Home › Research › Questions › Which VPNs have third-party security audits?
Which VPN providers have a third-party audit record?
This page is generated from the canonical independent_security_audit field. It does not add facts outside that dataset.
Direct answer
The dataset contains 5 provider records with a value for this question. 5 records are marked verified or partially verified, while 0 are provider claims.
Evidence table
| Provider | Value | Status | Source | Last verified |
|---|---|---|---|---|
| NordVPN | NordVPN's Trust Center describes recurring external assessments and app-security testing Separate from the no-logs field; the named report scope and audit dates are not extracted here. | Partially verified | NordVPN Trust Center | Verified 7 days ago (2026-09-20) |
| Proton VPN | Proton describes independent security audits of its open-source apps and publishes audit reports App-security audits and server-side no-logs audits remain separate evidence streams. | Partially verified | Proton VPN app security audits | Verified 7 days ago (2026-09-20) |
| Surfshark | Surfshark's Trust Center lists a 2026 Cure53 infrastructure and Dausos audit plus 2025 SecuRing infrastructure and application assessments Separate from no-logs assurance; the source describes scope at a high level and links the full reports. | Partially verified | Surfshark Trust Center | Verified 7 days ago (2026-09-20) |
| Mullvad | Mullvad's audit archive lists 2026 Android, GotaTun and account/payment security assessments, plus a 2024 Cure53 infrastructure audit The archive identifies target and publication date for each entry; individual report findings are not collapsed into a security certification. | Partially verified | Mullvad security audits archive | Verified 7 days ago (2026-09-20) |
| ExpressVPN | ExpressVPN's Trust Center lists 2026 Cure53 product audits, 2025 KPMG privacy commitments, and multiple protocol/app audits Separate from no-logs evidence; the page includes audits of products, apps, protocols and privacy commitments with different scopes. | Partially verified | ExpressVPN Trust Center | Verified 7 days ago (2026-09-20) |
| CyberGhost | Unknown No structured evidence record is currently attached for this field. | Unknown | Source not attached | Not yet verified |
| Private Internet Access | Unknown No structured evidence record is currently attached for this field. | Unknown | Source not attached | Not yet verified |
Important caveats
A security audit has a scope, date, exclusions and target. A linked provider archive is not a blanket security certification or a no-logs finding.
Methodology
Only the canonical independent_security_audit field is aggregated. No-logs audit records are kept in a separate field because the two audit types answer different questions.
Read sources and limitationsSources
Last updated: 2026-09-21 · Unknown values are not negative answers.