VPN audits and no-logs claims
How to read VPN audit report dates, scope and point-in-time limits. A claim, an announcement and an inspected report are different. Account, payment and metadata records still exist. Not a ranking.
Claim, announcement and inspected report
Three different things get sold as “audited”:
- Claim. The vendor’s no-logs or privacy page. ASD’s Australian Cyber Security Centre tells people that VPN providers have access to a large amount of their users’ data and to read the privacy policy. That is a claim to read, not an opened report. ACSC, Connecting to public Wi-Fi and hotspots (last updated 11 Apr 2023; fetched 12 Sep 2026).
- Announcement. A blog, press note or Trust Center badge that an engagement happened.
report_availability: announcement_onlyandfull_report_inspected: falseon this site. A scheduled 2026 audit with no results PDF is still an announcement. - Inspected report. A named PDF (or equivalent) that this site opened.
full_report_inspected: trueandreport_availability: full_report. A public URL that only rendered a cover canvas, or that sits behind login, NDA, email or dashboard gates, is not inspected.
Formula: row_class = inspected if full_report_inspected AND report_availability == full_report. Announcement-only is not inspected. Cover-only is not inspected.
Report dates are a snapshot
Stored report_date is the date on the document or the vendor’s issue date. It is not “verified today”. hide.me’s opened Securitum PDF is eight pages and describes the product as of 15 Mar 2024; the file date is 7 Jun 2024. IVPN’s opened Cure53 no-logs PDF is dated 20 Mar 2019; the vendor later said that engagement will not be repeated. Calculation clock 2026-09-12. Product last_verified dates stay on the research records.
Scope is what was in, not the whole product
Read the scope line before the marketing headline. Examples already stored:
- ExpressVPN’s opened KPMG PDF is ISAE (UK) 3000 Type I on the design of TrustedServer controls as at 28 Feb 2025. Type I is design, not operating effectiveness. ExpressVPN review.
- Surfshark’s opened Deloitte ISAE 3000 PDF is a no-logs assurance on named IT systems. Separate Cure53/SecuRing files are infrastructure or protocol work, not a second no-logs ISAE. Surfshark review.
- Mullvad’s opened X41, Cure53 and Assured PDFs are application, relay and GotaTun code reviews. They are not a no-logs ISAE. Mullvad VPN review.
- NIST SP 800-77 Rev. 1 describes IPsec as network-layer encryption of packets. That is confidentiality and integrity on a path, not anonymity and not a substitute for reading what the operator retains. NIST SP 800-77 Rev. 1 (June 2020; fetched 12 Sep 2026).
Point-in-time is not continuous assurance
An opened report describes the systems the auditor could see in a window. Proton VPN’s 2025 Securitum PDF was inspected; it is a point-in-time sample of production servers in Zürich, not the global fleet. The 2026 Proton Drive share listed a full_report URL; inner pages rendered as canvas, so full_report_inspected stays false. Inference: a later cover is not a substitute for the opened 2025 PDF.
ACSC’s October 2021 Using Virtual Private Networks publication is about organisational site-to-site and remote-access VPNs: log authentication and sessions, MFA, least privilege. It is not a consumer no-logs shopping list and not a certificate that a browsing-VPN operator keeps nothing. ACSC Using VPNs (October 2021 PDF). Essential Eight still expects organisations to log and monitor. Essential Eight explained.
Account, payment and metadata still exist
A no-logs claim on VPN traffic is not proof of zero retained data. Stored privacy rows still list account identifiers, payment or billing records, and often short-lived session or abuse metadata. That is why this site records retained_service_data separately from logging_policy. OAIC’s Australian Privacy Principles guidelines apply to APP entities; choosing a consumer VPN is not a determination that you, or the vendor, have satisfied the Privacy Act 1988. OAIC APP guidelines. This page is not legal advice.
Worked example: classify stored rows
Independent count over records already on this site. Hand checks: 0+2=2 (NordVPN announcement-only), 3+0=3 (Surfshark inspected), 1+1=2 (Proton 2025 PDF inspected, 2026 canvas not), 6+1=7 (IVPN inspected plus 2026 announcement), 2+2=4 (TunnelBear inspected plus 8th/9th-annual blogs), 4+0=4 (Mullvad inspected pentests, not a no-logs ISAE). Same class on two products is not a ranking. Business remote-access SOC 2 / ISO rows are announcement or gated; none are inspected here.
| Product | Logging policy | Inspected | Announcement | Uninspected report | Class | Retained account/payment |
|---|---|---|---|---|---|---|
| NordVPN | no_logs_claim | 0 | 2 | 0 | Announcement only | Yes (6 items) |
| Surfshark | no_logs_claim | 3 | 0 | 0 | Inspected report | Yes (6 items) |
| ExpressVPN | no_logs_claim | 2 | 0 | 0 | Inspected report | Yes (8 items) |
| Proton VPN | no_logs_claim | 1 | 0 | 1 | Inspected report | Yes (7 items) |
| Mullvad VPN | no_logs_claim | 4 | 0 | 0 | Inspected report | Yes (8 items) |
| IVPN | no_logs_claim | 6 | 1 | 0 | Inspected report | Yes (8 items) |
| Private Internet Access | no_logs_claim | 2 | 1 | 0 | Inspected report | Yes (8 items) |
| Windscribe | no_logs_claim | 3 | 0 | 0 | Inspected report | Yes (9 items) |
| TunnelBear | no_logs_claim | 2 | 2 | 0 | Inspected report | Yes (12 items) |
| hide.me VPN | no_logs_claim | 1 | 1 | 0 | Inspected report | Yes (8 items) |
| PrivadoVPN | no_logs_claim | 0 | 0 | 0 | Claim only | Yes (8 items) |
| PureVPN | no_logs_claim | 0 | 2 | 0 | Announcement only | Yes (11 items) |
| NordLayer | activity_logs | 0 | 3 | 0 | Announcement only | Yes (10 items) |
| Tailscale | connection_logs | 0 | 2 | 0 | Announcement only | Yes (9 items) |
| Twingate | activity_logs | 0 | 2 | 0 | Announcement only | Yes (8 items) |
| Cloudflare One | activity_logs | 0 | 3 | 0 | Announcement only | Yes (7 items) |
Machine-readable formula and counts: classify.json. Method: How we test.
Named rows used in the count
| Product | Auditor | Report date | Row class | What it is not |
|---|---|---|---|---|
| NordVPN no-logs-deloitte-2025 | Deloitte Lithuania | 2025-12-12 | Announcement | Not zero retained account or payment data. |
| NordVPN no-logs-deloitte-2024 | Deloitte Audit Lithuania | 2025-02-18 | Announcement | Not zero retained account or payment data. |
| Surfshark no-logs-deloitte-2025 | Deloitte Lietuva UAB | 2025-06-10 | Inspected | Not zero retained account or payment data. |
| ExpressVPN no-logs-kpmg-2025 | KPMG LLP | 2025-05-08 | Inspected | Type I is design, not operating effectiveness. |
| ExpressVPN lightway-cure53-2024 | Cure53 | 2024-12-03 | Inspected | A pentest is not a no-logs ISAE. |
| Proton VPN no-logs-securitum-2026 | Securitum | 2026-05-27 | Uninspected report | Cover-only or gated PDF is not inspected. |
| Proton VPN no-logs-securitum-2025 | Securitum (Martin Matyja, Maciej Szymczak) | 2025-09-19 | Inspected | Point-in-time; not continuous assurance. |
| Mullvad VPN app-x41-2024 | X41 D-Sec GmbH | 2024-12-10 | Inspected | A pentest is not a no-logs ISAE. |
| IVPN nologs-cure53-2019 | Cure53 | 2019-03-20 | Inspected | Point-in-time; not continuous assurance. |
| IVPN unlinked-access-cure53-2026 | Cure53 | Unknown | Announcement | An announcement is not an inspected report. |
| TunnelBear cure53-8th-annual-2024 | Cure53 | Unknown | Announcement | An announcement is not an inspected report. |
| TunnelBear cure53-9th-annual-2025 | Cure53 | Unknown | Announcement | An announcement is not an inspected report. |
| hide.me VPN securitum-nologs-2024 | Securitum | 2024-06-07 | Inspected | Point-in-time; not continuous assurance. |
| PureVPN no-logs-fourth-2023 | Well known audit firm (vendor copy; historical URL slug still names KPMG) | 2023-04-01 | Announcement | An announcement is not an inspected report. |
| NordLayer soc2-announcement | unknown | Unknown | Announcement | An announcement is not an inspected report. |
| Tailscale soc2-type2-announcement | unknown | Unknown | Announcement | An announcement is not an inspected report. |
Decision checklist
- Separate the vendor claim, the announcement, and an opened PDF. Do not treat a login-walled blog as inspected.
- Read the report date. A 2019 no-logs PDF does not describe 2026 servers.
- Read the scope. Type I is design. A pentest is not a no-logs ISAE. Mailx or GotaTun work is not the VPN tunnel log claim.
- Read what account, payment and session metadata the privacy notice still lists. A no-logs claim is not zero retained data.
- For company apps, ACSC’s organisational VPN PDF expects authentication logs. A consumer no-logs page is the wrong document. Business remote access.
- Keep MFA, updates and backups. ACSC does not present a VPN as a replacement for those controls.
Sources
- ASD’s ACSC, Connecting to public Wi-Fi and hotspots checked 2026-09-12
- ASD’s ACSC, Using Virtual Private Networks (October 2021) checked 2026-09-12
- ASD’s ACSC, Essential Eight explained checked 2026-09-12
- NIST SP 800-77 Rev. 1, Guide to IPsec VPNs checked 2026-09-12
- OAIC, Australian Privacy Principles guidelines checked 2026-09-12
- NordVPN, no-logs assurance engagement 2025 (blog; login-walled report) checked 2026-09-11
- Deloitte Lietuva, Surfshark ISAE 3000 no-logs report (10 Jun 2025 PDF) checked 2026-09-11
- KPMG LLP, ExpressVPN ISAE (UK) 3000 Type I (as at 28 Feb 2025 PDF) checked 2026-09-11
- Securitum, Proton VPN no-logs assessment 2025 PDF checked 2026-09-12
- Cure53, IVPN no-logs verification (20 Mar 2019 PDF) checked 2026-09-12
- X41 D-Sec, Mullvad application audit (10 Dec 2024 PDF) checked 2026-09-12
- Securitum, hide.me no-log policy (7 Jun 2024 PDF) checked 2026-09-12