VPN audits and no-logs claims

How to read VPN audit report dates, scope and point-in-time limits. A claim, an announcement and an inspected report are different. Account, payment and metadata records still exist. Not a ranking.

What this isA source-based reading of stored audit rows and privacy notices already on this site. Official Australian guidance is used for Australian claims. It is not a ranked winner list, not a numeric security score, and not a claim that you are untraceable, legally compliant or universally protected. Live app tests remain not tested.

Claim, announcement and inspected report

Three different things get sold as “audited”:

  1. Claim. The vendor’s no-logs or privacy page. ASD’s Australian Cyber Security Centre tells people that VPN providers have access to a large amount of their users’ data and to read the privacy policy. That is a claim to read, not an opened report. ACSC, Connecting to public Wi-Fi and hotspots (last updated 11 Apr 2023; fetched 12 Sep 2026).
  2. Announcement. A blog, press note or Trust Center badge that an engagement happened. report_availability: announcement_only and full_report_inspected: false on this site. A scheduled 2026 audit with no results PDF is still an announcement.
  3. Inspected report. A named PDF (or equivalent) that this site opened. full_report_inspected: true and report_availability: full_report. A public URL that only rendered a cover canvas, or that sits behind login, NDA, email or dashboard gates, is not inspected.

Formula: row_class = inspected if full_report_inspected AND report_availability == full_report. Announcement-only is not inspected. Cover-only is not inspected.

Report dates are a snapshot

Stored report_date is the date on the document or the vendor’s issue date. It is not “verified today”. hide.me’s opened Securitum PDF is eight pages and describes the product as of 15 Mar 2024; the file date is 7 Jun 2024. IVPN’s opened Cure53 no-logs PDF is dated 20 Mar 2019; the vendor later said that engagement will not be repeated. Calculation clock 2026-09-12. Product last_verified dates stay on the research records.

Scope is what was in, not the whole product

Read the scope line before the marketing headline. Examples already stored:

  • ExpressVPN’s opened KPMG PDF is ISAE (UK) 3000 Type I on the design of TrustedServer controls as at 28 Feb 2025. Type I is design, not operating effectiveness. ExpressVPN review.
  • Surfshark’s opened Deloitte ISAE 3000 PDF is a no-logs assurance on named IT systems. Separate Cure53/SecuRing files are infrastructure or protocol work, not a second no-logs ISAE. Surfshark review.
  • Mullvad’s opened X41, Cure53 and Assured PDFs are application, relay and GotaTun code reviews. They are not a no-logs ISAE. Mullvad VPN review.
  • NIST SP 800-77 Rev. 1 describes IPsec as network-layer encryption of packets. That is confidentiality and integrity on a path, not anonymity and not a substitute for reading what the operator retains. NIST SP 800-77 Rev. 1 (June 2020; fetched 12 Sep 2026).

Point-in-time is not continuous assurance

An opened report describes the systems the auditor could see in a window. Proton VPN’s 2025 Securitum PDF was inspected; it is a point-in-time sample of production servers in Zürich, not the global fleet. The 2026 Proton Drive share listed a full_report URL; inner pages rendered as canvas, so full_report_inspected stays false. Inference: a later cover is not a substitute for the opened 2025 PDF.

ACSC’s October 2021 Using Virtual Private Networks publication is about organisational site-to-site and remote-access VPNs: log authentication and sessions, MFA, least privilege. It is not a consumer no-logs shopping list and not a certificate that a browsing-VPN operator keeps nothing. ACSC Using VPNs (October 2021 PDF). Essential Eight still expects organisations to log and monitor. Essential Eight explained.

Account, payment and metadata still exist

A no-logs claim on VPN traffic is not proof of zero retained data. Stored privacy rows still list account identifiers, payment or billing records, and often short-lived session or abuse metadata. That is why this site records retained_service_data separately from logging_policy. OAIC’s Australian Privacy Principles guidelines apply to APP entities; choosing a consumer VPN is not a determination that you, or the vendor, have satisfied the Privacy Act 1988. OAIC APP guidelines. This page is not legal advice.

Worked example: classify stored rows

Independent count over records already on this site. Hand checks: 0+2=2 (NordVPN announcement-only), 3+0=3 (Surfshark inspected), 1+1=2 (Proton 2025 PDF inspected, 2026 canvas not), 6+1=7 (IVPN inspected plus 2026 announcement), 2+2=4 (TunnelBear inspected plus 8th/9th-annual blogs), 4+0=4 (Mullvad inspected pentests, not a no-logs ISAE). Same class on two products is not a ranking. Business remote-access SOC 2 / ISO rows are announcement or gated; none are inspected here.

Product class from stored audit rows. An announcement is not an inspected report. Not a ranking.
ProductLogging policyInspectedAnnouncementUninspected reportClassRetained account/payment
NordVPNno_logs_claim020Announcement onlyYes (6 items)
Surfsharkno_logs_claim300Inspected reportYes (6 items)
ExpressVPNno_logs_claim200Inspected reportYes (8 items)
Proton VPNno_logs_claim101Inspected reportYes (7 items)
Mullvad VPNno_logs_claim400Inspected reportYes (8 items)
IVPNno_logs_claim610Inspected reportYes (8 items)
Private Internet Accessno_logs_claim210Inspected reportYes (8 items)
Windscribeno_logs_claim300Inspected reportYes (9 items)
TunnelBearno_logs_claim220Inspected reportYes (12 items)
hide.me VPNno_logs_claim110Inspected reportYes (8 items)
PrivadoVPNno_logs_claim000Claim onlyYes (8 items)
PureVPNno_logs_claim020Announcement onlyYes (11 items)
NordLayeractivity_logs030Announcement onlyYes (10 items)
Tailscaleconnection_logs020Announcement onlyYes (9 items)
Twingateactivity_logs020Announcement onlyYes (8 items)
Cloudflare Oneactivity_logs030Announcement onlyYes (7 items)

Machine-readable formula and counts: classify.json. Method: How we test.

Named rows used in the count

Stored audit rows used in the worked example. Report date is point-in-time. Not a numeric security score.
ProductAuditorReport dateRow classWhat it is not
NordVPN
no-logs-deloitte-2025
Deloitte Lithuania2025-12-12AnnouncementNot zero retained account or payment data.
NordVPN
no-logs-deloitte-2024
Deloitte Audit Lithuania2025-02-18AnnouncementNot zero retained account or payment data.
Surfshark
no-logs-deloitte-2025
Deloitte Lietuva UAB2025-06-10InspectedNot zero retained account or payment data.
ExpressVPN
no-logs-kpmg-2025
KPMG LLP2025-05-08InspectedType I is design, not operating effectiveness.
ExpressVPN
lightway-cure53-2024
Cure532024-12-03InspectedA pentest is not a no-logs ISAE.
Proton VPN
no-logs-securitum-2026
Securitum2026-05-27Uninspected reportCover-only or gated PDF is not inspected.
Proton VPN
no-logs-securitum-2025
Securitum (Martin Matyja, Maciej Szymczak)2025-09-19InspectedPoint-in-time; not continuous assurance.
Mullvad VPN
app-x41-2024
X41 D-Sec GmbH2024-12-10InspectedA pentest is not a no-logs ISAE.
IVPN
nologs-cure53-2019
Cure532019-03-20InspectedPoint-in-time; not continuous assurance.
IVPN
unlinked-access-cure53-2026
Cure53UnknownAnnouncementAn announcement is not an inspected report.
TunnelBear
cure53-8th-annual-2024
Cure53UnknownAnnouncementAn announcement is not an inspected report.
TunnelBear
cure53-9th-annual-2025
Cure53UnknownAnnouncementAn announcement is not an inspected report.
hide.me VPN
securitum-nologs-2024
Securitum2024-06-07InspectedPoint-in-time; not continuous assurance.
PureVPN
no-logs-fourth-2023
Well known audit firm (vendor copy; historical URL slug still names KPMG)2023-04-01AnnouncementAn announcement is not an inspected report.
NordLayer
soc2-announcement
unknownUnknownAnnouncementAn announcement is not an inspected report.
Tailscale
soc2-type2-announcement
unknownUnknownAnnouncementAn announcement is not an inspected report.

Decision checklist

  • Separate the vendor claim, the announcement, and an opened PDF. Do not treat a login-walled blog as inspected.
  • Read the report date. A 2019 no-logs PDF does not describe 2026 servers.
  • Read the scope. Type I is design. A pentest is not a no-logs ISAE. Mailx or GotaTun work is not the VPN tunnel log claim.
  • Read what account, payment and session metadata the privacy notice still lists. A no-logs claim is not zero retained data.
  • For company apps, ACSC’s organisational VPN PDF expects authentication logs. A consumer no-logs page is the wrong document. Business remote access.
  • Keep MFA, updates and backups. ACSC does not present a VPN as a replacement for those controls.
LimitsNo live tunnels, leak tests or speed tests were run. Login, NDA, email and dashboard gates were not opened. A missing public PDF is omitted rather than filled. This guide is not legal advice, not a Privacy Act determination and not a compliance certificate.

Sources

Shortlist

0 of 3 products

Add products from a review, category table or finder results. Maximum 3.

Add two or three products in the same category to compare.