CyberGhost says it keeps no logs. The claim sits on a privacy policy, a decade-old audit, and RAM-only servers, three pieces of evidence that don’t carry equal weight. Here is what actually backs up the no-logs promise, and where it falls short.

What CyberGhost’s No-Logs Policy Claims

CyberGhost’s privacy policy states they do not collect or store:

  • Your originating IP address
  • Browsing history or the sites you visit
  • DNS queries
  • Connection timestamps or session duration
  • Traffic data or bandwidth usage per session

On paper, that’s a full no-logs commitment. The question, as always, is whether independent verification supports it.

The 2012 Deloitte Audit: Why Its Age Matters

CyberGhost’s most recent independent no-logs audit was carried out by Deloitte in 2012. That’s the audit CyberGhost still points to as proof of its no-logs claim, and it is now well over a decade old.

An audit is a snapshot of the infrastructure at the time it was run. Servers get replaced, software stacks change, ownership changes, entire company processes get rebuilt. A 2012 audit says nothing reliable about the systems CyberGhost runs today. Compare that to how the rest of the market handles this: NordVPN has been through repeat PwC engagements on an ongoing basis, and ProtonVPN had its no-logs infrastructure reviewed by KPMG in 2024. Recurring audits matter because they prove a policy holds up over time, not just once. A single audit from 2012, never repeated, is closer to a marketing footnote than a live guarantee.

This is the single biggest weakness in CyberGhost’s privacy story. Everything else, RAM-only servers, jurisdiction, can be verified or reasoned about independently. The no-logs claim itself has not been checked by an outside party in more than ten years.

What CyberGhost Actually Collects

CyberGhost’s policy acknowledges gathering a narrower set of data tied to account and app operation, not VPN activity:

  • Email address: required to create an account
  • Payment details: handled by third-party processors, not stored directly by CyberGhost
  • Aggregate app diagnostics and crash reports: non-identifiable data used to fix bugs and improve stability
  • Device type and app version: used for account and update management

None of this ties back to what you did while connected. But the email address is still an identity anchor: it’s the one piece of data CyberGhost could hand over if legally compelled, even if there’s nothing about your browsing to go with it.

RAM-Only Servers

CyberGhost operates on fully RAM-only infrastructure. No data gets written to a hard drive, so a server wipes itself clean on every reboot. If a server were ever seized, there would be nothing on disk to recover.

This is a real technical safeguard, and it’s independent of the audit question. RAM-only architecture doesn’t need a certificate to matter: it’s a structural fact about how the servers are built.

Jurisdiction: Romania, Outside 14-Eyes

CyberGhost is based in Romania, which sits outside the 14-Eyes intelligence-sharing alliance. Romanian courts have also historically pushed back on EU-wide data retention mandates, striking down mandatory retention laws on constitutional grounds. That combination makes Romania one of the more privacy-favorable jurisdictions a VPN can be headquartered in.

In practice, jurisdiction matters most when a no-logs claim is actually tested. Since CyberGhost has no activity logs to hand over (regardless of what a Romanian court could compel), the jurisdiction advantage is more of a bonus than the deciding factor.

Kape Technologies Ownership

CyberGhost is owned by Kape Technologies, the same holding company behind ExpressVPN, Private Internet Access, and ZenMate. In 2026, Kape went fully private under Teddy Sagi’s Unikmind group, exiting public markets entirely.

For users, this cuts two ways. A single company controlling several major VPN brands raises the obvious question of shared infrastructure and shared incentives across products marketed as competitors. And going private removes the disclosure requirements that come with being a publicly listed company, meaning less mandatory transparency about finances, governance, and any material issues going forward. Kape hasn’t been tied to a specific logging scandal, but reduced public accountability is a real cost, not a neutral event.

CyberGhost vs. Other VPN Logs Policies

VPNNo-logs auditLast auditRAM-only serversJurisdiction
CyberGhostYes2012 (Deloitte)YesRomania
NordVPNYesOngoingYesPanama
ProtonVPNYes2024 (KPMG)PartialSwitzerland
SurfsharkYes2021 (Cure53)YesNetherlands
MullvadYes2025/2026YesSweden

CyberGhost is the clear outlier on audit recency. Every other major provider on this list has been checked within the last five years; CyberGhost’s evidence predates the iPhone 5S.

Has CyberGhost Ever Handed Data to Authorities?

There’s no documented case of CyberGhost turning over user activity data to law enforcement or a court. That’s a mild positive signal, though it also reflects the fact that CyberGhost hasn’t faced a high-profile legal test the way Mullvad (raided by Swedish police in 2023, produced nothing) or NordVPN (server seized in Finland in 2018, produced nothing) have. An untested no-logs claim and a claim that survived a raid aren’t the same category of evidence, even if both currently show a clean record.

Should You Trust CyberGhost’s No-Logs Claim?

For casual, everyday use, streaming, general browsing, torrenting on a server that allows it, CyberGhost’s no-logs setup is probably fine. RAM-only servers and a Romanian jurisdiction outside 14-Eyes give it a reasonable technical and legal baseline, and there’s no known incident of data being turned over.

But be direct about the gap: a 2012 audit is not current evidence, and Kape’s move to full private ownership adds another layer of reduced transparency on top of an already stale audit trail. If your privacy needs are serious, journalism, activism, operating under a hostile government, CyberGhost’s outdated audit is a real disqualifier. NordVPN or ProtonVPN both have audits from the last two years and are the better call for high-stakes threat models.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Our Verdict

CyberGhost's no-logs infrastructure is technically sound: RAM-only servers, a privacy-friendly Romanian jurisdiction, and no known history of data handovers. But the no-logs claim itself rests on a single Deloitte audit from 2012, and that's simply too old to count as current proof. Combined with Kape Technologies going fully private in 2026, CyberGhost's transparency trail is thinner than it should be for the price. For everyday streaming and browsing, it's a reasonable, cheap option at $2.75/month on the annual plan. For anything higher stakes, look at a provider with a recent, recurring audit instead.

For more on how to weigh audit evidence generally, read How to Verify a VPN’s No-Log Policy: What Actually Counts as Proof. If you want a deeper dive on CyberGhost’s price and features beyond privacy, see our full CyberGhost review. And for the wider context on what Kape’s ownership shift means across its VPN brands, read Kape Technologies Goes Private: What It Means for ExpressVPN, CyberGhost, and PIA Users.