Private Internet Access has passed its third independent no-logs audit. Deloitte Audit Romania, one of the Big Four global auditing firms, examined PIA’s server infrastructure and IT management systems under the ISAE 3000 (Revised) standard and confirmed zero logs during the investigation window.
That result lines up with what PIA’s privacy policy has always claimed. What makes this audit worth a headline isn’t the finding itself, it’s the fact that this is the third time PIA has put itself through the process.
What the Deloitte audit actually checked
Deloitte Audit Romania’s review covered PIA’s live VPN server infrastructure and the IT management systems behind it, examined under ISAE 3000 (Revised), the international standard used for assurance engagements outside of financial reporting. Auditors went looking for connection logs, activity records, or any identifying data that would contradict PIA’s no-logs policy.
They found nothing to hand over, because nothing was recorded. That’s consistent with the setup PIA already runs: RAM-only “NextGen” servers that wipe on every reboot, and client apps that are fully open source on GitHub, so anyone can inspect what the software actually does rather than trust a marketing page.
Why a third audit matters more than a first one
A single no-logs audit tells you a provider’s infrastructure was clean on the day someone checked. A repeated audit tells you something different: that the provider keeps inviting outside scrutiny instead of pointing back at an old report from years ago.
PIA’s audit history now runs 2022, 2024, and this latest one, reported in 2026. Three separate engagements, three clean results, with no gap long enough to suggest the company is stalling on follow-ups. That cadence is the part worth paying attention to. A one-off audit can be a PR exercise timed around a funding round or a bad news cycle. A provider that keeps commissioning the same uncomfortable test, on a company that already has nothing to hide, is behaving the way you’d want a privacy-first VPN to behave.
| Year | Auditor | Standard | Result |
|---|---|---|---|
| 2022 | Deloitte | No-logs infrastructure review | Consistent with policy |
| 2024 | Deloitte | No-logs infrastructure review | Consistent with policy |
| 2026 | Deloitte Audit Romania | ISAE 3000 (Revised) | Zero logs found |
For a longer breakdown of how this compares to PIA’s court-tested track record, see our piece on whether PIA keeps logs, which covers the two FBI subpoenas where the company had nothing to produce.
What ISAE 3000 actually means
ISAE 3000 (Revised) is the international standard auditors use for assurance engagements that aren’t financial statements, things like security controls, data handling, or in this case, a no-logs claim. It’s the same general family of standard that underpins SOC 2 reports, though the two aren’t identical. What matters for a VPN audit is that ISAE 3000 requires the auditor to gather sufficient evidence directly from the systems in question, not just review policy documents and take the company’s word for it.
That distinction is the difference between a paper audit and a live one. A paper audit checks whether the privacy policy is internally consistent. A live audit, which is what Deloitte performed here, checks the actual production servers and management systems against that policy. If PIA’s engineers had quietly started logging connection data somewhere, this is the kind of engagement that would catch it.
How this compares to the court record
PIA’s audit history isn’t the only evidence on the table. The company’s no-logs claim has already been tested twice in US federal court, in 2016 and 2018, when FBI subpoenas asked PIA to hand over identifying data tied to specific investigations. Both times, PIA had nothing to produce. A subpoena is a different kind of test than an audit: it’s adversarial, unscheduled, and carries real legal consequences for lying. An audit, by contrast, is scheduled and paid for by the company being audited, which is why cadence and independence of the auditor both matter so much.
Put the two together and you get a fuller picture than either provides alone. The court record proves the no-logging architecture held up when nobody at PIA had advance warning. The Deloitte audits prove the same architecture has stayed consistent across four years of scheduled scrutiny. For the full breakdown of the court cases, our deep dive on whether PIA keeps logs covers both subpoenas in detail.
The transparency report numbers
PIA also published its latest quarterly transparency report alongside the audit news. In the final three months of 2025, the company logged 30 separate requests from authorities: subpoenas, warrants, other government requests, and informal or foreign requests. In every one of those 30 cases, PIA reported the same outcome, authorities walked away empty-handed because there was no logged information to hand over.
That number matters because it’s not a hypothetical. These are real requests, from real legal processes, tested against the infrastructure the Deloitte audit just examined. The transparency report and the audit are two different types of evidence pointing at the same conclusion.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
The Kape ownership context, briefly
PIA is owned by Kape Technologies, the same parent company behind ExpressVPN, CyberGhost, and ZenMate. Ownership consolidation in the VPN industry is worth tracking in general, since it affects who ultimately controls infrastructure decisions across multiple brands. In PIA’s specific case, the repeated audits and the open-source apps are the parts that matter for a no-logs assessment. Nothing in the Deloitte findings suggests the Kape ownership has changed how PIA’s servers are configured.
RAM-only servers and open-source apps, the other half of the case
An audit only confirms what auditors found on the days they looked. The infrastructure design is what makes a clean result likely every other day too. PIA’s “NextGen” servers run entirely in RAM rather than writing to disk, so every reboot wipes the server clean. There’s no persistent log file sitting around waiting to be seized, subpoenaed, or accidentally left on during a misconfiguration. Combine that with client apps that are fully open source on GitHub, and independent researchers, not just paid auditors, can check what the software actually sends and stores.
None of this is new to PIA’s 2026 audit specifically. But it’s the context that explains why three separate Deloitte engagements, four years apart, keep landing on the same result. When the underlying architecture doesn’t retain data in the first place, there’s nothing for a new audit to discover that the last one didn’t.
What this means if you’re choosing a VPN for privacy
If your main reason for wanting a VPN is to keep your ISP, network administrator, or advertisers from tracking you, PIA’s evidence file now covers three separate types of proof: a court record, a repeated third-party audit, and a quarterly transparency report that keeps landing on the same “nothing to hand over” outcome. Few budget VPNs can point to all three.
The honest caveat is jurisdiction. PIA is a US company, inside the Five Eyes intelligence-sharing alliance, which is a structural fact no audit changes. If your threat model involves a state-level adversary specifically targeting you, that’s still worth weighing against providers based in Switzerland or Panama. For most people using a VPN against ordinary ISP snooping and public Wi-Fi risk, the audit and transparency report numbers are more than enough reassurance.
How this fits PIA’s overall standing
PIA currently scores 3.7/5 in our comparison table, behind category leaders like NordVPN (4.6/5) and ProtonVPN (4.3/5) on overall features and streaming performance, but its privacy evidence stacks up well for the price. At roughly $3.33/mo on the 1-year plan, PIA remains one of the cheapest ways to get a VPN with a repeatedly audited no-logs claim and unlimited device connections.
If you’re weighing PIA against a higher-scoring all-rounder, NordVPN still wins on streaming and speed, but PIA’s audit history now stacks up credibly against providers charging two or three times as much.
Our verdict
Three audits from the same category of auditor, over four years, with a transparency report backing up the same story in between, is a stronger signal than any single clean report could be on its own. This doesn’t change PIA’s overall score in our table, since the privacy fundamentals were already reflected there, but it does remove any lingering doubt for buyers who were waiting for a second or third opinion before trusting the no-logs claim.
PIA's third consecutive no-logs audit, this time from Deloitte Audit Romania under ISAE 3000, confirms what its court record and transparency reports have already shown: there's nothing to log because nothing gets logged. The repetition is the real story here, not the result. Combined with RAM-only servers and open-source apps, PIA's privacy case is as verifiable as any budget VPN on the market.
Sources: TechRadar and the PIA privacy audit blog post.
Keep reading: Private Internet Access Review 2026 and ProtonVPN Passes SOC 2 Type II and Fourth No-Logs Audit in 2026.