X-VPN says it does not log user activity, and in 2026 it backed that claim with an independent audit for the first time. Before you take any no-logs claim at face value, though, it’s worth understanding exactly what got audited, who did the auditing, and where X-VPN still falls short of the top-rated providers.
The 2026 audit, explained
X-VPN completed an independent no-logs audit under the ISAE 3000 (Revised) assurance standard, with fieldwork concluding on February 28, 2026, and the results made public in June 2026. The audit was carried out by one of the Big Four accounting firms, though X-VPN has not named the specific auditor publicly in its own materials, which is itself worth flagging since the most trusted audits in this industry, such as NordVPN’s and ProtonVPN’s, are published with the auditor’s name attached.
The review examined five specific areas: whether sensitive user activity data is stored or recorded, whether only the minimum data needed to run the service is processed, whether server and code infrastructure remain secure across deployment and operation, whether X-VPN’s privacy policy matches its actual practices, and whether internal data protection oversight functions independently.
What the audit found
Based on the audit’s conclusions, X-VPN does not track, collect or store data that could identify individual users or reveal their browsing activity. That is a meaningful result, and it moves X-VPN from a company making an unverified claim to one with third-party assurance behind it, which very few VPNs at its price point can say.
What the audit does not tell you
An ISAE 3000 assurance review is not the same thing as the deep, publicly published technical audits that Cure53 performs for Mullvad or that PwC has performed multiple times for NordVPN. Those audits typically include a detailed public report covering specific findings, remediated vulnerabilities and methodology. X-VPN’s audit, as reported, has not been accompanied by a similarly detailed public report that independent security researchers can scrutinize line by line. That does not mean the audit was not thorough, but it does mean users have less to independently verify than they would with a provider that publishes full audit findings.
How X-VPN compares on logs and trust
| Provider | Logs policy | Audit type | Public report | Score |
|---|---|---|---|---|
| NordVPN | No logs | 7 audits (PwC and others) | Yes, detailed | 4.63/5 |
| ProtonVPN | No logs | Audited + SOC 2 | Yes | 4.24/5 |
| Mullvad | No logs | 4 Cure53 audits | Yes, detailed | 4.04/5 |
| X-VPN | No logs | ISAE 3000, 2026 | Limited detail | 3.02/5 |
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
Why X-VPN’s overall score is still modest
X-VPN sits at 3.02 out of 5 in our overall ranking, and the gap to the top providers is not really about logging at all. Its server infrastructure, jurisdiction transparency and consistency across platforms all score lower than NordVPN, ProtonVPN or Mullvad. At $11.99 a month or $71.99 for the first year, it is not meaningfully cheaper than better-scoring alternatives either, which makes the case for switching to it purely on the strength of one 2026 audit weaker than it might first appear.
Should the new audit change how you think about X-VPN?
It should improve your confidence somewhat, but not to the point of treating X-VPN as equivalent to providers with a longer track record of published, detailed, repeated audits. One assurance review from 2026 is a good start. NordVPN’s seven audits and Mullvad’s real-world test, when Swedish police seized its servers and found nothing retrievable, represent years of accumulated, independently checked evidence. A single ISAE 3000 report does not yet put X-VPN in that company.
What to actually look for in a no-logs claim
Any VPN can write “we don’t keep logs” in its privacy policy. What separates a credible claim from marketing copy is independent verification: has the audit been performed by a named, reputable firm, is the methodology and scope of the audit made public, and has the provider been audited more than once over time rather than a single point-in-time check. Our guide on how to verify a VPN’s no-logs policy walks through the specific questions worth asking of any provider, X-VPN included.
What connection data does X-VPN actually collect?
Beyond the no-logs claim about browsing activity, most VPNs, X-VPN included, still collect some account-level data to run the service: your email address if you sign up with one, payment information handled by the payment processor rather than stored directly, and aggregate, non-identifying usage statistics such as total bandwidth consumed across the service. None of this is unusual or contradicts a no-logs policy, which specifically refers to not logging which sites you visit, when, or for how long while connected. The distinction matters because “no logs” is sometimes misread as “no data collected at all,” which is not what any mainstream VPN, audited or not, actually promises.
How to check on X-VPN’s audit status yourself
Rather than taking any summary, including this one, entirely at face value, X-VPN publishes information about its 2026 audit on its own site, and the announcement was also covered independently by outlets including CIO and Macworld. Reading the original announcement and any available auditor statement directly is worth the ten minutes it takes, especially before making a decision based purely on marketing language. Providers with nothing to hide generally make this easy to find rather than burying it deep in a support article somewhere you would only stumble across by accident.
If you’re currently using X-VPN
There is no evidence contradicting X-VPN’s no-logs claim, and the 2026 audit is a genuine step toward accountability that puts it ahead of VPNs with no audit history at all. If your usage is casual, general browsing privacy and unblocking geo-restricted content, X-VPN’s current audit status is reasonable. If your threat model involves real risk, journalism, activism, or operating somewhere VPN use itself carries legal consequences, the deeper and more frequently verified track records of NordVPN, ProtonVPN or Mullvad are the safer bet.
Jurisdiction matters alongside the audit
X-VPN’s corporate structure has historically been less transparent about its home jurisdiction than competitors that clearly state their base, such as Proton in Switzerland or Mullvad in Sweden. Jurisdiction affects what legal demands a provider can be compelled to comply with, independent of whatever its no-logs policy says on paper. This is a separate consideration from the audit itself, but it belongs in the same conversation when deciding how much trust to place in any provider’s privacy claims, especially if you are choosing between several similarly priced, similarly audited options.
X-VPN's 2026 ISAE 3000 audit is a genuine step toward verified no-logs claims, but it is a single, less detailed review compared to the repeated, publicly documented audits behind NordVPN and Proton VPN. For casual use, X-VPN's claim now has real backing. For higher-stakes privacy needs, the more established providers still have a stronger track record.
Keep reading: Does Mullvad Keep Logs? What the Police Raid Actually Proved and How to Verify a VPN’s No-Logs Policy.