Table of Contents
- What “No-Log” Actually Means (and Why Most Claims Can’t Be Taken at Face Value)
- How We’re Judging Privacy Here: Audits, Jurisdiction, Track Record
- Best VPNs for Privacy, Side by Side
- Jurisdiction and the 5/9/14-Eyes Alliances, Explained Simply
- Has This VPN Ever Been Forced to Hand Over Data?
- Red Flags That Mean a “No-Log” Claim Isn’t Worth Much
- Bottom Line
- FAQ[+]
For privacy purposes, three things about a VPN are actually measurable. Has an independent auditor verified the logging claims? Where does the company sit legally? And has its no-logs policy ever survived an actual legal demand? Encryption marketing answers none of those.
Most “no-log” headlines fail on at least one of those. This piece puts four providers side by side on exactly those terms, then explains how to spot a claim that sounds strong but proves nothing.
What “No-Log” Actually Means (and Why Most Claims Can’t Be Taken at Face Value)

“No-logs” is not a regulated term. It’s marketing, and it covers several very different promises.
At its weakest, it means the provider doesn’t keep a record of which websites you visit. At its strongest, it means the provider retains no activity logs, no connection metadata (timestamps, session duration, assigned IP), and no account data that could be linked to usage at all.
Those are not the same claim, and providers rarely spell out which one they mean.
A connection log, for example, might record that someone using your account connected at 2:14 a.m. and stayed online for 90 minutes. That alone isn’t browsing history, but combined with other records it can be enough to associate an account with activity. That’s the same kind of metadata pattern behind whether an employer can see what you do on Wi-Fi.
Activity logs go further. They can include destinations, DNS queries, and traffic volume by endpoint. A provider can genuinely claim “no activity logs” while still holding metadata that a determined legal request could target.
- Connection log
- Timestamps, session duration, assigned IP, bandwidth used. Metadata about the fact that you connected, not what you did.
- Activity log
- Destinations visited, DNS queries, traffic by endpoint. A record of what you actually did online.
Unaudited claims are worth little. Any company can write “we keep no logs” on a page. The statement only becomes checkable when an outside firm examines the infrastructure and publishes what it found. The same standard applies to any security claim, whether that’s a VPN’s logging policy or understanding what HP Wolf Security does on a managed laptop.
So the practical question is never “does this VPN claim no logs?” It’s “who verified that, when, and what exactly did they verify?” The rest of this piece applies that filter.
How We’re Judging Privacy Here: Audits, Jurisdiction, Track Record
Three criteria drive this comparison, and only three.
Independent third-party audits. A named auditing firm, a date, and a defined scope. Older audits matter less; a current one is stronger.
Legal jurisdiction. Where the company is headquartered determines which laws and courts can reach it, as explained in detail below. That matters because connection metadata can outlive a session; it’s the same reason tracking an old IP address is sometimes possible well after the fact.
Track record. Has the provider ever actually been tested? A raid, a subpoena, a court order, a breach. This is the hardest criterion to fake.
Audits show what should happen. Jurisdiction shows what could be compelled. Track record shows what did.
The next sections walk through each criterion, followed by a checklist for any provider.
Best VPNs for Privacy, Side by Side
Most of these audits landed in the most recent cycle, as the table below shows. Proton VPN and Mullvad have the most thorough documentation; NordVPN has the longest audit chain; Surfshark’s reports are less detailed.
| Provider | Latest audit | Auditor | Jurisdiction | Been legally tested? |
|---|---|---|---|---|
| Proton VPN | Aug 18 – Sep 19, 2025 (no-logs, fourth annual) | Securitum | Switzerland (outside Five/Nine/Fourteen Eyes) | No public raid or subpoena test |
| Mullvad | Oct 13-31, 2025 (source-code, API/backend); Aug 11-22, 2025 (web-app pen test) | X41 D-Sec GmbH; Assured Security Consultants | Sweden (Fourteen Eyes) | Yes, 2023 police raid, Gothenburg office |
| NordVPN | Most recent published February 2026 | Deloitte | Not asserted here | Security incident tested in 2019, not a legal logging demand |
| Surfshark | 2025, plus June 2025 configuration review | Deloitte | Not asserted here | No public legal test |
| Provider | Latest audit | Jurisdiction | Legally tested? |
|---|---|---|---|
| Proton VPN | Securitum, Aug-Sep 2025 (4th annual) | Switzerland (outside 5/9/14-Eyes) | No public test |
| Mullvad | X41 D-Sec (Oct 2025) + Assured Security (Aug 2025) | Sweden (Fourteen Eyes) | Yes – 2023 police raid, nothing seized |
| NordVPN | Deloitte, Feb 2026 (6th audit) | Not asserted | 2019 breach, not a logging demand |
| Surfshark | Deloitte, 2025 + Jun 2025 config review | Not asserted | No public test |
Proton VPN. Securitum’s fourth consecutive annual audit (Aug–Sep) confirmed no activity or metadata logging. Annual repeats matter more than any single result, since the pattern gets refreshed yearly. Swiss jurisdiction keeps it outside all three intelligence alliances below.
Mullvad. Assured Security’s pen test (Aug 11–22, 2025) reportedly found no critical, high, or medium-risk vulnerabilities. X41 D-Sec’s source-code audit (Oct) covered API and backend (authentication, payments, WireGuard distribution) and found five issues (three medium, two low). That kind of code-level scrutiny, separate from logging policy, is the same depth worth checking for before trusting any VPN protocol, including OpenVPN implementations. Mullvad is Swedish.
NordVPN. Six Deloitte audits since 2022, most recently published February 2026, reconfirm the no-logs policy, where consistency is the strength. These verify logging behavior but don’t examine code like Mullvad’s source-code audit, so they speak to logs, not software vulnerabilities.
Surfshark. Deloitte reportedly audited the no-logs policy; a June configuration review covered different server types (standard, static-IP, MultiPort). Jurisdiction isn’t asserted here because it wasn’t independently verified.
IVPN is another provider that publishes regular third-party audits, though we’re not citing specific dates or auditors for it here.
For the most detailed verification of both logging and software, Mullvad’s audit pair is strongest. For jurisdiction outside the Eyes alliances, Proton VPN is the pick, and its fourth consecutive annual audit means that choice costs nothing in verification.
Jurisdiction and the 5/9/14-Eyes Alliances, Explained Simply

Jurisdiction determines who can compel a VPN to hand over whatever it holds. Three intelligence-sharing arrangements matter.
- Five Eyes: United States, United Kingdom, Canada, Australia, New Zealand. Unrestricted intelligence sharing among members.
- Nine Eyes: the Five Eyes plus Denmark, France, the Netherlands, and Norway. Broader sharing, still routine.
- Fourteen Eyes: the Nine Eyes plus Germany, Belgium, Italy, Spain, and Sweden. The loosest arrangement, with sharing described as situational rather than automatic.
Concretely, imagine a provider headquartered in a Five Eyes country receives a lawful order for subscriber data. Even if it holds no activity logs, it may be required to hand over account details, payment records, and connection metadata, and it may be barred from telling you the order happened. The same order issued to a Swiss provider runs into a different legal framework.
That doesn’t make providers inside these alliances untrustworthy. It changes what they can be forced to do.
Mullvad is Swedish, placing it inside the Fourteen Eyes arrangement, with the loosest sharing tier. Proton VPN is Swiss, outside all three. If your threat model centers on state-level legal pressure more than ordinary law enforcement, that distinction is the one that matters most. If it doesn’t, audit quality probably matters more to you than alliance membership.
Has This VPN Ever Been Forced to Hand Over Data?

Mullvad, 2023. Swedish police raided Mullvad’s Gothenburg office via German judicial cooperation, seeking customer data. They seized nothing, because Mullvad’s RAM-disk-only servers store no logs or personal data. This is the strongest evidence a no-logs claim can produce.
Private Internet Access. US court proceedings tested PIA’s no-logs policy in 2016, 2018, and 2020. Each time PIA couldn’t produce logs, because none existed. Three legal tests across four years, same outcome.
NordVPN, 2019. A rented datacenter server was breached. NordVPN stated no activity logs were exposed (none were collected) and ended that contract. This tests server hardening, not logging policy. A breach and a subpoena test different things.
Takeaway: Mullvad and PIA are the only providers with documented instances of legal pressure that produced no data; PIA is included here for its court record even though it isn’t one of the four providers compared above. Proton VPN, NordVPN, and Surfshark have no public record of being forced to hand over user data, which is weaker evidence than having been tested and passing. A no-logs audit also only covers the provider’s side. It says nothing about what a scammer can do with TeamViewer if they talk their way onto your device directly, a separate risk no logging policy addresses.
Red Flags That Mean a “No-Log” Claim Isn’t Worth Much
Apply this checklist to any provider, including the four above.
- No named auditor. Unverifiable. Auditors stake their reputation; if the provider won’t name them, ask why.
- No linked report. A summary isn’t an audit. You’re reading a paraphrase, not the actual findings.
- Audit older than about two years with no refresh. Code, infrastructure, and ownership change. A stale audit describes a company that may no longer exist.
- Vague scope. “Security audit” tells you nothing. No-logs verification, source-code review, and pen testing answer different questions.
- Jurisdiction inside Five Eyes with no transparency report. If compelled to hand over data with nothing published about requests, you can’t assess the risk.
- No legal test history. The claim has never faced a real adversary.
- Warrant-canary gaps. If a canary statement disappears or stops updating, that’s a signal.
- Audits from a firm with no verifiable security practice. Check that they actually do this work for other clients.
- No-log claims that never specify which logs. If the policy doesn’t distinguish activity, connection, and account data, assume the narrowest interpretation.
Takeaway: The single most useful signal is an audit within the last two years by a named firm with a downloadable report.
Bottom Line
Judge VPN privacy claims on audits, jurisdiction, and track record, and most marketing collapses into one of three tiers.
If jurisdiction matters most, Proton VPN is the pick. Its Swiss base sits outside Five, Nine, and Fourteen Eyes, backed by Securitum’s fourth consecutive annual audit. NordVPN’s longer Deloitte chain is the trade-off there, since it verifies logging behavior without the source-code depth of Mullvad’s audits.
If verification depth matters most, Mullvad is the pick. The X41 D-Sec source-code audit and the Assured Security Consultants penetration test both completed within the same year, backed by a 2023 police raid that ended with nothing seized, the strongest single piece of evidence in this comparison. The trade-off is Swedish jurisdiction inside the Fourteen Eyes arrangement. None of that audit depth covers the devices connecting through the tunnel, either; a smart TV can get a virus through old firmware no matter which provider handles the connection.
Surfshark’s reportedly audited Deloitte record and June configuration review are current, but on legal track record it stands with Proton VPN and NordVPN. All three lack a public test, the one criterion where only Mullvad and PIA can point to an actual legal challenge that produced nothing.
The short version: Proton VPN for jurisdiction, Mullvad for audit depth and proven track record, NordVPN for audit consistency, Surfshark only if the first three don’t fit your needs. For specific use cases like using a VPN with Amazon Firestick, verify that the provider’s app or protocol (WireGuard, OpenVPN, or proprietary) works reliably on your target device before committing.
FAQ
What does “no-logs” mean for a VPN?
It means the provider claims not to retain records of your activity, and usually of your connections as well. The phrase isn’t regulated, so what’s actually covered varies by provider. The only way to know which version applies is to read the audit scope. The marketing page won’t tell you.
How are VPN privacy claims verified?
Through independent third-party audits, ideally with a named firm, a published date, and a defined scope covering logging behavior or source code. Penetration tests and source-code reviews verify different things than no-logs audits. Unaudited claims are effectively unverifiable.
Which VPNs have been independently audited?
- Proton VPN: Securitum
- Mullvad: X41 D-Sec and Assured Security Consultants
- NordVPN: Deloitte, six audits through February 2026
- Surfshark: Deloitte
IVPN also publishes regular third-party audits. PIA’s no-logs policy has also been tested directly in US court.
What jurisdiction is best for VPN privacy?
Based on the claims asserted in this piece, Proton VPN’s Swiss jurisdiction sits outside the Five, Nine, and Fourteen Eyes alliances, while Mullvad’s Swedish jurisdiction sits in the Fourteen Eyes tier, which has the loosest sharing of the three. The right choice depends on whether state-level legal pressure is part of your threat model.
Can VPN companies be forced to give up user data?
Yes, they can be compelled to hand over whatever they hold. Whether that’s useful depends on what they keep. Mullvad’s raid and PIA’s repeated US court tests both ended with nothing produced, because no logs existed. A provider that holds no data has nothing to surrender.









