Skip to main content

Home › Research › Questions › Which VPNs have third-party security audits?

Citation-friendly answer

Which VPN providers have a third-party audit record?

This page is generated from the canonical independent_security_audit field. It does not add facts outside that dataset.

Direct answer

The dataset contains 5 provider records with a value for this question. 5 records are marked verified or partially verified, while 0 are provider claims.

Evidence table

Which VPNs have third-party security audits? evidence records
ProviderValueStatusSourceLast verified
NordVPNNordVPN's Trust Center describes recurring external assessments and app-security testing

Separate from the no-logs field; the named report scope and audit dates are not extracted here.

Partially verifiedNordVPN Trust CenterVerified 7 days ago (2026-09-20)
Proton VPNProton describes independent security audits of its open-source apps and publishes audit reports

App-security audits and server-side no-logs audits remain separate evidence streams.

Partially verifiedProton VPN app security auditsVerified 7 days ago (2026-09-20)
SurfsharkSurfshark's Trust Center lists a 2026 Cure53 infrastructure and Dausos audit plus 2025 SecuRing infrastructure and application assessments

Separate from no-logs assurance; the source describes scope at a high level and links the full reports.

Partially verifiedSurfshark Trust CenterVerified 7 days ago (2026-09-20)
MullvadMullvad's audit archive lists 2026 Android, GotaTun and account/payment security assessments, plus a 2024 Cure53 infrastructure audit

The archive identifies target and publication date for each entry; individual report findings are not collapsed into a security certification.

Partially verifiedMullvad security audits archiveVerified 7 days ago (2026-09-20)
ExpressVPNExpressVPN's Trust Center lists 2026 Cure53 product audits, 2025 KPMG privacy commitments, and multiple protocol/app audits

Separate from no-logs evidence; the page includes audits of products, apps, protocols and privacy commitments with different scopes.

Partially verifiedExpressVPN Trust CenterVerified 7 days ago (2026-09-20)
CyberGhostUnknown

No structured evidence record is currently attached for this field.

UnknownSource not attachedNot yet verified
Private Internet AccessUnknown

No structured evidence record is currently attached for this field.

UnknownSource not attachedNot yet verified

Important caveats

A security audit has a scope, date, exclusions and target. A linked provider archive is not a blanket security certification or a no-logs finding.

Methodology

Only the canonical independent_security_audit field is aggregated. No-logs audit records are kept in a separate field because the two audit types answer different questions.

Read sources and limitations

Sources

Last updated: 2026-09-21 · Unknown values are not negative answers.