PureVPN’s privacy policy promises a strict no-logs setup, and an independent audit from Sec Consult backs part of that claim up. But PureVPN also has a documented case from 2017 where it handed connection logs to the FBI, under an earlier version of the same no-logs promise. Both facts are true at once, and here’s how they fit together.
What PureVPN’s No-Logs Policy Claims
PureVPN’s current terms of service state that it does not log:
- Your browsing history or the sites you visit
- Your originating IP address once connected
- DNS queries made through the VPN
- Traffic content or data transferred during a session
- Connection timestamps tied to your online activity
That’s a standard no-logs commitment, matching the wording most competitors use. The real question is whether it has been checked by anyone outside the company, and whether it has actually held up when tested.
The Sec Consult Audit: What It Covered
PureVPN’s no-logs infrastructure was independently reviewed by Sec Consult, its most recent formal audit. The review looked at PureVPN’s server configuration and backend systems to confirm the company isn’t storing the activity data its policy says it doesn’t collect.
That’s a genuine, recent audit, and it puts PureVPN ahead of providers like CyberGhost, whose only no-logs audit dates back to 2012, or Windscribe, which has never had a formal one. On paper, PureVPN’s current setup compares reasonably well against the rest of the market.
But an audit checks the infrastructure as it exists on the day the auditors show up. It doesn’t retroactively confirm what a company did with the same claim years earlier, and that’s exactly where PureVPN’s story gets complicated.
What PureVPN Actually Collects
Beyond activity logs, PureVPN’s policy acknowledges a narrower set of account-related data:
- Email address: needed to create and manage your account
- Payment details: processed by third-party billing providers, not stored in full by PureVPN directly
- App diagnostics and crash data: non-identifying technical data used to fix bugs
- Device and connection metadata: general app performance info, not tied to browsing activity
None of that reveals what you did while connected. But it’s still the kind of account data that could be handed over if a court in Hong Kong compelled it, which brings us to the part of PureVPN’s history that any honest review has to address.
The 2017 FBI Case: Why It Still Matters
In 2017, PureVPN handed over connection logs that helped the FBI identify a suspect in a cyberstalking case. The story was widely reported at the time, and it stuck because PureVPN was marketing a no-logs service when it happened. The company kept enough connection metadata (timestamps, IP addresses used to correlate sessions) to link an account to the activity investigators were after, despite telling customers it didn’t log that kind of information.
This predates PureVPN’s current audited infrastructure. The company has since restructured its logging practices and brought in Sec Consult to verify the change. That’s a real, meaningful shift, not a cosmetic one. But it also means PureVPN is a provider that has already been caught making a no-logs claim it couldn’t back up once before. An audit proves what’s true today. It can’t undo a track record.
That’s the tension at the center of this whole question: is a 2026 audit enough to outweigh a 2017 incident under the same kind of promise? Reasonable people can land differently on that, but nobody evaluating PureVPN should skip the history to focus only on the current audit.
Jurisdiction: Hong Kong
PureVPN is based in Hong Kong, which sits outside the formal Five Eyes, Nine Eyes, and Fourteen Eyes intelligence-sharing alliances. Strictly on paper, that’s a neutral-to-decent position.
In practice, Hong Kong is flagged independently for surveillance concerns that go beyond the Eyes alliances, given the tightening relationship between Hong Kong’s legal system and mainland Chinese authority over the past several years. That’s a separate risk from formal intelligence-sharing membership, and it’s worth weighing on its own rather than assuming “not in 14-Eyes” settles the jurisdiction question the way it might for a provider based in, say, Switzerland or Panama.
Ownership: Who’s Behind PureVPN
PureVPN is operated by GZ Systems Limited, a company incorporated in Hong Kong. Unlike Kape Technologies (which owns ExpressVPN, CyberGhost, and PIA under one roof), PureVPN isn’t part of a larger multi-brand portfolio you’d recognize from other reviews on this site. That’s a small point in its favor: no shared infrastructure questions, no sibling brands to cross-reference.
It doesn’t change the jurisdiction math, though. A Hong Kong-incorporated company is still a Hong Kong-incorporated company, subject to Hong Kong law regardless of how its ownership structure is drawn up. If you’re weighing PureVPN specifically because of who owns it, the more relevant fact is where it’s legally based, not the corporate chart above it.
PureVPN vs. Other VPN Logs Policies
| VPN | No-logs audit | Last audit | Jurisdiction | Caught logging before? |
|---|---|---|---|---|
| PureVPN | Yes | Sec Consult (latest) | Hong Kong | Yes, 2017 FBI case |
| NordVPN | Yes | Ongoing (PwC, Deloitte 2026) | Panama | No |
| ExpressVPN | Yes | PwC | British Virgin Islands | No |
| CyberGhost | Yes but stale | 2012 (Deloitte) | Romania | No |
This is where PureVPN’s picture gets genuinely mixed rather than simply bad. Its audit is more recent than CyberGhost’s. Its jurisdiction is arguably better than a Fourteen-Eyes country on paper. But it’s the only provider on this table with a confirmed past incident of handing over logs while marketing a no-logs product, and that history doesn’t disappear just because the infrastructure has since changed.
Should You Trust PureVPN’s No-Logs Claim?
For low-stakes daily use like streaming, general browsing, or accessing geo-blocked content, PureVPN’s current setup is probably fine. The Sec Consult audit is real, the pricing is genuinely competitive (PureVPN’s two-year plan works out to roughly $2.42 a month, among the cheapest on the market), and streaming access is solid for Netflix, Disney+, and Hulu even if BBC iPlayer and HBO Max are more hit-or-miss. Speed is the other tradeoff worth flagging: PureVPN scores 3/5 on our speed testing, noticeably behind NordVPN, ExpressVPN, or Surfshark, so don’t expect it to be the fastest option in the room even setting privacy questions aside.
For anything higher stakes, journalism, activism, operating in a country with aggressive surveillance, the 2017 incident is a legitimate disqualifier, not a footnote to skim past. A provider that has already shown its no-logs claim can fail under pressure needs a longer track record of holding up before it earns the same trust as one that’s never had that problem. NordVPN and ProtonVPN both carry recent audits with no history of a similar incident, and they’re the safer call when the stakes are real.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
PureVPN's current no-logs infrastructure checks out under a real, recent Sec Consult audit, and its Hong Kong jurisdiction sits outside the formal Eyes alliances even if it carries its own separate surveillance concerns. What keeps PureVPN from a clean recommendation is 2017: a documented case where it handed over connection logs while marketing itself as a no-logs provider. The company has changed its practices and brought in outside verification since. That's real progress, and it means PureVPN is a defensible pick for everyday streaming and browsing at around $2.42/month on the two-year plan. But for anything where a logging failure has real consequences, a provider with a clean history, not just a current audit, is the safer bet.
Related reading
For a broader framework on weighing audit evidence, see Best Audited No-Logs VPN in 2026: Verified Picks. If ownership structure factors into your decision, our VPN ownership consolidation map covers who’s behind the major providers. And for a similar case study on a provider with an aging audit, read Does CyberGhost Keep Logs in 2026?