Skip to main content

Home › Research › Questions › Which VPNs have independent no-logs audits?

Citation-friendly answer

Which VPN providers have independently audited no-logs policies?

This page is generated from the canonical independent_no_logs_audit field. It does not add facts outside that dataset.

Direct answer

The dataset contains 4 provider records with a value for this question. 4 records are marked verified or partially verified, while 0 are provider claims.

Evidence table

Which VPNs have independent no-logs audits? evidence records
ProviderValueStatusSourceLast verified
NordVPNNordVPN's Trust Center says its no-logs claims were independently verified in 2018 and four more times afterward

The page gives a verification history but does not expose each report's scope, exclusions or exact publication dates in this record.

Partially verifiedNordVPN Trust CenterVerified 8 days ago (2026-09-20)
Proton VPNProton VPN describes a fifth consecutive annual Securitum audit of its VPN infrastructure and no-logs policy, with a 2026 report linked

The provider publishes the audit and describes infrastructure, configuration, procedures and staff interviews; this record still does not reproduce the full report.

Partially verifiedProton VPN no-logs auditVerified 8 days ago (2026-09-20)
SurfsharkSurfshark's Trust Center lists Deloitte no-logs assurance reports from 2023 and 2025

The source identifies the report years; the full report scope and exclusions are not extracted here.

Partially verifiedSurfshark Trust CenterVerified 8 days ago (2026-09-20)
MullvadUnknown

The current audit archive lists app, infrastructure and account/payment security audits; no distinct no-logs audit record is extracted.

UnknownSource not attachedNot yet verified
ExpressVPNExpressVPN's Trust Center lists a KPMG privacy-policy audit in December 2023 and a KPMG no-logs audit in September 2022

The provider page lists audit targets and months; full report scope and exclusions are not extracted here.

Partially verifiedExpressVPN Trust CenterVerified 8 days ago (2026-09-20)
CyberGhostUnknown

No structured evidence record is currently attached for this field.

UnknownSource not attachedNot yet verified
Private Internet AccessUnknown

No structured evidence record is currently attached for this field.

UnknownSource not attachedNot yet verified

Important caveats

A linked audit-related source is not the same as a complete audit verification. Scope, exclusions and report date must be extracted before a record can be treated as fully verified.

Methodology

This answer aggregates only the canonical independent_no_logs_audit field. Provider claims and partial source links remain visibly labelled and are not converted into a certification.

Read sources and limitations

Sources

Last updated: 2026-09-21 · Unknown values are not negative answers.