Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.
Every provider claims to keep no logs. Most now pay an accounting firm to confirm it, and the resulting badge goes on the homepage.
The badge is worth something, but less than it looks. An audit happens on a date the company picks, with a scope the company agrees. The tests that carry more weight are the ones nobody scheduled, and two providers in our own catalogue failed those.
What a No-Logs Policy Actually Claims
Three different things hide under one phrase, and providers rarely separate them.
Activity logs are what you did: sites, files, destinations. Nobody credible claims to keep these.
Connection logs are that you connected: timestamps, the address you came from, the address you were given, session length. This is the category that has unmasked people.
Aggregate data is bandwidth totals and app versions. Almost everyone keeps some, and almost nobody calls it a log.
⚠️ The PureVPN case turned on the middle category. The company said it stored connection data for debugging rather than activity, and that distinction did not help the person it identified.
What an Audit Proves
Worth being precise, because audits are useful and routinely oversold.
The company chooses the firm, the date and the scope. A no-logs audit typically examines configuration and process over a defined window, then reports what the auditors saw.
A good report names its limits. It says which servers were examined, which systems were out of scope, and what the auditors could not verify.
⚠️ A raw audit count tells you less than it looks. Providers advertise totals that mix no-logs work with protocol reviews and application penetration tests. Our own table counts only the no-logs kind, which is why our numbers look smaller than the marketing — and what that count actually shows across the whole market has its own page.
| Provider | No-logs audits | Auditor | Jurisdiction |
|---|---|---|---|
| NordVPN | 6 | PwC, Deloitte | Panama |
| Surfshark | 2 | Deloitte | Netherlands (9 Eyes) |
| ExpressVPN | 3 | KPMG | British Virgin Islands, Kape-owned |
| CyberGhost | 3 | Deloitte | Romania, Kape-owned |
| PureVPN | 4 | KPMG | BVI, operated from Pakistan |
| IPVanish | 2 | Leviathan, Schellman | United States (Five Eyes), Ziff Davis-owned |
| Windscribe | 1 | Packetlabs, production infrastructure | Canada (Five Eyes); Greek case dismissed, no data to give |
| Proton VPN | 5 | Securitum | Switzerland, moving infrastructure to EU |
| Private Internet Access | 3 | Deloitte | United States (Five Eyes), Kape-owned |
| Mullvad | 10+ | Cure53, Assured AB | Sweden (14 Eyes) |
| TunnelBear | Annual since 2017 | Cure53 | Canada (Five Eyes), US parent |
| Norton VPN | 2 | VerSprite | United States (Five Eyes) |
| Hotspot Shield | 0 | protocol audited, policy not | United States (Five Eyes) |
| AirVPN | 0 | none — the client is open source instead | Italy (14 Eyes) |
| IVPN | 8, annual since inception | Cure53 | Gibraltar (status disputed) |
| Hide.me | 1 modern, in 2024 | Securitum, though one source names Altius IT | Malaysia (outside the alliances) |
| PrivadoVPN | 0 | none in six years of operation | Iceland (moved from Switzerland, 2026) |
| TorGuard | 0 | none; settled a lawsuit without disclosing records | United States (Five Eyes) |
| FastestVPN | 1, in 2023 | Altius IT | Cayman Islands (outside the alliances) |
| StrongVPN | 0 | none in over two decades | United States (Five Eyes), Ziff Davis-owned |
| VyprVPN | 1, in 2018 | Leviathan Security, before the 2023 sale | United States (Five Eyes), Certida-owned since 2023 |
| PrivateVPN | 0 | none; support says there is nothing to audit | Sweden (14 Eyes), ownership disputed |
| ZoogVPN | 0 | none; support describes one as planned | Greece (outside the alliances), run from Ukraine |

The Tests Nobody Scheduled
Here is the evidence that cannot be arranged in advance.
Mullvad, April 2023. Six officers from Sweden’s National Operations Department arrived at the Gothenburg office with a search warrant, intending to seize computers holding customer data. They left with nothing, because no such data existed. The chief executive noted it was the first such visit in fourteen years. It is also why Mullvad tops our privacy ranking, which weighs evidence of this kind above everything else. What Swedish law allowed there, and what it never reached, has its own page.
ExpressVPN, 2017. Turkish investigators seized a server during the inquiry into the assassination of ambassador Andrey Karlov and recovered nothing usable. Turkish law aims at providers rather than users, which is how the hardware came into the case.
Private Internet Access, 2016 and 2018. Two federal subpoenas in United States criminal cases produced nothing on both occasions.
Windscribe, Greece, April 2025. Prosecutors charged a co-founder personally rather than the company, after a server was allegedly used in a cybercrime, with Interpol involved. The company states the case was dismissed because it had zero user data to provide. As he put it, a provider cannot hand over what it does not have.
AirVPN, Italy, 2024. It was never tested at all, because it closed its own market rather than accept an obligation to block. That is a different kind of signal, and it arrives without any audit behind it.
TorGuard, United States, 2022. Sued by twenty-five film studios, it settled by blocking a protocol rather than by retaining records, and disclosed no customer data throughout. Less a test it passed than one it negotiated. Evidence of this kind is what our main ranking scores under security and privacy.

The Two That Failed
This is the part the industry prefers not to list, and it matters more than any badge.
PureVPN supplied connection logs to the FBI in October 2017. Court documents in a cyberstalking case showed that its records linked two email accounts to the same shared address, which identified the suspect. The company said it had kept login data for debugging rather than activity logs.
IPVanish handed user connection information to Homeland Security in 2016. The disclosure emerged in 2018, and the company had advertised zero logs throughout.
⚠️ Both are fair to raise and unfair to leave unqualified. IPVanish changed hands afterwards, and PureVPN commissioned independent audits in response. Neither incident is current behaviour, and both are the reason to ask what a provider did before the badge existed — we put that question to PureVPN and PIA side by side, since one failed and the other passed twice.
RAM-Only, and the Provider Who Disagrees
The other claim that appears on every homepage deserves the same scrutiny.
Servers running from volatile memory keep nothing across a reboot. Seize the hardware and there is no disk to read, which is exactly what made the Turkish seizure uneventful.
⚠️ Proton VPN calls it marketing hype. Its argument is that a running server’s memory is just as readable to anyone with root access, so the protection applies to physical seizure rather than to intrusion. That is a minority position from a provider with five published audits, and it is worth hearing — though the jurisdiction behind those audits is being rewritten.
What to Look For
Five things, in the order they tell you something.
A report you can actually read, rather than a summary of one behind a login.
A named firm and a named scope. Deloitte, KPMG, PwC, Cure53 and Securitum all publish differently, and the scope matters more than the logo — sometimes even the auditor’s name is reported two ways.
A date within the last two years. An audit from 2019 describes a company that may no longer exist in the same form, and one provider commissions a fresh one every year rather than pointing back at an old report.
A transparency report listing how many requests arrived and what was handed over.
Ownership, which decides who benefits from the answer. Two of the providers with the strongest audit records share a parent, and that is worth knowing alongside the reports.

How We Research
This page draws on Mullvad’s own blog post of April 2023 and reporting by Gizmodo, TechRadar, PCMag and Hackread for the Gothenburg search warrant, on TechRadar for the dismissal of the Greek case against Windscribe’s founder, on VPN.com and Gizmodo for the 2017 Turkish server seizure, on CyberInsider and VPNpro for the two PIA subpoenas, on Protectstar and vpntesting for the PureVPN disclosure of October 2017 and the IPVanish disclosure that emerged in 2018, and on Proton VPN’s published position on RAM-only infrastructure. Audit counts and jurisdictions come from our own table, which counts no-logs work only. We do not run our own tests, and where our table disagrees with an outside source we use ours. Our full method lives on the About Us page.
No-Logs FAQ
It usually means no activity logs — no record of the sites you reached. Connection logs are the category that matters legally, because timestamps and address pairs can identify someone when cross-referenced. Aggregate data such as bandwidth totals is kept by almost everyone and rarely described as logging.
They are useful and limited. The provider chooses the auditor, the date and the scope, then decides how much of the report to publish. A good audit names what it could not verify. Counting audits tells you little, because totals often mix no-logs work with protocol and application testing.
Among the providers we review, four have faced unscheduled tests and had nothing to hand over: Mullvad in a 2023 police visit, ExpressVPN in a 2017 server seizure in Turkey, Private Internet Access in two federal subpoenas, and Windscribe in an April 2025 Greek prosecution of a co-founder, dismissed because the company had no user data to provide.
Yes. PureVPN supplied connection logs to the FBI in October 2017 in a cyberstalking case, and IPVanish provided connection information to Homeland Security in 2016, which came to light in 2018. IPVanish has since changed owners and PureVPN commissioned audits afterwards.
It protects against physical seizure, because nothing persists across a reboot. Proton VPN argues publicly that the protection is oversold, since a running server’s memory is readable to anyone with root access. Both positions are reasonable, and neither replaces a published audit.
The Verdict
An audit is a good sign and a weak proof. It reports what auditors saw, on a date the company chose, within a scope the company agreed.
The unscheduled tests are the ones that separate claims from practice. Mullvad, Windscribe, PIA and ExpressVPN have all been through one and had nothing to hand over. PureVPN and IPVanish had something, and handed it over.
So read the report rather than the badge, check the date, and ask what the provider did in the years before anyone was watching. The wider safety question covers what has actually gone wrong, including the free services that leaked everything they had promised not to keep.
