“We don’t keep logs.” It’s the single most repeated sentence in the VPN industry — and, historically, one of the least verifiable. For years, that phrase sat on landing pages as a marketing claim, resting entirely on the provider’s word. Today, it’s something closer to a testable hypothesis, thanks to a small ecosystem of auditing firms that have built entire practices around walking into VPN infrastructure and checking whether the “no-log” claim actually survives contact with reality.
This piece pulls back the curtain on what a no-log audit actually involves — who performs them, what they can and cannot see, why some audits are worth far more than others, and how to read an audit report like a skeptic rather than a marketing department.
Why “Trust Us” Stopped Being Good Enough
The turning point for the industry wasn’t a single scandal, but a slow accumulation of them. Providers that had publicly sworn off logging were later shown — through court filings, seized servers, or leaked databases — to have retained connection metadata, timestamps, or even user IP addresses. Each incident chipped away at the idea that a privacy policy alone was sufficient evidence of privacy.
Users, journalists, and eventually regulators started asking a more pointed question: if you have nothing to hide, why not let someone independent check? That question is what created the modern no-log audit market.
Who Actually Performs These Audits
No-log audits aren’t run by anonymous “security teams” — the credible ones are conducted by recognized accounting and cybersecurity firms with a reputation to protect. The names that show up repeatedly across the industry include:
- Big-four-adjacent accounting firms — brought in for their assurance and audit methodology expertise, typically producing an Attestation Report following recognized assurance standards.
- Specialist cybersecurity consultancies — firms that focus specifically on penetration testing and infrastructure review, often producing more technical, source-code-level assessments.
- Academic or independent researchers — occasionally brought in for narrower, technically focused reviews of specific claims (like RAM-only server architecture).
The distinction matters. An accounting-style audit tends to verify process — does the company have policies, access controls, and configurations consistent with a no-log claim? A technical audit tends to verify implementation — does the actual server code, in practice, write anything to persistent storage? The strongest audit trail combines both.
What Auditors Actually Look At
A serious no-log audit isn’t a five-minute chat with the CTO. It typically involves several layers of investigation:
1. Server Configuration Review
Auditors examine live production servers — not staging environments or sanitized demo boxes — to check what’s actually running. This includes reviewing VPN daemon configuration files, system logging daemons (syslog, journald), and any custom logging scripts that might capture connection data.
2. Source Code Inspection
For providers that allow it, auditors review the actual server-side code handling client connections, looking for any function calls that write IP addresses, timestamps, bandwidth usage, or session duration to disk or to a remote logging service.
3. Infrastructure Architecture Mapping
This is where RAM-only (“diskless”) server claims get tested. Auditors trace the physical and virtual infrastructure to confirm whether servers genuinely boot from and operate entirely in volatile memory, meaning any data — logs included — is wiped on every reboot.
4. Third-Party Data Flows
A provider can have a spotless internal logging policy and still leak metadata through third-party analytics tools, customer support platforms, payment processors, or cloud infrastructure providers. Rigorous audits map these external dependencies too.
5. Employee Interviews
Auditors interview engineers and operations staff directly, cross-checking their answers against the technical evidence to catch inconsistencies between stated policy and actual practice.
An audit is only as good as its scope. A report that says “we reviewed the privacy policy and interviewed management” is not the same as one that says “we inspected the running configuration of 40 production servers across three data centers.”
The Limits Every Reader Should Understand
No-log audits are valuable, but they are not magic, and treating them as absolute proof is its own kind of naivety. A few structural limitations are worth internalizing:
| Limitation | What It Means |
|---|---|
| Point-in-time snapshot | An audit reflects infrastructure as it existed during the review window — not a permanent guarantee about future configurations. |
| Auditor is paid by the provider | The VPN company selects and pays the auditing firm, which creates an inherent (though usually well-managed) conflict of interest. |
| Scope is negotiable | Providers can limit which servers, regions, or systems are included, potentially leaving weaker infrastructure out of view. |
| No enforcement mechanism | An audit isn’t a legal contract. If a provider changes its practices the day after publication, there’s no built-in mechanism to catch it. |
None of this means audits are worthless — quite the opposite. It means a single audit should be treated as one strong data point among several, not a permanent seal of approval.
Reading an Audit Report Like a Skeptic
When you’re evaluating a VPN’s audit history, a few questions separate a meaningful claim from a hollow one:
- Is the full report public, or just a summary? A one-paragraph press release quoting the audit is not the same as a downloadable PDF with methodology and findings.
- How recent is it? Infrastructure changes constantly. An audit from three years ago tells you little about today’s servers.
- Has it been repeated? Providers who commission recurring audits — annually or more often — are signaling confidence rather than a one-time PR stunt.
- Did the audit include source code, or only policy review? Look for language distinguishing between a “compliance walkthrough” and an actual technical inspection.
- Were any issues found — and fixed? Paradoxically, an audit that reports zero findings whatsoever can be a yellow flag. Real infrastructure reviews often surface minor issues; what matters is whether they were disclosed and remediated.
The Direction of Travel
The trend across the industry is toward more frequent, more technical, and more transparent verification. Some providers have moved beyond one-off audits into continuous, published transparency reports paired with recurring third-party review cycles. Others have begun open-sourcing server-side applications so that independent researchers can inspect the code directly, without waiting for a commissioned report.
This shift matters because it changes the burden of proof. A decade ago, the default assumption was to take a no-log claim at face value unless proven otherwise. Today, the more reasonable default is the opposite: treat a no-log claim as unverified marketing until it’s backed by a recent, scoped, and technically substantive audit — ideally one that’s been repeated more than once.
The Bottom Line
A no-log policy is a promise. An audit is an attempt to check whether that promise matches reality. Neither is a perfect guarantee, but the gap between “trust us” and “here’s a technical report from an independent firm that inspected our production servers” is enormous. As you evaluate any VPN’s privacy claims, the presence, recency, depth, and transparency of its audit history should weigh as heavily as any speed test or feature comparison — because ultimately, speed doesn’t matter if your traffic history is sitting in a log file somewhere waiting to be subpoenaed.
