not read the adjectives.

No-logs VPN questions

What is the most private no-logs VPN?
For privacy specifically, Mullvad and IVPN are the strongest picks: both keep almost no data, run audited diskless infrastructure, accept anonymous payment and run no affiliate programme. Mullvad's no-data record was demonstrated when Swedish police raided its office in 2023 and found nothing to seize.
Does a no-logs VPN mean I am anonymous?
No. A no-logs VPN means the provider keeps no record of your activity, which limits what can be handed over later. It does not make you anonymous — the sites you log into still know who you are, and your browser can still be fingerprinted. A VPN shifts trust to the provider; it does not erase you.
Which VPNs have actually proven their no-logs claim?
Three cases stand out. Turkish authorities seized an ExpressVPN server in 2017 and found no logs; Private Internet Access was subpoenaed in 2016 and 2018 with nothing to produce; and Swedish police raided Mullvad in 2023 and left empty-handed. These real-world tests are stronger evidence than any marketing claim.
How often should a no-logs VPN be re-audited?
At least once a year, because audits are point-in-time snapshots. The strongest providers publish a fresh independent report annually — Proton VPN, NordVPN, Surfshark, CyberGhost and TunnelBear all do. If the most recent audit you can find is several years old, treat the claim as stale.
Is a free no-logs VPN safe?
Some are and many are not. A few reputable providers offer audited free tiers, but a large number of free VPNs — including several China-owned apps with tens of millions of downloads — monetise by logging or selling data. If a free VPN has no independent audit and no clear owner, assume it is the product, not the tool.