The State of VPN Audits (2026): Half the Market Has One Report or None

Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.

Every provider claims it keeps no logs. So we counted how many have let anyone check.

Eleven of the twenty-three providers we review have one audit or none. Seven have never commissioned one at all. Between all twenty-three, the total comes to fifty-two published reports.

And two providers account for eighteen of those fifty-two. The distribution is the finding.

What We Counted, and How

Twenty-three providers, from our own audit table. That table lists every service we have reviewed, with the number of published no-logs audits, the firm that conducted them, and the jurisdiction.

Only published no-logs audits count here. Not penetration tests, not application reviews, not store verification badges — the distinction matters and we set it out separately.

⚠️ Two entries resist counting. Mullvad publishes annually and the total exceeds ten, so we count it as ten. TunnelBear publishes annually since 2017 without a running total, so it sits outside the arithmetic.

Where sources disagree, the table says so. One provider’s auditor is named differently by different accounts, and we record both.

The Distribution

Seven providers: no audit ever. Hotspot Shield, AirVPN, PrivadoVPN, TorGuard, StrongVPN, PrivateVPN and ZoogVPN.

Four providers: exactly one. Windscribe, Hide.me, FastestVPN and VyprVPN. In one of those cases the single report dates from 2018 and predates a change of owner and country.

Six providers: two or three. That is the commercial middle of the market.

⚠️ And two providers hold eighteen reports between them. Mullvad and IVPN, neither of which sells on convenience. One of them pays no affiliate commission at all.

How published no-logs audits are distributed across the twenty-three providers we review

Who Does the Checking

Four firms cover eleven of the sixteen audited providers. Deloitte appears four times, Cure53 three, and KPMG and Leviathan Security twice each.

So the verification layer is more concentrated than the market it checks. A reader comparing two providers is often comparing two reports by the same firm.

⚠️ The auditor’s identity is part of what a report is worth. One firm appears twice among providers holding a single report each, and it is not a name that appears anywhere else in our table.

Five more firms appear once each. Securitum, Schellman, VerSprite, Packetlabs and Assured AB — each attached to one provider.

Which audit firms check which share of the VPN market, by number of providers
See NordVPN Plans →
Six scheduled audits, by two different firms

Where Two Weaknesses Overlap

Nine of the twenty-three operate from Five Eyes countries. That is not a finding on its own, because architecture matters more than jurisdiction.

But three providers combine both gaps. Hotspot Shield, TorGuard and StrongVPN have no audit and a United States base.

⚠️ That pairing is the one worth noticing. No independent verification, and a legal framework with real reach — as the Apple case shows for a comparable power.

AirVPN is the defensible exception among the unaudited. It has published no report, and its client is open source instead. That is a different kind of evidence rather than an absence of it.

The seven providers with no audit, and the three that also operate from Five Eyes countries

What the Numbers Do Not Show

An audit count is not a ranking. Four reports from a firm nobody recognises are worth less than one from a firm everybody does.

Nor does a count show age. A single audit from 2018 describes a company that has since changed owner and country, which is a different claim from a report published last year.

⚠️ And audits do not test what courts test. Three providers in this table have faced subpoenas or a police search, and those outcomes tell you something no scheduled report can.

Ownership sits underneath all of it. Two groups hold five of these brands, and some parents also own publications that review VPNs — our ownership map traces every one.

The Full Table

Every provider we review, with its audit count, its auditor and its jurisdiction. This is the dataset the figures above come from.

ProviderNo-logs auditsAuditorJurisdiction
NordVPN6PwC, DeloittePanama
Surfshark2DeloitteNetherlands (9 Eyes)
ExpressVPN3KPMGBritish Virgin Islands, Kape-owned
CyberGhost3DeloitteRomania, Kape-owned
PureVPN4KPMGBVI, operated from Pakistan
IPVanish2Leviathan, SchellmanUnited States (Five Eyes), Ziff Davis-owned
Windscribe1Packetlabs, production infrastructureCanada (Five Eyes); Greek case dismissed, no data to give
Proton VPN5SecuritumSwitzerland, moving infrastructure to EU
Private Internet Access3DeloitteUnited States (Five Eyes), Kape-owned
Mullvad10+Cure53, Assured ABSweden (14 Eyes)
TunnelBearAnnual since 2017Cure53Canada (Five Eyes), US parent
Norton VPN2VerSpriteUnited States (Five Eyes)
Hotspot Shield0protocol audited, policy notUnited States (Five Eyes)
AirVPN0none — the client is open source insteadItaly (14 Eyes)
IVPN8, annual since inceptionCure53Gibraltar (status disputed)
Hide.me1 modern, in 2024Securitum, though one source names Altius ITMalaysia (outside the alliances)
PrivadoVPN0none in six years of operationIceland (moved from Switzerland, 2026)
TorGuard0none; settled a lawsuit without disclosing recordsUnited States (Five Eyes)
FastestVPN1, in 2023Altius ITCayman Islands (outside the alliances)
StrongVPN0none in over two decadesUnited States (Five Eyes), Ziff Davis-owned
VyprVPN1, in 2018Leviathan Security, before the 2023 saleUnited States (Five Eyes), Certida-owned since 2023
PrivateVPN0none; support says there is nothing to auditSweden (14 Eyes), ownership disputed
ZoogVPN0none; support describes one as plannedGreece (outside the alliances), run from Ukraine

⚠️ It changes. Providers commission audits, companies change hands, and jurisdictions move — three providers in this table relocated during 2026 alone. So treat any count, including ours, as accurate on the date shown.

How We Research

Every figure on this page comes from our own audit table, which we maintain across all twenty-three reviews and which lists sources in each individual review rather than here. We count only published no-logs audits. Mullvad publishes annually with a total above ten, and we count ten; TunnelBear publishes annually without a stated total and sits outside the arithmetic. Where accounts disagree on an auditor’s identity, the table records both versions. We do not commission audits, run tests or verify reports ourselves — we read what providers publish and record what they do not. Our method lives on the About Us page.

VPN Audits FAQ

How many VPNs have been independently audited?

Of the twenty-three providers we review, sixteen have published at least one no-logs audit and seven have published none. Eleven have one report or none at all, which is just under half the group.

Which VPN has the most audits?

Mullvad, which publishes annually and has done for over a decade, followed by IVPN with eight. Between them those two account for eighteen of the fifty-two reports in our table. Neither sells on convenience, and one pays no affiliate commission.

Which VPNs have never been audited?

Seven in our table: Hotspot Shield, AirVPN, PrivadoVPN, TorGuard, StrongVPN, PrivateVPN and ZoogVPN. AirVPN is the defensible case, since its client is open source instead. The others rest on their policy pages.

Does a higher audit count mean a better VPN?

No. The auditor’s reputation, the scope of the work and the age of the report all matter. A single recent audit by a well-known firm says more than several old ones by a firm nobody recognises, and a court test says something no audit can.

Who audits VPN providers?

A small number of firms. Deloitte covers four providers in our table, Cure53 three, and KPMG and Leviathan Security two each — eleven of the sixteen audited providers between them. Five further firms appear once each.

The Verdict

Almost half the market has one report or none. Eleven providers of twenty-three, and seven of those have never been checked at all.

The top of the market is thin too. Two providers hold eighteen of the fifty-two reports, and four firms do most of the checking.

So the useful question is not whether a provider claims no logs. Every one does. Ask who checked, when, and whether the report is public.

See the Ranking Built on This →
Where unaudited providers are excluded, and two of the top three pay us nothing
Scroll to Top