Nearly every provider in our top ten advertises an independent audit. We read all of them this cycle, including the appendices, and the gap between what the reports say and what the landing pages claim is wide enough to be worth writing about.
What an audit does prove
A good no-logs audit means a named firm had access to production infrastructure and configuration for a defined period, looked for stored user data, and did not find it. That is genuinely valuable. It is far better evidence than a promise on a pricing page, and providers who submit to repeat audits have something to lose by lying.

The four things it does not prove
- That the state on audit day is the state today. Most audits are a snapshot of a two-to-six week window. An audit from 2023 tells you about 2023.
- That the auditors saw everything. Scope sections routinely exclude billing systems, support ticket archives, and internal analytics — all of which can hold identifying data.
- That the company cannot start logging tomorrow. Nothing in an audit is a technical guarantee; it is an observation about past behaviour.
- That the parent company is clean. Several providers are owned by holding groups with other data businesses, and audits almost never cross that boundary.
If a provider will not publish the full report — only a summary page — treat the audit as marketing.
How we weight audits in our scoring
An audit inside the last 12 months with a published full report and production infrastructure in scope is worth the most. Older reports decay in our privacy score at roughly a point a year. Summary-only publications get about a third of the weight. A provider with no published audit at all is not disqualified, but the privacy score is capped until one exists.
The strongest signal is not one audit, it is a pattern of them, and it is stronger still when the client source is public so the report can be checked against the code. Proton VPN and Mullvad both publish source and repeat their audits; NordVPN has now been through four. Whatever else is true, a company that keeps inviting people to look has made it expensive to be caught lying.
How to read the report itself
Start with the scope section, which is usually the shortest part and always the most revealing. It tells you which systems were examined, over what period, and — by omission — what was not. Billing systems, support ticket archives and internal analytics are the three most commonly excluded, and all three can hold identifying data.
Then check who commissioned it and who performed it. A named firm with an audit practice carries considerably more weight than an unnamed "independent security researcher", and a report the provider publishes in full carries more weight than a summary page linking to nothing.
The questions worth asking support
- Can I read the full report rather than the summary?
- What was in scope, and what was explicitly excluded?
- When was the audit period, and when is the next one scheduled?
- Does the audit cover the parent company or only this entity?
A provider that answers all four of those clearly is telling you something useful. A provider that cannot is also telling you something useful.



