Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.
ExpressVPN audit numbers lead every provider in our tables: 27 independent audits by May 2026, the company announced, which it says is more than any other VPN provider. They span PwC’s 2019 review of its privacy policy and TrustedServer and three KPMG assurance reports on its no-logs claims. Many more are Cure53 security audits of Lightway, apps, browser extensions, Aircove routers and newer products. Each type checks something different.
This guide lists the audits by auditor, explains what each kind proves and does not, and shows how ExpressVPN compares.
The ExpressVPN Audit Count
ExpressVPN announced its 27th independent audit on 28 May 2026, when Cure53 reviewed ExpressMailGuard and Identity Defender, TechRadar reported. Cure53 found 13 issues in the first and 11 in the second, with no critical findings, TechRadar added.
Counts from other sites lag behind: vpnMentor reported the 23rd in July 2025 and one 2026 review cited 19 or more. Our VPN audit tracker explains why counts vary between sources. vpnMentor belongs to Kape, which also owns ExpressVPN, so we weigh its findings alongside independent sources.

No-Logs Assurance: PwC and KPMG
PwC Switzerland reviewed ExpressVPN’s privacy policy compliance and TrustedServer in June 2019, and its build verification process in June 2020, ExpressVPN’s Trust Center lists. KPMG followed with assurance reports, including one as at 12 December 2023.
The third KPMG report, covering 28 February 2025, used the ISAE (UK) 3000 Type 1 standard, vpnMentor reported. It gave reasonable assurance that the systems prevented activity logging. Type 1 checks design at a point in time, not operation over a period.
Security Testing: Cure53
Cure53 has audited Lightway four times, most recently in October 2024, and TrustedServer in May 2022, the Trust Center lists. It has also checked the browser extension three times, the ExpressKeys password manager, and the Aircove routers twice.
In 2026 it reviewed ExpressAI, ExpressKeys’ architecture, EventVPN, Identity Defender and ExpressMailGuard, alongside the older VPN components. These are security tests: they look for flaws an attacker could use, rather than certifying a logging policy.

Other Auditors
F-Secure audited the Windows app version 12 in April 2022, the Trust Center lists, and vpnMentor also names Praetorian among past auditors. That spread of firms means no single auditor’s method shapes the whole record. TechRadar notes ExpressVPN holds four ISO certifications as well.
Certifications check management processes rather than code, so they complement audits rather than replace them. They show how the company runs security, not whether a given app has flaws. Our no-logs policies guide explains which audits prove what.
What the Audits Do Not Prove
A point-in-time assurance report shows the system’s design prevented logging on that date; it cannot prove what happened before or after. Security audits find flaws but do not guarantee none remain. Neither kind tells you how a provider would respond to a legal demand.
ExpressVPN publishes the reports on its Trust Center, so you can read the scope of each one. Read the scope first; it tells you what the auditor set out to check, and what it left out.
How ExpressVPN Compares
Our tables record six audits for NordVPN, five Securitum audits for Proton VPN, more than 10 for Mullvad and four KPMG reports for PureVPN. ExpressVPN’s 27 lead on count, though the mix includes product security tests as well as no-logs checks. Compare like with like: no-logs reports with no-logs reports.
Kape owns ExpressVPN, CyberGhost and PIA, so audits of one do not cover the others. Our ExpressVPN alternatives guide weighs audits against price.

Other Kape Brands
CyberGhost and PIA, ExpressVPN’s sister brands under Kape, rely on Deloitte: three audits each in our table, plus court records for PIA. ExpressVPN’s own programme is separate and much larger.
Our ExpressVPN vs CyberGhost page compares the two Kape services side by side.
Lightway Under Scrutiny
Cure53 has audited Lightway, ExpressVPN’s own protocol, four times since 2021, the most of any single component in the record. That matters because a custom protocol lacks the wide public review that WireGuard and OpenVPN have.
Lightway now uses post-quantum key exchange by default, our tables record. Our Lightway vs WireGuard guide compares it with the open standard.
Reading an Audit Yourself
Open the report on the Trust Center, then check the auditor, the date, the scope and the standard used. Each report states these on its first pages, before the findings. Look at the findings section for severity ratings and whether the report notes each issue as fixed or still open. Our guide to ExpressVPN safety covers what its audits and history show.
A report with findings is normal; what matters is that ExpressVPN fixed them and the scope covered what you care about. Older reports may describe versions you no longer use, so prefer the newest. Our NordVPN vs ExpressVPN page compares two of the most audited providers.
How We Research
This page draws on ExpressVPN’s Trust Center, its May 2026 audit announcement and KPMG blog post, TechRadar’s report, vpnMentor on the third KPMG audit and our audit tables, which we corrected to the full count. We cross-checked these sources against each other, and where they conflict or something can’t be verified, we say so in the text rather than guessing. We checked time-sensitive figures, including prices in US dollars, on 8 October 2026. The main source we relied on is ExpressVPN’s Trust Center. Our full approach lives on the About Us page.
ExpressVPN Audit FAQ
27 independent audits by May 2026, the company says.
PwC Switzerland in 2019 and KPMG, most recently as at February 2025.
Lightway four times, apps, extensions, routers and newer products.
No; assurance reports cover a point in time.
On ExpressVPN’s Trust Center.
The Verdict
The ExpressVPN audit record is the broadest we track: 27 audits mixing no-logs assurance and security testing. Read the scope of each report to see what it proves.
