What Is a No-Logs Audit? How to Read One in 2026
Every VPN says it is independently audited. What a no-logs audit actually covers, why one audited provider beats another, and five checks before you trust it.
Published August 27, 2026· By Juan Martinez

Every VPN’s marketing page now carries some version of the same line: independently audited, no-logs verified. It has become table stakes — a provider without an audit looks negligent next to one that has three. But a no-logs audit is not a single thing. Among the 14 VPNs reviewed on this site, the audits behind that phrase differ on who ran them, what they examined, whether you can read the resulting report, how often they happen, and whether the no-logs claim has ever been tested by someone who wanted it to fail. Each of those differences changes how much the audit is worth. This guide walks through what a no-logs audit actually covers and the five things to check before you let one decide your choice.
What a No-Logs Audit Actually Examines
Start with what the auditor is looking at. A no-logs audit is almost never a firm watching a VPN’s servers around the clock. In the typical engagement, the auditor reviews server configuration files, deployment and change-management processes, internal procedures, and staff interviews, and checks whether that setup is consistent with the provider’s stated policy of not recording user activity. Proton VPN’s 2026 engagement, for example, had two Securitum consultants on-site in Zurich reviewing configs, operating procedures, and interviews against ten specific no-logging criteria — activity tracking, metadata logging, the ability to link a user to a server session, and so on.
Most of the larger providers frame this under ISAE 3000 (Revised), an international assurance standard issued by the International Auditing and Assurance Standards Board and effective since December 2015. NordVPN, Surfshark, CyberGhost, and Private Internet Access all cite it; ExpressVPN’s KPMG engagement uses the UK equivalent. The standard is worth understanding because it defines two things that get blurred in marketing copy.
Reasonable assurance versus limited assurance. Under the standard’s own text, a reasonable assurance engagement is one where the practitioner “reduces engagement risk to an acceptably low level” and states the conclusion “in a positive form” — essentially, the systems are designed and operating in line with the no-logs claim. A limited assurance engagement accepts higher risk and produces a conclusion worded negatively: nothing came to our attention to suggest the claim is materially misstated. Both are legitimate; they are not the same level of confidence, and the marketing line “passed an ISAE 3000 audit” doesn’t tell you which one you’re looking at.
Point-in-time versus over-a-period. ExpressVPN’s most recent KPMG report is described as a Type 1 engagement assessed “as of February 28, 2025” — a snapshot of whether the controls were designed and in place on that date. A Type 2 report would additionally test that those controls operated effectively across a period of months. A point-in-time report is a photograph; it says nothing about the day after.
There is also a quieter distinction in the standard between an attestation engagement — where the provider prepares the description of its own controls and the auditor reports on that — and a direct engagement, where the auditor does the measuring. The Big Four no-logs assurance reports are generally the former.
The Audited Providers, Side by Side
Here is how the no-logs audit picture looks across the 14 VPNs reviewed on this site, on the axes that decide an audit’s weight — most transparent reporting at the top, unaudited at the bottom.
| Provider | Most recent no-logs audit | Auditor | Report access | Cadence | Adversarial test |
|---|---|---|---|---|---|
| Proton VPN | 2026 | Securitum | Fully public, no login | 5 consecutive years | — |
| IVPN | 2019 (no-logs specifically); security audits ongoing | Cure53 | Fully public (minor redactions) | Annual since 2019, no gap, rotating scope | — |
| Mullvad | 2024 (infrastructure) | Cure53 | Fully public (minor redactions) | 4 infra audits since 2018 | Swedish police search, 2023 — nothing seized |
| TunnelBear | 2025 (security, white-box) | Cure53 | Public, with full vulnerability counts | 8 consecutive years | — |
| OVPN | 2026 | Cure53 | Public — summary, raw triage, remediation timeline | Periodic | Swedish court case, 2020 — plaintiffs failed to force disclosure |
| ExpressVPN | As of Feb 2025 | KPMG | Gated behind accepting KPMG’s terms | 23 audits since 2018 | — |
| NordVPN | Nov–Dec 2025 | Deloitte (PwC before 2022) | Login-gated to a Nord Account | 6 engagements since 2018 | — |
| Surfshark | 2025 | Deloitte | Login-gated to a Surfshark account | 2 audits (2023, 2025) | — |
| CyberGhost | 2025 | Deloitte | Public summary | 3 audits since 2022 | — |
| Private Internet Access | 2024 | Deloitte | Public summary | 2 audits (2022, 2024) | US court cases 2016 & 2018; Russian server seizure 2016 — no data produced |
| hide.me | Jul 2024 | Securitum | Public | 2 audits, 9 years apart | — |
| Windscribe | Jun 2024 (infrastructure) | Packetlabs | Public reports | 3 public audits | Dutch server seizure, Feb 2026 — company reports nothing usable found |
| IPVanish | Apr 2025 | Schellman (Leviathan in 2022) | Account portal or media request | 2 audits (2022, 2025) | — |
| Astrill | None | — | — | — | — |
The rest of this guide is how to use a table like that — for these providers or any other.
Check 1: Can You Actually Read the Report?
This is the fastest way to sort audited providers, and the gap is wider than most people expect.
Fully public, no login: Proton VPN publishes all five years of its Securitum reports (2022-2026) as direct downloads. IVPN and Mullvad publish their Cure53 reports in full, with only sensitive technical details like internal hostnames redacted.
Login-gated: NordVPN and Surfshark both state that the full ISAE 3000 technical report is available only to logged-in account holders. What’s public is a summary blog post. Outside scrutiny of the actual findings is limited to what the provider chooses to put in that summary.
Terms-and-conditions gated: ExpressVPN’s full KPMG report requires accepting KPMG’s own terms and conditions to view — a lighter gate than an account login, but still not a free download.
Media-request or account-portal gated: IPVanish says customers can retrieve its Leviathan (2022) and Schellman (2025) reports through the account portal, and journalists can request them by email.
When you can’t read the report, “independently audited” collapses back into a claim you’re taking on trust — just a claim with a well-known firm’s name attached to it. That’s not worthless, but it’s a materially weaker thing than a report you or a researcher can open and check.
Check 2: How Often, and Was There a Gap?
A single audit ages. Infrastructure changes, staff turns over, a new logging feature ships. What matters is whether the provider re-audits on a schedule and whether there’s been a long silence.
Annual, no gaps: IVPN has commissioned an audit every year since 2019 without a break — seven completed by mid-2026, with an eighth underway. Proton VPN has five consecutive years. TunnelBear has eight consecutive annual Cure53 audits. Mullvad has run four dedicated infrastructure audits (2018, 2020, 2022, 2024) plus separate app and payment audits.
Every two to three years: CyberGhost has three Deloitte audits since 2022. NordVPN has six assurance engagements since 2018. Surfshark’s no-logs policy has been through two Deloitte audits, 2023 and 2025.
Twice, with a long gap: hide.me’s no-logs claim was audited by Defense Code in 2015 and then not again until Securitum in July 2024 — a nine-year silence. The 2024 audit is real and recent, but it isn’t part of an established cadence.
Once or twice total: Private Internet Access has two Deloitte audits (2022, 2024). Windscribe has three public audits, though only one (Packetlabs, 2024) covers production server infrastructure.
None: Astrill has no independent no-logs audit at all. Its no-logs claim rests entirely on its own privacy policy.
One useful refinement: IVPN and Mullvad rotate audit scope rather than re-running an identical test. IVPN’s first audit (2019) verified the no-logs claim specifically; later years covered the VPN gateway, then the customer website and backend, then the core authentication system. That’s broader coverage over time, but it also means the no-logs claim itself isn’t re-verified every single year — the label “eight audits” doesn’t mean “eight no-logs audits.”
Check 3: Who Ran It, and Does That Match the Question?
Two different kinds of firm show up in VPN audits, and they do different work.
Big Four accounting firms — Deloitte (NordVPN, Surfshark, CyberGhost, PIA), KPMG (ExpressVPN), PwC (NordVPN’s early engagements) — run assurance engagements under ISAE 3000. They’re checking whether a described set of controls exists and is consistent with a policy claim, against an accounting standard. That’s a real, structured discipline, and it’s the right tool for a no-logs policy attestation.
Specialist security firms — Cure53 (Mullvad, IVPN, TunnelBear, OVPN, and Surfshark’s infrastructure), Securitum (Proton VPN, hide.me), Leviathan and Schellman (IPVanish), Packetlabs (Windscribe) — run technical audits and penetration tests, often white-box with full source code and backend access. TunnelBear’s most recent Cure53 engagement ran 44 working days with full code access. That’s a different question: can we break this, and what did we find in the code?
Neither is “better” in the abstract — they answer different questions, and several providers use both. But if a provider’s only audit is a Big Four policy attestation, you have assurance about the policy framework, not a technical review of the implementation, and vice versa. The word “audit” covers both.
Check 4: Has the Claim Ever Been Tested by Someone Hostile?
A commissioned audit is a company paying a firm to check its own work against the company’s own description of that work. It’s a real signal, but it’s cooperative by design. A smaller number of providers have had their no-logs claim tested by a party that wanted to extract user data:
- Private Internet Access — subpoenaed in a 2016 FBI investigation and again in a 2018 federal hacking trial (US v. Colby); in both, PIA produced no identifying user data because it had none to produce. (These are sourced from news reporting, not court documents we’ve fetched directly.)
- Mullvad — on April 18, 2023, at least six Swedish National Operations Department officers arrived at Mullvad’s Gothenburg office with a search warrant seeking customer data. They left with nothing after Mullvad demonstrated the data didn’t exist — the company’s first search-warrant visit in over 14 years, and still its most recent as of mid-2026.
- OVPN — in a 2020 Swedish court case, movie-industry rights holders tried and failed to force OVPN to identify a user; the court found there was nothing to hand over and ordered the plaintiffs to pay OVPN’s legal costs. (This predates OVPN’s 2023 acquisition and the resulting shift to a US-incorporated operating entity.)
- PIA (again) and Windscribe — both had physical servers seized by authorities (PIA in Russia, 2016; Windscribe in the Netherlands, February 2026) and both reported that nothing usable was on them. Windscribe’s is the company’s own account, not independently confirmed.
This kind of evidence isn’t available for most providers, and you can’t manufacture it — it requires an actual subpoena or raid. But where it exists, it tests the thing an audit can only infer: what happens when someone with legal force asks for data the provider says it doesn’t keep.
Check 5: Is a Clean Report Actually the Best Sign?
Not necessarily. TunnelBear publishes the real vulnerability counts from each annual Cure53 audit rather than a blanket “passed” summary: its seventh audit found 7 issues of medium severity or higher out of 13 total; its eighth found 10 medium-or-higher issues plus 3 low-severity — all reported as fixed or mitigated. That’s a bumpier-looking record than the largely clean summaries some other frequently-audited providers publish. It’s also more informative. A provider that shows you what the auditors found and how it responded is giving you more to work with than one that publishes three sentences confirming everything was fine.
OVPN’s 2026 Cure53 audit is a similar case: it published a summary, the raw vulnerability triage, and a public remediation timeline. The findings themselves were minor — logging verbosity in debug builds, removed before release — but the disclosure was unusually complete.
The instinct to read “no issues found” as the gold standard is backwards. What you want is enough detail to judge the finding and the response.
Even a Good Audit Has Edges
IVPN — a provider with one of the most consistent audit records anywhere — announced in June 2026 that it would stop commissioning no-logs audits specifically. Its stated reasoning is worth quoting: “audits are a snapshot in time: any VPN service receiving a no-logs stamp from independent evaluators can update its systems and start collecting sensitive data the following day,” and “some VPN providers cite such audits as a marketing tool that creates a false sense of security.” IVPN still commissions security and infrastructure audits; it’s the no-logs attestation specifically it has soured on.
You don’t have to fully agree with that position to take the point. A no-logs audit tells you about a defined scope, at a defined time, against the provider’s own description of its systems. It doesn’t cover the provider’s email marketing, its parent company’s other businesses, or what changes the week after the auditors leave. It’s one input, not a verdict.
Reading an Audit for a Provider Not on This List
The five checks apply to any VPN:
- Find the actual report. If the only thing you can find is a blog post, that’s your answer to Check 1. A named firm with no readable report is a weaker signal than an unglamorous firm with a full public PDF.
- Check the standard and the assurance level. ISAE 3000 reasonable assurance and a Type 2 (over-a-period) scope is a stronger engagement than limited assurance at a single point in time. The report states which.
- Check the date and the cadence. A 2021 audit with no follow-up is not the same as a 2021 audit followed by 2023 and 2025. A multi-year gap is a real flag.
- Check what was in scope. “No-logs audit” and “security audit” and “app audit” are different engagements. A provider can have several audits and still not have re-verified its no-logs claim recently.
- Look for adversarial evidence. Court cases, subpoena responses, and server seizures that produced nothing are rarer and harder to fake than a commissioned report. Where they exist, weight them.
A VPN that has been audited is doing more than one that hasn’t. But the phrase on the marketing page is the start of the question, not the end of it — and once you know what to look for, the audited providers sort themselves into clearly different tiers. If you want the fullest disclosure available today, Proton VPN, Mullvad, and IVPN publish their reports in full with no login — and Mullvad and Private Internet Access each add the rarer signal of a claim that held up when someone with legal force came looking.