# VPN audits and no-logs claims — classification

Observed / calculated: 2026-09-12, Australia/Sydney  
Method: original calculation over stored product audit rows.  
Not: a product ranking, a numeric security score, a live-app test, a guarantee of anonymity, or a Privacy Act determination.

## Classes

1. Inspected: `full_report_inspected = true` and `report_availability = full_report`.
2. Announcement: `report_availability = announcement_only`, or a `full_report` URL that was not opened (cover-only canvas, login/NDA/email/dashboard gate).
3. Claim: `logging_policy = no_logs_claim` and no inspected or announcement row.

Unknown: the `audits` key is missing. Empty `audits: []` with a no-logs claim is claim-only.

## Hand arithmetic

- NordVPN: `0+2=2` announcement-only. Login-walled Deloitte PDF was not opened.
- Surfshark: `3+0=3` inspected. Deloitte ISAE 3000 PDF opened. Separate pentest files are not a second no-logs ISAE.
- Proton VPN: `1+1=2`. 2025 Securitum PDF inspected. 2026 Drive canvas is cover-only.
- IVPN: `6+1=7`. 2019 Cure53 no-logs PDF inspected. 2026 Unlinked Access is announcement-only.
- TunnelBear: `2+2=4`. TB-11/TB-10 PDFs inspected. 8th/9th annual blogs are announcement-only.
- Mullvad: `4+0=4` inspected pentests. Not a no-logs ISAE.

Type I (ExpressVPN KPMG) is design, not operating effectiveness. hide.me Securitum PDF is 8 pages; product as of 15 Mar 2024. A no-logs claim is not zero retained account or payment data.

See `/guides/vpn-audits-no-logs-explained`.
