No-log VPN audits explained: what they prove

A no-log audit is a point-in-time check: an independent firm — Deloitte, KPMG, Securitum, or Cure53 — examines a VPN's servers and policies and reports whether it found logging. It covers a defined scope on a specific date, not the future. Check the auditor, the year, the scope, and whether the report is public.

Every major VPN claims it keeps no logs. The claim costs nothing to make. What backs it up is a paper trail: a named auditor, a dated report, and a scope statement you can read. Six of the eight providers in our full VPN rankings have commissioned formal no-logs engagements from firms such as Deloitte, KPMG, and Securitum. The other two — Mullvad and Windscribe — hold security audits that answer a different question. Knowing which is which tells you how much weight “independently audited” really carries.

What does a no-log audit actually check?

The auditor tests one thing: whether the provider’s systems match what its privacy policy promises. Depending on scope, that means inspecting live server configurations, change management, incident response, and any system that could store user data. CyberGhost’s 2025 engagement is a concrete example — Deloitte Audit Romania examined the server network, configuration and change management, incident response, and the dedicated-IP token system.

Most big-brand audits run under ISAE 3000 (Revised), an international assurance standard. Deloitte applied it for NordVPN, Surfshark, CyberGhost, and Private Internet Access; KPMG used the UK version for ExpressVPN. Two phrases in these reports carry more meaning than the logo on the cover. “Reasonable assurance” means the auditor collected enough evidence to support its conclusion — useful, but not absolute proof. “As of” pins that conclusion to a defined scope on a specific date, not to every server forever.

Who audited the big VPNs, and when?

No-logs audit status of eight major VPNs (vendor audit pages, as of 23 Jul 2026)
ProviderAuditorLatestEngagement typeFull report
NordVPNDeloitte LithuaniaDec 2025ISAE 3000 no-logs assurance — sixth since 2018Nord Account login required
ExpressVPNKPMG LLP2025 (as of 28 Feb 2025)ISAE (UK) 3000 Type 1 — TrustedServer and no-logs policyGated behind KPMG terms
SurfsharkDeloitte2025ISAE 3000 no-logs assurance — second, after Jan 2023Paying subscribers, logged in
Proton VPNSecuritum2026No-logs infrastructure audit — fifth annual in a rowPublished in full
CyberGhostDeloitte Audit Romania2025ISAE 3000 no-logs audit — third since 2022Downloadable
Private Internet AccessDeloitte Audit Romania2025ISAE 3000 no-logs review — third since 2022Downloadable
Mullvad VPNCure53Jun 2024Infrastructure security audit — not a no-logs attestationNot verified
WindscribePacketlabsJun 2024Server-stack privacy audit and pen test — not a no-logs attestationNot verified

“Not verified” in the last column means public access to the full report is unconfirmed.

Two details the marketing pages tend to bury:

  • Report access varies widely. Proton VPN publishes all five Securitum reports (2022–2026) in full — more on that in our Proton VPN review. CyberGhost and Private Internet Access offer their Deloitte reports as downloads. ExpressVPN gates its KPMG report behind an accept-the-terms screen. NordVPN and Surfshark show theirs only inside a logged-in account — Surfshark to paying users only.
  • Cadence now matters as much as the audit itself. NordVPN’s December 2025 engagement was its sixth no-logs verification since 2018: PwC Switzerland in 2018 and 2020, then Deloitte every year from 2022 to 2025. Proton VPN has run five annual audits in a row. A single audit from years ago is a snapshot, not a habit.

When “audited” does not mean a no-logs attestation

The most recent audit of Mullvad’s no-logging infrastructure is Cure53’s June 2024 engagement — the fourth — scoped, in Mullvad’s words, to “anything that would impact privacy”. Cure53 looked for any way a user’s traffic anonymity or integrity could be compromised and found no such issues. That is real scrutiny. It is still not a formal no-logs attestation: no one signed an assurance opinion that Mullvad’s operations match its policy. Mullvad’s later audits, in 2025 and 2026, covered other components — the web app, the payment and account API, and its apps — so June 2024 remains the freshest independent look at the servers themselves.

Windscribe fits the same pattern. Packetlabs audited and penetration-tested its rebuilt server stack in June 2024, covering RAM-disk servers and defenses against exposing personally identifiable information. No formal no-logs attestation exists; Windscribe instead points to a Greek court case as real-world evidence of what it stores.

Neither type of audit is worthless. A hostile expert probing live infrastructure is stronger evidence than a policy read-through. But “our servers resisted an expert attack” and “our operations match our no-logs policy” are different findings, and vendor marketing rarely tells you which one was bought.

What a clean report cannot prove

  • Anything after the report date. ExpressVPN’s KPMG opinion holds “as of 28 Feb 2025”; NordVPN’s 2025 fieldwork ran from 10 Nov to 12 Dec 2025. Configurations, vendors, and policies can change the week after fieldwork ends. That is why yearly cadence beats any single report.
  • Data outside the scope. These engagements test activity and connection logging. Account and billing records still exist — the provider knows who pays — and some services keep limited connection metadata such as timestamps or server assignments. The privacy policy, not the audit, governs that layer.
  • Tomorrow’s legal orders. No audit can rule out a provider being compelled to start logging. Jurisdiction is the backdrop: Private Internet Access is a US company and Windscribe a Canadian one — both Five Eyes countries — while NordVPN operates from Panama and Proton VPN from Switzerland.
  • Everything upstream of the VPN. Payment processors, app stores, and hosting providers each see fragments of your identity and traffic that no VPN audit reviews.

Five checks before you trust an audit claim

  1. A named auditor. Deloitte, KPMG, Securitum, Cure53, Packetlabs — real firms with reputations to lose. An unnamed “independent third party” is a red flag.
  2. A recent date. The leaders re-audit every year. A report from three or four years back describes servers that may no longer exist.
  3. A scope you can restate. Live infrastructure or paperwork? Which systems — servers, management tooling, dedicated-IP systems, apps? If the announcement is vague, assume the narrow reading.
  4. A report you can open. A published PDF beats a gated download, and both beat a press release summarizing itself.
  5. Corroboration beyond the audit. Proton VPN states its no-logs policy has held in more than 400 legal cases. Private Internet Access says subpoenas produced no data. Windscribe cites a Greek court ruling. CyberGhost publishes quarterly transparency reports. These are vendor statements, not neutral findings — but audits plus court outcomes plus transparency reports stack into something no single document gives you.

Audit strength is one input in a bigger decision. How to choose a VPN covers the other criteria — price honesty, features, jurisdiction — and the most private VPNs ranks the providers that clear the highest bar on exactly the evidence above.

Frequently asked questions

Frequently asked questions

What is a no-log VPN audit?

An independent firm examines a VPN service — its servers, configurations, and data-handling processes — to test whether the no-logs claim in the privacy policy matches how the service actually operates. Most major engagements follow the ISAE 3000 assurance standard and produce a dated, scoped report.

Do no-log VPN audits prove a VPN keeps no logs?

No. An audit gives reasonable assurance about the specific systems examined during a specific window. It cannot certify every server, every moment in time, or anything that changes after the report date. Treat it as strong evidence, not proof.

Who performs no-log VPN audits?

Independent firms hired by the provider. Among the eight major VPNs we track: Deloitte has audited NordVPN, Surfshark, CyberGhost, and Private Internet Access; KPMG audits ExpressVPN; Securitum audits Proton VPN annually; Cure53 and Packetlabs performed the latest Mullvad and Windscribe infrastructure audits.

What data can a no-log VPN still keep?

Account and billing records almost always exist, because the provider needs to know who has paid. Some services also keep limited connection metadata, such as timestamps or server assignments. Audits rarely cover that layer, so the privacy policy is the document to read.

How often should a VPN be audited?

The strongest providers now re-audit every year: NordVPN has had annual Deloitte engagements since 2022, and Proton VPN has published five consecutive annual Securitum reports. A report older than about two years describes infrastructure that may have changed completely.

Can law enforcement still get data from a no-log VPN?

Authorities can always ask; the question is what exists to hand over. If activity logs are genuinely not kept, requests for them come back empty — Proton VPN and Private Internet Access both state this has happened in real cases. Account and payment records are separate and may still be produced.

Sources

  1. NordVPN blog — No-logs assurance engagement 2025 — accessed
  2. NordVPN — No-log VPN — accessed
  3. ExpressVPN blog — KPMG 2025 no-logs policy audit — accessed
  4. Surfshark blog — Deloitte no-logs policy verified again — accessed
  5. Proton VPN blog — No-logs audit — accessed
  6. Proton VPN — homepage (jurisdiction) — accessed
  7. Mullvad blog — Fourth infrastructure audit completed by Cure53 — accessed
  8. CyberGhost — Privacy audit 2025 — accessed
  9. CyberGhost — No-logs VPN — accessed
  10. Private Internet Access blog — Security audit 2025 — accessed
  11. Private Internet Access — Terms of service — accessed
  12. Windscribe — Has Windscribe been audited? — accessed
  13. Windscribe — Terms of use — accessed
  14. PCWorld — Most VPNs say they don't keep logs — accessed
  15. Encapsulated — What is a no-log VPN — accessed