RAM-Only VPN Servers: What the Design Does and Does Not Prove
How diskless server design affects local data persistence, what it cannot guarantee, and how to evaluate provider evidence.
Published by: Ahmet Tepe
Source-led article. Provider claims and independent records are kept distinct; no laboratory result is implied unless stated. How this site works →

RAM-only (diskless) VPN servers run their operating system and service state in volatile memory rather than writing it to a local data disk. This can reduce local persistence after shutdown. It does not by itself prove that a VPN keeps no logs or that no information is held by central systems.
What the design can and cannot tell you
A local disk can retain operating-system or application data, depending on configuration. A RAM-only design reduces this particular storage path. It cannot prevent an operator from observing a running server, sending telemetry elsewhere, or retaining records in a control plane or another service. Nor does the label tell you how keys, boot images, monitoring, or administrator access are controlled.
There is no single universal RAM-only boot process. Some environments load an image over a network; other implementations use different provisioning and verification systems. Ask which systems an audit examined rather than assuming signed images or short-lived certificates are present.
Provider examples and scope
- ExpressVPN describes its TrustedServer architecture as RAM-only. Its public material explains that servers load a fresh software stack during startup. Review the provider's current TrustedServer description and the scope and date of any linked audit.
- NordVPN publicly describes RAM-based infrastructure. Its historical breach concerned a rented server in Finland in 2018 and was disclosed in 2019; read the company's incident response alongside independent reporting. The incident does not establish that a diskless design existed at that time.
- Proton VPN documents full-disk encryption for its servers and describes Secure Core as a routing and physical-security feature. Its RAM-only article and Secure Core documentation describe distinct controls; Secure Core should not be described as proof that the entire fleet is diskless.
- Mullvad announced completion of its migration to RAM-only VPN infrastructure in September 2023 in this provider update. This is a dated provider statement; check later disclosures for changes.
These examples describe different controls and statements. They are not a ranking or a guarantee of current security.

Read audits carefully
An audit is evidence about the systems, period, and scope the auditor examined. Look for the auditor, publication date, service or fleet coverage, testing method, exclusions, and whether important findings were resolved. A RAM-only statement and a no-logs audit answer different questions. Neither removes the need to understand accounts, payment records, support systems, telemetry, and legal requests.
A historical server seizure can also be informative, but it should not be retroactively credited to an architecture introduced later. For example, the 2017 Turkey seizure of an ExpressVPN server predates the provider's later TrustedServer rollout; the event is not proof that RAM-only design caused the outcome.
Questions worth asking
- Does “RAM-only” cover every production VPN server or only a subset?
- What data can the running service send to central monitoring, and how long is that data retained?
- What did the most recent independent audit cover, and what did it exclude?
- How are server images, management access, and signing keys protected?
- What account and payment data is retained outside the VPN server?
Treat diskless architecture as one layer in a wider evidence review. See our VPN security checklist and methodology.
Primary references and verification
These sources support the article's core definitions, platform rules or technical claims. Service terms and product behavior can change; links were checked on August 27, 2026.
- ExpressVPN: ExpressVPN Trust Center
Provider-maintained audit and security documentation; independently verify scope.
- NordVPN: NordVPN Trust Center
Provider-maintained audit, ownership and security documentation; independently verify scope.
Read sources and limitations. If a source has changed or a claim needs correction, use the contact page.

Ready to make a decision?
Explore source-based provider profiles and comparisons organized by real-world use case.
Related Posts

Current Cyberattacks in October 2026: NetScaler Zero-Days, Fake AI Brands and Conference Phishing
A source-led October 2026 briefing on exploited Citrix NetScaler VPN gateways, ChatGPT- and Claude-themed phishing, Star Blizzard lures and what a VPN can and cannot do.

Current Cyberattacks in September 2026: Passkey Phishing, AI Fraud and Fake Downloads
A source-led September 2026 briefing on passkey phishing, AI-assisted invoice fraud, fake installers, fake IT support and VPN limits.

Mullvad Is Shutting Down Its Public Encrypted DNS: What Changes Before November 2026?
Mullvad will retire its public encrypted DNS service and sponsor Quad9 instead. Here is who needs to migrate, what browser and Apple users should do, and what does not change.