NordVPN has passed its sixth independent no-logs audit. Deloitte Lithuania spent five weeks, from November 10 to December 12, 2025, examining the company’s server infrastructure and IT management systems, and concluded that everything lines up with NordVPN’s no-logs statement.

That’s the same claim NordVPN has made since day one. What makes this audit worth a headline isn’t the result, it’s the count. Six times now, over eight years, an outside auditor has come in and checked.

What Deloitte actually looked at

The engagement ran under ISAE 3000 (Revised), the international standard used for assurance work outside financial reporting, things like security controls, data handling, or in this case, a no-logs claim. Deloitte’s practitioners got access to NordVPN’s live systems for the full five-week window and reviewed privacy-relevant configuration settings and deployment processes across the standard VPN server fleet, plus specialty configurations: Double VPN, Onion Over VPN, and obfuscated servers.

Auditors also inspected technical logs directly and sat down with NordVPN employees to check that internal practices match the written policy. That combination matters. A policy review only tells you the paperwork is consistent. Interviews and live system inspection tell you whether the people running the infrastructure actually operate the way the policy says they do.

The final report, issued December 12, 2025, states that NordVPN’s IT systems and supporting operations are designed and implemented in line with its no-logs statement. Read that sentence carefully, because it says less than it sounds like. This was a point-in-time assessment: Deloitte checked the systems as they operated during that five-week window, not a permanent guarantee covering every day since.

The audit history, in full

NordVPN’s no-logs claim has now been checked six separate times since 2018:

YearAuditorResult
2018PwCNo logs found
2020PwCNo logs found
2022DeloitteNo logs found
2023DeloitteNo logs found
2024DeloitteNo logs found
2025Deloitte LithuaniaNo logs found

That’s two different Big Four auditors, six separate engagements, spread across eight years, all landing on the same conclusion. For context on what these audits look like when a rival provider goes through the same process, we covered PIA’s third no-logs audit and ProtonVPN’s SOC 2 Type II certification earlier this year. The pattern across the industry is the same: providers with a real claim to make keep inviting outsiders to check it.

Why repeating the audit matters more than passing it once

A single clean audit tells you the infrastructure was fine on the day someone looked. It doesn’t tell you much about the eight weeks before or the eight weeks after. That’s the honest limit of any point-in-time assessment, and it’s why one audit report, however clean, has always been a weaker signal than people assume.

A sixth audit changes the math. NordVPN has now submitted to this exact scrutiny in 2018, 2020, 2022, 2023, 2024, and 2025, without a gap long enough to suggest it was waiting out a bad news cycle or timing a report around a funding round. That’s the behavior you’d expect from a company with nothing to hide, not the behavior of one running a one-time PR exercise timed to a marketing push.

Contrast that with a provider that ran a single audit years ago and still leans on it in every ad. A stale audit tells you almost nothing about current infrastructure. Server configurations change, engineering teams turn over, and logging can quietly get re-enabled somewhere for debugging and never get switched back off. Repeat, recent audits are the only way to catch that kind of drift before it becomes a real privacy problem.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Why the specialty server coverage matters

Deloitte reviewed Double VPN, Onion Over VPN, and obfuscated servers specifically, not just NordVPN’s standard fleet, and that detail matters more than it might seem. These specialty modes exist precisely for users with a higher threat model: journalists, activists, people in restrictive jurisdictions. If a no-logs failure was going to hide anywhere, a niche server type with lower usage and less engineering attention would be the likely spot.

Auditing the standard fleet alone would have left an obvious gap. Extending the same scrutiny to every server category NordVPN offers is the difference between a marketing-friendly audit and one that actually closes the door on the question.

How this fits NordVPN’s overall standing

NordVPN scores 4.63/5 overall in our comparison table, with a perfect 5/5 on audited no-logs, the highest sub-score in that category of any provider we track. It operates out of Panama, outside the Five Eyes, Nine Eyes, and Fourteen Eyes intelligence-sharing alliances, a jurisdictional advantage that’s separate from but complementary to the audit record.

Neither point makes the other redundant. Jurisdiction determines what a government can legally compel NordVPN to hand over. Repeated audits confirm there’s nothing sitting on the servers to hand over in the first place, regardless of jurisdiction. Together they’re a stronger case than either alone, which is exactly the same logic we laid out when covering PIA’s court-tested no-logs history alongside its own audit trail.

If you want the full breakdown of NordVPN’s features, speeds, and pricing, our NordVPN review covers where it lands against the rest of the field. And if you’re wondering how to judge any provider’s no-logs marketing rather than taking our word for it, our guide to verifying a VPN’s no-logs policy walks through what separates a real audit from a rubber stamp.

What this means if you’re picking a VPN for privacy

If privacy is your main reason for wanting a VPN, rather than streaming or gaming, an audit history like this is the strongest evidence you can realistically get without personally inspecting a data center. NordVPN’s pricing sits at $12.99/month on the monthly plan, or an effective $4.99/month on the one-year plan ($59.88/year), with a 30-day free trial and a 60-day money-back guarantee, so testing the service costs nothing if you decide it isn’t for you.

No audit is a substitute for a court subpoena testing the claim in the real world, and no single company’s marketing should be taken purely at face value. But six independent engagements, from two separate Big Four firms, spanning eight years and covering every server type NordVPN operates, is about as close to “prove it” as this industry gets.

Our verdict

NordVPN's sixth no-logs audit isn't news because of what Deloitte found. It's news because of how many times NordVPN has now asked to be checked. A single clean report is a snapshot. Six of them, from two different Big Four auditors across eight years, covering every server type including the niche ones, is a sustained practice. Combined with a 5/5 audited no-logs score and Panama jurisdiction outside the major intelligence alliances, NordVPN's privacy case is as verifiable as any consumer VPN on the market.

Sources: Tom’s Guide, NordVPN’s official blog post on the assurance engagement, and TechRadar.

Keep reading: NordVPN Review 2026 and How to Verify a VPN’s No-Logs Policy: What Audits Actually Check.