IPVanish carries a reputation problem it can’t fully outrun: in 2016, under a different owner, it handed connection logs to the FBI despite marketing itself as a no-logs VPN. That history is real and worth taking seriously. It’s also nearly a decade old, and the company behind IPVanish today is not the company that did it.

Here’s what actually happened, what’s changed since, and whether IPVanish deserves your trust in 2026.

The 2016 incident, plainly

In a child abuse investigation, the FBI subpoenaed IPVanish, then owned by Highwinds Network Group (later folded into Mudhook Media and then StackPath), for user connection records. According to court documents, IPVanish provided IP logs and other identifying data tied to the target account, directly contradicting its own no-logs marketing at the time. It was one of the clearest cases in VPN history of a “no-logs” claim proving false under legal pressure.

The company was sold to J2 Global (now Ziff Davis) in 2019, well after the incident, under new leadership with no connection to the decisions made in 2016.

What IPVanish’s policy claims now

According to our database, IPVanish’s no-logs policy has since been audited, with Schellman Compliance conducting independent reviews in both 2022 and 2025. Our tracking gives this a 5/5 score for audited no-logs status, the same top tier as NordVPN and Proton VPN, on the basis of those completed audits confirming the infrastructure matches the stated policy.

That’s a real, meaningful change from 2016. An independent auditor examining server configuration and confirming no persistent logging is a different category of evidence than a marketing claim, and IPVanish now has two rounds of it on record.

The parts that still count against it

Three structural details keep IPVanish from a clean bill in our full comparison, and they’re worth separating from the 2016 history because they’re current, not historical.

US jurisdiction. IPVanish is a US company inside the Five Eyes intelligence-sharing alliance, and our database scores its jurisdiction at 2/5. A US legal order, including a National Security Letter with a gag provision, can compel disclosure regardless of audit history. This is a structural risk shared with every US-based provider, not unique to IPVanish, but it stacks on top of the 2016 history in a way that’s hard to fully separate.

No bug bounty program. Our data shows IPVanish scores 0/5 on transparency for bug bounty, meaning it has no formal program rewarding external researchers for finding vulnerabilities. Most top-tier competitors, including NordVPN and Surfshark, run active programs here.

Partial RAM-server rollout. IPVanish scores 3/5 on RAM-only servers in our tracking, indicating the migration to diskless infrastructure is real but not complete across its full network, unlike NordVPN or Proton VPN, both fully RAM-only.

Where IPVanish does well

Leak protection scores a full 5/5 in our testing, meaning DNS, IPv6 and WebRTC leaks are properly blocked across its apps. Speed sits at 4/5, solid if not class-leading. And IPVanish allows unlimited simultaneous device connections on every plan, a genuine differentiator against providers that cap you at 5 or 10 devices, useful for a large household or anyone managing multiple work and personal devices under one subscription.

Overall, IPVanish scores 3.60/5 in our full comparison, putting it in the middle of the field: ahead of budget options with weaker infrastructure, behind the audited, RAM-only, bug-bounty-backed leaders like NordVPN (4.63/5) and Proton VPN (4.30/5).

How the 2022 and 2025 audits actually worked

It’s worth being specific about what a Schellman audit covers, since “audited” gets used loosely across the industry. Schellman Compliance, a licensed CPA firm that performs SOC 2 and similar attestations for security-focused companies, examined IPVanish’s server infrastructure and internal processes to confirm the company doesn’t retain the kind of connection or activity logs its policy says it doesn’t. This is a snapshot audit: it verifies configuration at the time of the review, not a continuous guarantee going forward, which is why repeat audits matter more than a single one. IPVanish repeating the process in 2025, three years after the first, is a meaningfully stronger signal than a one-off audit from years ago that’s never been repeated.

Compare this to the standard set by NordVPN, which has now completed six audits since 2018, or Proton VPN’s SOC 2 audit history. IPVanish’s two-audit record is real progress from having zero audits at the time of the 2016 incident, but it’s still thinner than the annual cadence the very top providers maintain. That gap is reflected in IPVanish’s overall score sitting well below the leaders even though its no-logs category score matches them.

How IPVanish compares against similarly priced rivals

At roughly $2.19 to $3.33 a month on longer plans, IPVanish competes directly with Private Internet Access and CyberGhost rather than with the premium tier occupied by NordVPN and Proton VPN. PIA, also US-based, has the stronger trust story of the two thanks to two FBI subpoenas that produced nothing to hand over, a court-tested record IPVanish doesn’t have. CyberGhost, based in Romania, avoids the Five Eyes jurisdiction question entirely but has a thinner audit history than either. cture, but PIA’s court-tested no-logs claim is the closest thing to IPVanish’s own story, just with a stronger real-world test behind it.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Should you trust IPVanish with your data in 2026?

The honest answer depends on what you’re protecting against. If your concern is everyday privacy, hiding browsing activity from your ISP, protecting yourself on public Wi-Fi, or keeping your IP address off of data broker lists, IPVanish’s current infrastructure and two completed audits make it a reasonable choice. The 2016 incident happened under different ownership, with different leadership, and the company has had nine years and two independent audits to demonstrate the policy now matches reality.

If your threat model includes government surveillance, journalism in a hostile jurisdiction, or anything where a US legal order under Five Eyes cooperation is a real risk, the jurisdiction issue matters more than the audit history resolves. In that case, a provider based outside the Nine Eyes and Fourteen Eyes network, like Proton VPN in Switzerland or NordVPN in Panama, removes a structural risk that no audit can fully offset, since audits confirm current infrastructure, not immunity from a country’s legal system.

How to verify a no-logs claim yourself

Don’t take any provider’s marketing at face value, IPVanish included. Our guide to verifying a VPN’s no-logs claim walks through what an audit report actually needs to say, how to find the original documents rather than a company’s summary of them, and what red flags to watch for in vague or self-reported claims. For a wider view of who currently holds the strongest audited no-logs records, our best audited no-logs VPNs roundup ranks the full field side by side.

How IPVanish stacks up against other providers with a similar history

IPVanish isn’t the only VPN carrying an old incident into its current marketing. Our breakdown of whether NordVPN keeps logs covers a different kind of past scare, a 2018 server breach rather than a logging failure, and how the company’s subsequent audit program addressed it. The pattern across the industry is consistent: past incidents don’t disappear, but a provider’s response to them, specifically whether it opens itself to repeated independent audits, is the clearest signal of whether the policy is real today.

Our verdict: IPVanish’s 2016 logging incident happened under different ownership and doesn’t reflect the company’s current infrastructure, which has now passed two independent Schellman audits (2022 and 2025). It scores 3.60/5 overall in our database, solid for everyday privacy but held back by US/Five Eyes jurisdiction (2/5), no bug bounty program, and a partial RAM-server rollout. For everyday privacy, IPVanish is trustworthy. For a stronger jurisdiction story, NordVPN (4.63/5) or Proton VPN (4.30/5) are the safer picks.