VPN Logging Policies - What Providers Keep
Every VPN claims no logs - few prove it. We break down what VPNs can log, what no-log really means, and which providers have verified logging policies.
What VPNs Can Log
Understanding logging starts with knowing what's technically possible to record. VPN logs fall into three categories:
- Connection logs: when you connected and disconnected, your real IP, the VPN IP assigned, session duration
- Activity logs: websites visited, files downloaded, DNS queries, per-site bandwidth - the most invasive type
- Aggregate logs: total bandwidth or server load with no link to any individual - generally considered harmless
What "No-Log" Should Mean
A genuine no-log VPN keeps no connection logs and no activity logs. If subpoenaed or breached, there's simply nothing to reveal about who did what. Some providers retain minimal aggregate data (like total bandwidth for capacity planning), which is acceptable because it can't identify individual activity. The problem is that every VPN claims "no logs" - so the claim is only meaningful when it's verified.
Logging Policies by Provider
| Provider | No-Log Claim | Verified By | Last Audit | Jurisdiction |
|---|---|---|---|---|
| Mullvad | Yes | Cure53, Assured, Radically Open Security | 2024-06 | Sweden |
| ProtonVPN | Yes | Securitum | 2024-04 | Switzerland |
| NordVPN | Yes | Deloitte, PricewaterhouseCoopers | 2024-06 | Panama |
| IVPN | Yes | Cure53 | 2022-02 | Gibraltar |
| ExpressVPN | Yes | KPMG, PricewaterhouseCoopers, Cure53 | 2024-09 | British Virgin Islands |
| Surfshark | Yes | Deloitte, Cure53 | 2023-11 | Netherlands |
| CyberGhost | Yes | Deloitte | 2024-03 | Romania |
| Private Internet Access | Yes | Deloitte + court-proven | 2024-01 | United States |
| Windscribe | Yes | Cure53 | 2024-05 | Canada |
| hide.me | Yes | DefenseCode | 2023-04 | Malaysia |
| VyprVPN | Yes | Leviathan Security | 2018-11 | Switzerland |
| PrivadoVPN | Yes | Switzerland | ||
| Mozilla VPN | Yes | Cure53 | 2023-03 | United States |
| TunnelBear | Yes | Cure53 | 2023-01 | Canada |
| PureVPN | Yes | KPMG, Altius IT | 2023-08 | British Virgin Islands |
| IPVanish | Yes | Leviathan Security | 2022-01 | United States |
| ZoogVPN | Yes | Greece | ||
| FastestVPN | Yes | Altius IT | 2023-02 | Cayman Islands |
| StrongVPN | Yes | United States | ||
| Hotspot Shield | Yes | AV-TEST | 2022-06 | United States |
All six maintain no-log policies verified by reputable auditors. The standouts: PIA is the only one court-proven, and NordVPN and ExpressVPN carry the most audits over the longest period.
Risk-free - 30-day money-back guarantee
How Policies Get Verified
- Independent audits: firms like Deloitte, KPMG, PwC, Cure53, and Securitum inspect servers, code, and data-handling processes
- Court records: when a provider is legally compelled and produces nothing (as PIA did), that's the strongest proof possible
- Open-source code: lets anyone confirm the app isn't logging behind the scenes
- RAM-only servers: hardware that can't retain data across a reboot makes long-term logging physically impossible
Logging Red Flags
Avoid a VPN if you spot any of these:
- No independent audit - an unverified no-log claim is just marketing
- Vague or contradictory policy - claims "no logs" but the privacy policy lists connection data it collects
- Free VPNs with hidden costs - many fund themselves by logging and selling user data
- History of handing over data - past incidents where a provider produced user logs despite a no-log claim
For the full breakdown of who audited whom and what each report covered, see our no-log VPN guide and VPN audits page.