“No-logs” is the most overused marketing claim in the VPN industry. Every provider says it. The ones that mean it have the audit reports to prove it.

This article only covers VPNs that have undergone at least one credible independent audit of their no-logs claims. We are not ranking providers on their privacy policy documents. We are ranking them on what independent auditors actually found when they looked at live production systems.

Why no-logs audits matter

A VPN provider that collects no user data has nothing to hand over to law enforcement, data brokers, or hackers. But a promise on a website costs nothing. Audits cost real money, involve reputational risk if issues are found, and produce documentation that can be scrutinized.

The difference between an audited and unaudited no-logs claim is the difference between a verbal promise and a contract. Both can be broken, but one has accountability built in.

Tier 1: Most extensively audited

NordVPN (4.6/5) - 7 independent audits

NordVPN holds the record for independent security audits among consumer VPN providers. Its audit history includes no-logs verifications by Deloitte (2025), Versprite (2023), and PricewaterhouseCoopers (multiple years), plus an infrastructure penetration test by Cure53 and an ISO 27001 certification.

The most recent Deloitte audit specifically tested production servers for log retention, connection metadata, and timestamps. Auditors found nothing. NordVPN publishes full audit reports rather than just summaries, allowing independent review of methodology and findings.

Panama jurisdiction means NordVPN is not subject to EU data retention directives or US National Security Letters.

Get NordVPN

ProtonVPN (4.3/5) - 4 no-logs audits + SOC 2 Type II

ProtonVPN has completed four consecutive no-logs audits by Securitum, with each audit testing live infrastructure rather than documentation. In 2026, it added a SOC 2 Type II certification, which audits business-level security controls over a sustained period of time rather than a single snapshot.

Swiss jurisdiction provides statutory protection against secret government data requests. Switzerland is outside all major intelligence-sharing alliances and has among the strongest data protection laws in the world.

Get ProtonVPN

Tier 2: Well-audited, fewer reviews

Mullvad (4.2/5) - 4 Cure53 audits

Mullvad has conducted four infrastructure and application audits with Cure53, one of the most respected security audit firms for privacy software. Cure53’s audits of Mullvad have covered the VPN client applications, browser extension, and server infrastructure.

Mullvad also underwent a real-world test of its no-logs claims in 2023 when Swedish police seized servers. Investigators left empty-handed: there were no logs to retrieve. This is the most credible possible evidence of a working no-logs policy, because it happened under actual enforcement conditions rather than a controlled audit.

ProviderScoreAuditsAuditorJurisdiction
NordVPN4.6/57Deloitte, Cure53, PwCPanama
ProtonVPN4.3/54 + SOC 2SecuritumSwitzerland
Mullvad4.2/54Cure53Sweden
Surfshark4.1/52Cure53Netherlands
ExpressVPN3.7/52KPMGBVI
IPVanish3.6/51LeviathanUSA

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Surfshark (4.1/5) - 2 Cure53 audits

Surfshark has completed two infrastructure audits by Cure53. The most recent, in 2023, covered server infrastructure and client applications. It also holds an ISO 27001 certification, similar to NordVPN’s.

The lower audit frequency compared to Tier 1 providers is the main limitation. Surfshark’s no-logs commitment is credible but less comprehensively tested than NordVPN or ProtonVPN.

ExpressVPN (3.7/5) - 2 KPMG audits

ExpressVPN has two no-logs audits by KPMG. The audits are genuine (KPMG is a Big Four accounting firm with a credible security practice) but less frequent than competitors. Ownership by Kape Technologies remains a concern for users who want structurally simple, single-purpose privacy companies.

Providers we cannot recommend on this criterion

Several major VPN providers make no-logs claims without independent audits to support them. CyberGhost publishes quarterly transparency reports, which are useful but not a substitute for independent testing. PIA publishes open-source client code, which allows inspection of the client but not the server infrastructure.

These providers may well maintain no-logs policies in practice, but we cannot verify this independently. For users who specifically want audited privacy claims, they do not qualify.

Our verdict

NordVPN and ProtonVPN are the clearest choices for users who prioritize independently verified no-logs policies above all else. Mullvad's real-world police test is worth more than any number of paper audits. Surfshark and ExpressVPN are credible but less comprehensively tested. Any provider without at least one independent audit should not be trusted with sensitive traffic.

Keep reading: How to Verify a VPN’s No-Logs Policy: What Audits Actually Check and Five Eyes, Nine Eyes, and What VPN Jurisdiction Actually Means.