Most commercial VPN providers claim they do not keep logs. The phrase appears on landing pages, in marketing emails, and in YouTube ad reads. “No-logs,” “zero-logs,” “we never track our users” — it’s the table-stakes claim of the entire industry.
It’s also one of the most poorly defined and frequently misleading claims in consumer software.
This guide walks through what “no-logs” actually means, how to verify a provider’s claims, and what to look for beyond the marketing copy.
Quick checklist before trusting a no-logs claim
Before going deeper, here’s the short version. A credible no-logs claim should be able to answer yes to most of these:
- Does the provider define exactly which logs it does and does not keep?
- Has the claim been independently audited recently?
- Is the audit report public, or only summarized in marketing language?
- Has the provider ever faced a legal request, server seizure, or breach where the claim was tested?
- Does the privacy policy explain connection logs, usage logs, diagnostic logs, and third-party sharing separately?
- Is the company structure clear, including ownership, jurisdiction, and parent companies?
Each of these is unpacked below.
What “logs” actually means
A VPN routes your internet traffic through its servers. To do that, the servers necessarily process your data in real time. The question isn’t whether the VPN sees your traffic — it does, by definition. The question is what it stores, for how long, and what it does with it afterward.
There are several distinct types of logs a VPN might keep:
Connection logs — records that you connected, when, from which IP address, and to which server. Many VPNs that claim “no-logs” actually keep these for short periods, citing “service quality” reasons.
Usage logs — records of what you did once connected: which sites you visited, which protocols you used, how much data you transferred. This is the data that matters most for privacy. Genuine no-logs providers don’t keep these.
Aggregate logs — anonymized statistics like total bandwidth used across all users, server load averages, geographic distribution of connections. Most providers keep these and most users don’t object.
Diagnostic logs — temporary records used to debug connection issues. Some providers keep these for hours, others not at all.
When a provider says “no-logs,” they could mean any combination of the above. The phrase has no single technical definition, and there is no VPN-specific enforcement body deciding who gets to use it. Misleading advertising laws still apply, but that’s a much higher bar than industry certification.
The questions a provider’s privacy policy needs to answer
A real no-logs claim should specify:
- What data is processed in memory only, never written to disk
- What data is written to disk, and for how long
- What happens to that data after the retention period
- What data is shared with third parties, including parent companies
- What data is provided in response to legal requests, and from which jurisdictions
If a privacy policy uses the phrase “no-logs” but doesn’t address these points specifically, treat the claim as marketing rather than a meaningful commitment.
Read the policy with the assumption that anything not explicitly excluded is included. “We don’t log your browsing history” doesn’t mean they don’t log connection times or IP addresses.
Independent audits: what they prove and what they don’t
The strongest verification a VPN provider can offer is an independent audit of their no-logs claim by a reputable security firm. Examples include ExpressVPN’s repeated KPMG audits, NordVPN’s Deloitte no-logs assurance engagements (six completed as of late 2025), Proton VPN’s annual Securitum audits (four consecutive as of 2025), and Mullvad’s recurring infrastructure and application audits by Cure53 and Assured AB.
An audit is significant because it brings a third party into the chain of accountability. If an audit firm signs off on a no-logs claim and the provider is later found to have logged user data, the firm’s reputation is on the line. That creates real incentive for honest reporting.
But audits have limits worth understanding:
An audit is a snapshot. Most VPN audits are conducted under the ISAE 3000 standard as Type I engagements, which evaluate the design and implementation of controls at a specific moment in time. A Type II audit, which evaluates how those controls perform over a longer period, is rarer and stronger. Either way, a provider could change their logging practices the day after the auditors leave.
Audits depend on scope. If the audit only covers certain servers, certain regions, or certain time periods, the rest of the operation is unverified.
Audit reports are usually summaries. Some providers publish full reports, or make them available behind a click-through agreement. Others only release marketing-friendly excerpts. Read the actual report when it’s available. The summary on the provider’s homepage is not the audit.
The right way to read an audit: it’s stronger evidence than no audit, but it’s not a guarantee. Recent audits matter more than old ones. Repeated audits matter more than one-offs. Public audit reports matter more than private ones.
Real-world tests: when claims meet courts
The most reliable evidence about logging practices comes from situations where governments or law enforcement have asked providers for user data. A few cases worth knowing:
In 2017, ExpressVPN was part of a Turkish government investigation. Authorities seized one of the company’s servers in Turkey. The investigation concluded that no relevant data was found, supporting the company’s no-logs claim at that point in time.
In 2019, Proton VPN was ordered by a Swiss court, acting on a foreign data request, to turn over logs that could identify a user. Proton was unable to comply because the requested logs did not exist.
In 2017, the FBI subpoenaed Private Internet Access for user logs related to a criminal case. Court documents showed the company genuinely had no logs to provide.
These cases don’t prove anything about a provider’s current practices, but they’re stronger evidence than a privacy policy. A provider that has been legally compelled to produce logs and produced nothing has demonstrated their claim under the only conditions that count.
Breaches and security incidents: a different kind of test
Breaches are not the same as legal demands, but they can also reveal whether a provider was storing sensitive data.
In 2018, NordVPN had one third-party server in Finland affected by a data center management vulnerability, disclosed publicly in 2019. The breach revealed configuration details on that single server, but no user activity logs were exposed. The company stated and external review supported that none existed on the server. NordVPN responded by rebuilding its infrastructure and committing to recurring third-party audits.
A breach where there’s nothing useful to find is weaker evidence than a court case, but it’s still informative. If sensitive logs existed, a server compromise would expose them.
Jurisdiction: more nuanced than “Five Eyes bad, offshore good”
A VPN provider’s legal home affects what they can be compelled to do, but not in a simple way.
Providers based in countries within the Five Eyes, Nine Eyes, or Fourteen Eyes intelligence-sharing alliances, which include the US, UK, Canada, Australia, and most of Western Europe, can be subject to data retention notices, subpoenas, and gag orders. The US has National Security Letters that can compel disclosure of certain subscriber information along with nondisclosure requirements. The UK Investigatory Powers Act has its own notices regime that can apply to telecommunications operators.
Providers based in jurisdictions outside these alliances, such as Switzerland, Panama, the British Virgin Islands, or Iceland, face different legal pressures. This isn’t a guarantee of better privacy. It’s a different threat model.
A provider claiming to be in Panama or the BVI but with most of its corporate operations elsewhere isn’t actually outside those jurisdictions in any meaningful sense. Look for where the company is incorporated, where its servers are owned, and where its parent company is based.
But the strongest protection isn’t jurisdiction at all. It’s technical. If useful logs are never created, there is less to hand over regardless of where the company is based. A provider in a difficult jurisdiction with genuinely no logs is in a stronger position than a provider in a friendly jurisdiction that quietly retains data.
What to look for, in order of weight
When evaluating a VPN’s no-logs claim, weight evidence in roughly this order:
- Documented cases of government data requests producing no usable data. This is the highest bar.
- Recent independent audits with published findings and a clear scope. Bonus if repeated annually.
- Open-source clients and transparency reports, allowing independent verification of what the software actually does and how often legal requests are received.
- Clear, specific privacy policies that address all the log categories above.
- Technical architecture that makes logging difficult, such as RAM-only servers, ephemeral session identifiers, and automated configuration auditing.
- Jurisdiction. Relevant but secondary to the technical and audit picture.
- A track record of public accountability: security disclosures, breach reports, willingness to address criticism.
A provider that meets the first criterion (real-world legal test) and the second (recent audit) has demonstrated their claim about as well as any VPN can. A provider that meets none of these is asking you to take their word for it.
Beyond VPNs: the same principle applies
The same way of thinking applies to any privacy-focused service. Whether you are choosing a VPN, an encrypted email provider, a password manager, or a privacy-focused hosting company, the question isn’t “what does the homepage promise?” The better question is “what evidence exists when that promise is tested?”
Marketing language is cheap. Audits, court records, and breach disclosures are not. The companies that have actually been tested and held up are a much smaller group than the companies that claim privacy.
The honest summary
No VPN can prove they don’t log. They can only provide evidence that, taken together, makes the claim credible. The strongest evidence comes from cases where the claim was tested against legal pressure and held.
For most users, the practical takeaway: pick a provider with a recent independent audit, a clear privacy policy, and ideally a documented case where logs were demanded and not produced. Treat the marketing copy as a starting point for investigation, not as evidence in itself.
If a VPN’s only no-logs evidence is the words “no logs” on their homepage, you’re back to trusting marketing. Which, for a privacy tool, is exactly the wrong default.