Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.
Every provider claims it keeps no logs. So we counted how many have let anyone check.
Eleven of the twenty-three providers we review have one audit or none. Seven have never commissioned one at all. Between all twenty-three, the total comes to fifty-two published reports.
And two providers account for eighteen of those fifty-two. The distribution is the finding.
What We Counted, and How
Twenty-three providers, from our own audit table. That table lists every service we have reviewed, with the number of published no-logs audits, the firm that conducted them, and the jurisdiction.
Only published no-logs audits count here. Not penetration tests, not application reviews, not store verification badges — the distinction matters and we set it out separately.
⚠️ Two entries resist counting. Mullvad publishes annually and the total exceeds ten, so we count it as ten. TunnelBear publishes annually since 2017 without a running total, so it sits outside the arithmetic.
Where sources disagree, the table says so. One provider’s auditor is named differently by different accounts, and we record both.
The Distribution
Seven providers: no audit ever. Hotspot Shield, AirVPN, PrivadoVPN, TorGuard, StrongVPN, PrivateVPN and ZoogVPN.
Four providers: exactly one. Windscribe, Hide.me, FastestVPN and VyprVPN. In one of those cases the single report dates from 2018 and predates a change of owner and country.
Six providers: two or three. That is the commercial middle of the market.
⚠️ And two providers hold eighteen reports between them. Mullvad and IVPN, neither of which sells on convenience. One of them pays no affiliate commission at all.

Who Does the Checking
Four firms cover eleven of the sixteen audited providers. Deloitte appears four times, Cure53 three, and KPMG and Leviathan Security twice each.
So the verification layer is more concentrated than the market it checks. A reader comparing two providers is often comparing two reports by the same firm.
⚠️ The auditor’s identity is part of what a report is worth. One firm appears twice among providers holding a single report each, and it is not a name that appears anywhere else in our table.
Five more firms appear once each. Securitum, Schellman, VerSprite, Packetlabs and Assured AB — each attached to one provider.

Where Two Weaknesses Overlap
Nine of the twenty-three operate from Five Eyes countries. That is not a finding on its own, because architecture matters more than jurisdiction.
But three providers combine both gaps. Hotspot Shield, TorGuard and StrongVPN have no audit and a United States base.
⚠️ That pairing is the one worth noticing. No independent verification, and a legal framework with real reach — as the Apple case shows for a comparable power.
AirVPN is the defensible exception among the unaudited. It has published no report, and its client is open source instead. That is a different kind of evidence rather than an absence of it.

What the Numbers Do Not Show
An audit count is not a ranking. Four reports from a firm nobody recognises are worth less than one from a firm everybody does.
Nor does a count show age. A single audit from 2018 describes a company that has since changed owner and country, which is a different claim from a report published last year.
⚠️ And audits do not test what courts test. Three providers in this table have faced subpoenas or a police search, and those outcomes tell you something no scheduled report can.
Ownership sits underneath all of it. Two groups hold five of these brands, and some parents also own publications that review VPNs — our ownership map traces every one.
The Full Table
Every provider we review, with its audit count, its auditor and its jurisdiction. This is the dataset the figures above come from.
| Provider | No-logs audits | Auditor | Jurisdiction |
|---|---|---|---|
| NordVPN | 6 | PwC, Deloitte | Panama |
| Surfshark | 2 | Deloitte | Netherlands (9 Eyes) |
| ExpressVPN | 3 | KPMG | British Virgin Islands, Kape-owned |
| CyberGhost | 3 | Deloitte | Romania, Kape-owned |
| PureVPN | 4 | KPMG | BVI, operated from Pakistan |
| IPVanish | 2 | Leviathan, Schellman | United States (Five Eyes), Ziff Davis-owned |
| Windscribe | 1 | Packetlabs, production infrastructure | Canada (Five Eyes); Greek case dismissed, no data to give |
| Proton VPN | 5 | Securitum | Switzerland, moving infrastructure to EU |
| Private Internet Access | 3 | Deloitte | United States (Five Eyes), Kape-owned |
| Mullvad | 10+ | Cure53, Assured AB | Sweden (14 Eyes) |
| TunnelBear | Annual since 2017 | Cure53 | Canada (Five Eyes), US parent |
| Norton VPN | 2 | VerSprite | United States (Five Eyes) |
| Hotspot Shield | 0 | protocol audited, policy not | United States (Five Eyes) |
| AirVPN | 0 | none — the client is open source instead | Italy (14 Eyes) |
| IVPN | 8, annual since inception | Cure53 | Gibraltar (status disputed) |
| Hide.me | 1 modern, in 2024 | Securitum, though one source names Altius IT | Malaysia (outside the alliances) |
| PrivadoVPN | 0 | none in six years of operation | Iceland (moved from Switzerland, 2026) |
| TorGuard | 0 | none; settled a lawsuit without disclosing records | United States (Five Eyes) |
| FastestVPN | 1, in 2023 | Altius IT | Cayman Islands (outside the alliances) |
| StrongVPN | 0 | none in over two decades | United States (Five Eyes), Ziff Davis-owned |
| VyprVPN | 1, in 2018 | Leviathan Security, before the 2023 sale | United States (Five Eyes), Certida-owned since 2023 |
| PrivateVPN | 0 | none; support says there is nothing to audit | Sweden (14 Eyes), ownership disputed |
| ZoogVPN | 0 | none; support describes one as planned | Greece (outside the alliances), run from Ukraine |
⚠️ It changes. Providers commission audits, companies change hands, and jurisdictions move — three providers in this table relocated during 2026 alone. So treat any count, including ours, as accurate on the date shown.
How We Research
Every figure on this page comes from our own audit table, which we maintain across all twenty-three reviews and which lists sources in each individual review rather than here. We count only published no-logs audits. Mullvad publishes annually with a total above ten, and we count ten; TunnelBear publishes annually without a stated total and sits outside the arithmetic. Where accounts disagree on an auditor’s identity, the table records both versions. We do not commission audits, run tests or verify reports ourselves — we read what providers publish and record what they do not. Our method lives on the About Us page.
VPN Audits FAQ
Of the twenty-three providers we review, sixteen have published at least one no-logs audit and seven have published none. Eleven have one report or none at all, which is just under half the group.
Mullvad, which publishes annually and has done for over a decade, followed by IVPN with eight. Between them those two account for eighteen of the fifty-two reports in our table. Neither sells on convenience, and one pays no affiliate commission.
Seven in our table: Hotspot Shield, AirVPN, PrivadoVPN, TorGuard, StrongVPN, PrivateVPN and ZoogVPN. AirVPN is the defensible case, since its client is open source instead. The others rest on their policy pages.
No. The auditor’s reputation, the scope of the work and the age of the report all matter. A single recent audit by a well-known firm says more than several old ones by a firm nobody recognises, and a court test says something no audit can.
A small number of firms. Deloitte covers four providers in our table, Cure53 three, and KPMG and Leviathan Security two each — eleven of the sixteen audited providers between them. Five further firms appear once each.
The Verdict
Almost half the market has one report or none. Eleven providers of twenty-three, and seven of those have never been checked at all.
The top of the market is thin too. Two providers hold eighteen of the fifty-two reports, and four firms do most of the checking.
So the useful question is not whether a provider claims no logs. Every one does. Ask who checked, when, and whether the report is public.
