Some links on this site are affiliate links. If you buy through them we may earn a commission, at no extra cost to you. How this works.

No-log VPNs compared: which providers actually get audited

Technical guide · Last reviewed August 2026

Every VPN says it keeps no logs. Very few prove it. If you want audited privacy, pick by evidence: IVPN and Mullvad offer anonymous accounts and long audit histories; ExpressVPN is the cheapest audited mainstream option at about $2.99/month; Proton VPN splits the difference at $3.49/month with a two-year plan.

What "no logs" actually means

The phrase is marketing shorthand. In practice, a VPN can record three very different kinds of data, and "no logs" rarely means all three are absent:

  • Usage logs — which websites you visit, DNS queries, file contents. This is what people picture when they hear "logs," and it is also the easiest for a provider to avoid collecting. It has no business purpose, so serious providers simply do not build it.
  • Connection metadata — when you connected, from which IP, to which server, how much bandwidth you used. Useful for abuse management, so many providers keep short-lived or aggregate versions of it.
  • Account data — email address, payment method, subscription status. Every provider holds this, because the service cannot be delivered without it.

When you compare VPNs, the real question is which of these three layers exist, for how long, and whether an outside auditor has verified the claim rather than just read the marketing page.

Why an audit matters more than the privacy policy

A no-logs policy is a promise written by the company that wants your money. An audit is a third-party review of what the systems actually do: whether servers are configured to write logs, whether the apps transmit identifiers they should not, and whether internal tooling can reconstruct a session. Audits have real limits — they are a snapshot of specific apps and servers at a point in time — but they convert a claim into something checkable.

The providers that publish audits repeatedly, year after year, are betting their reputation on being checked. That is the strongest available signal short of a court case.

Provider Audit record Jurisdiction Entry price Anonymous signup Refund window
IVPN 7th annual audit completed May 2025 Gibraltar $2/week, $60/year Yes (account number, no email) 30 days
Mullvad App & infrastructure audits published Sweden €5/month flat Yes (account number, cash accepted) 30 days
Proton VPN Multiple app audits since 2024 Switzerland $3.49/month (2-year Plus) No (email required) 30 days
ExpressVPN KPMG June 2025, Cure53 May 2026 British Virgin Islands $2.99/month (Basic, 2-year) No (email required) 30 days

Prices checked August 2026 on provider pricing pages; audit dates from provider trust pages. Long-term plan prices shown; renewal rates are higher.

Does jurisdiction still matter in 2026?

Partly. All four providers above are based outside the major intelligence-sharing alliances, which means a government demand for data has to go through slower, more visible legal channels — mutual legal assistance treaties rather than a local gag order. Sweden, Switzerland, and the British Virgin Islands each have their own legal pressure points, but the shared practical effect is that bulk, covert data collection is harder to impose than it is on, say, a US-based provider.

Jurisdiction matters less than it did a decade ago, though. The more meaningful question is what data a provider could hand over even when legally compelled — which is where audits and seizure cases come in.

What happens when police seize the servers

Two documented cases answer this question better than any policy page:

  • Mullvad, 2023: Swedish police raided the company's Gothenburg office and seized servers under a warrant targeting a specific investigation. Mullvad's response was that the officers would find nothing of investigative value, because the systems are built to hold no customer traffic data. Nothing usable was reported found.
  • ExpressVPN, 2017: Turkish authorities seized a physical server as part of an investigation into a diplomat's assassination. The company confirmed the seizure, and confirmed the server contained no logs that could identify users.

These cases matter because they are the no-logs claim tested under real legal pressure, not under a friendly auditor's scope. See why most VPNs fail in China for a related look at how censorship infrastructure probes services from the other direction.

What "no logs" still doesn't protect

Even the strictest audited VPN knows a few things about you, and you should size your expectations around them:

  • Account and payment trail. Unless you pay with cash or Monero, your bank knows you bought a VPN. IVPN and Mullvad let you sign up with a generated account number instead of an email; IVPN and Mullvad also accept cash and cryptocurrency.
  • Court-ordered targeted logging. Proton disclosed in its transparency reporting that a 2021 Swiss court order required it to enable IP logging for one specific account, which it did and published. This is the correct behavior under the rule of law — and a reminder that "no logs" is a default, not an absolute guarantee.
  • Traffic analysis from outside. Your ISP still sees that you connect to a VPN, and when. No VPN policy changes that. For travel to restrictive networks, combine a no-log provider with obfuscated protocols, as covered in our pre-trip setup checklist.

Selection advice: If anonymity of the account itself is the priority, pick Mullvad (flat €5/month, cash accepted) or IVPN (longest audit history of the four). If you want the cheapest audited mainstream service, ExpressVPN Basic at $2.99/month is hard to beat. Proton VPN Plus is the pragmatic middle: audited, Swiss, and a strong all-rounder at $3.49/month. Our method for weighing these factors is explained on How We Pick.

Frequently asked questions

What does a VPN no-logs policy actually mean?
It means the provider does not record which websites you visit, when you connect, or which IP address you were assigned. Most providers still need to know your account identifier and payment details. The meaningful difference between providers is not the marketing claim but whether an independent auditor has verified what their systems actually collect.
Which VPNs have had the most independent audits?
IVPN completed its seventh annual third-party security audit in May 2025. ExpressVPN has published audits by KPMG (most recently June 2025) and Cure53, including app audits as recent as May 2026. Mullvad publishes audits of its applications and infrastructure on its website, and Proton VPN has published several independent audits of its apps since 2024.
Do audited no-log VPNs still collect any data?
Yes. Audits verify that a provider does not log traffic, but a provider still needs an account record to deliver the service. Unless you sign up anonymously, that usually includes an email address, a payment trail, and possibly aggregate bandwidth counters. Proton VPN disclosed in 2021 that a Swiss court order had required it to log the IP of one specific account, which it published in its transparency report.
Can a no-log VPN hand over data under a court order?
Only data that exists can be handed over. In 2023 Swedish police raided Mullvad's Gothenburg office and seized servers; because Mullvad does not store customer traffic data, nothing usable was found. In 2017 Turkish authorities seized an ExpressVPN server with the same result. A no-logs architecture makes compelled disclosure mostly empty, which is why audits and past seizure cases matter more than policy text.
Which no-log VPN should I pick?
If you want anonymous accounts and the most audits, IVPN and Mullvad are the strongest picks. If you want a mainstream audited service with the lowest long-term price, ExpressVPN Basic at about $2.99 per month is the cheapest audited option. Proton VPN Plus is a good middle ground at $3.49 per month with a two-year plan.