Sat. Aug 1st, 2026

“We never track, log, or share your data” is one of the most repeated sentences in the VPN industry, and one of the least specific. It is easy to write, costs nothing to publish, and does not by itself describe any particular technical arrangement. Independent audits exist precisely because that sentence, on its own, cannot be distinguished from an identical sentence written by a provider that logs everything. This piece is about learning to separate the language of marketing from the language of verified engineering.

The vocabulary problem

Part of what makes no-log claims hard to evaluate is that “log” itself is not a single, agreed-upon term. A provider can honestly say it keeps “no logs” while still retaining a timestamp of the last successful login, an aggregate count of total bandwidth used that month, or a crash report that happens to include a device’s IP address. None of that necessarily contradicts a no-activity-logging policy, but it does mean two providers can both say “zero logs” while operating very different systems underneath. Reputable providers address this by publishing a precise breakdown of exactly what limited operational data, if any, is retained, rather than relying on the phrase “no logs” to do all the work.

Key takeaway

The words ‘no logs’ describe an intention. An audit describes an inspection. Only one of those can be independently checked.

Two case patterns worth studying

Recurring, named, dated assurance engagements

One provider whose audit history is unusually well documented has undergone a series of independent no-logs assurance engagements roughly on an annual cadence, conducted under the ISAE 3000 assurance standard by a Big Four accounting firm’s regional practice. Each engagement examined the configuration of the company’s IT systems and supporting operations across its standard, double-hop, obfuscated, Tor-over-VPN, and peer-to-peer server categories, and each resulting report explicitly stated the exact fieldwork window it covered. That repeated, dated, named pattern is what turns a claim into something reviewers can actually track over time, rather than a one-time press release that gets cited forever after.

Real-world seizure as an unplanned stress test

Independent audits are not the only way a no-log claim gets tested. In one widely reported case, a foreign government’s investigators physically seized a VPN server as part of a criminal investigation, expecting connection records that would identify a specific user. The provider had told the authorities in advance that it did not retain the kind of connection logs being requested, and the subsequent inspection of the seized hardware reportedly turned up no data that could answer the investigators’ questions. That outcome does not replace a formal audit, but it functions as an unplanned, high-stakes confirmation that is arguably harder to stage-manage than a scheduled review, since the provider had no advance opportunity to prepare the specific server that was taken.

Reading the gap between the claim and the scope

A recurring mistake in how no-log claims get repeated online is treating “audited” as if it certifies everything the company does. In practice, most no-log assurance reports are narrowly scoped to connection and activity logging on VPN infrastructure. They typically say nothing about the company’s marketing website analytics, its payment processor’s data retention, or its customer support platform, unless those systems were explicitly included in the engagement. A provider that has a genuinely strong, narrowly-scoped audit is not being dishonest by not mentioning what was excluded, but a reviewer repeating the claim without noting the scope is doing the reader a disservice.

Marketing phrase What it actually requires to be verifiable Question a reviewer should ask
“We never log your activity” A defined description of what counts as “activity” and confirmation no such data is written to disk What operational metadata, if any, is retained and for how long?
“Independently audited” A named examining firm, dated fieldwork, and an accessible report or summary Who performed the audit, and can I see the report?
“Zero-knowledge architecture” Architecture-level review confirming the system cannot technically retain the data in question Was the architecture itself reviewed, or only a configuration setting?
“Proven in court” A documented case where a legal or law-enforcement request produced no usable data Is there a public record of the specific case being referenced?

Why repetition is not the same as evidence

No-log claims often spread through the review ecosystem faster than the evidence behind them. A single audit gets summarized in a press release, the press release gets paraphrased by dozens of comparison sites, and within a few years the original scope and date range have been stripped away entirely, leaving only the confident phrase “audited no-logs VPN.” Anyone conducting genuine verification work should trace a claim back to its original, dated source rather than trusting how many times it has been repeated. Repetition builds familiarity, not credibility.

What actually closes the gap

Three things consistently separate a verifiable claim from an unverifiable one: a named, credentialed examiner; a specific, dated scope of what was tested; and public accessibility of the resulting report, even in summary form. When all three are present, a marketing sentence has effectively been converted into an inspectable fact. When any one of them is missing, the claim should be treated as marketing language until proven otherwise, regardless of how many times it has been repeated across the review landscape.

Why marketing teams and engineering teams describe the same system differently

Part of the confusion around no-log claims comes from the fact that the people writing the homepage copy and the people configuring the servers are rarely the same people, and rarely reviewing each other’s language closely. A marketing team’s job is to produce a confident, simple, reassuring sentence. An engineering team’s honest description of the same system is usually longer, more conditional, and full of caveats about specific server types, specific data categories, and specific retention windows. Neither team is necessarily acting in bad faith, but the gap between their two versions of the same fact is exactly where an unverified claim tends to live. A published audit report is valuable specifically because it forces the engineering version of the story into public view, caveats included, rather than letting the simplified marketing version stand unchallenged.

What a reviewer’s own comparison table should actually contain

Review sites frequently publish tables comparing VPN providers on whether they are “audited” with a simple yes or no column. That format, while easy to skim, collapses exactly the distinctions that matter: it treats a six-time, recurring, named, ISAE 3000 engagement the same as a single sentence in a five-year-old blog post. A more useful comparison would break “audited” into at least three separate columns: the name of the examining firm, the date of the most recent engagement, and whether the underlying report or a substantive summary is publicly accessible. Collapsing all of that into one checkmark makes for a cleaner-looking table, but it actively works against the goal of helping readers tell a genuine verification apart from an audit-shaped marketing claim.

Applying this to your own research

The practical takeaway for anyone comparing VPN providers is to stop treating “no logs” and “audited no logs” as the finish line of research and start treating them as the starting point of a slightly longer check. Search for the provider’s own audit page rather than relying on a third-party summary. Look specifically for the examining firm’s name and the fieldwork dates. If a court case or seizure is cited as supporting evidence, look for independent news coverage of that specific event rather than accepting the provider’s own retelling. None of these checks take long individually, but together they are what actually separates a provider whose privacy claims can be checked from one whose claims simply sound checkable.

The role of transparency reports alongside audits

A no-log audit answers whether a provider’s systems are configured to avoid generating identifying data in the first place. A separate but related document, the transparency report, answers a slightly different question: how many legal requests, subpoenas, or court orders has the provider actually received, and how many of those were fulfilled with any user data. Providers with strong transparency practices tend to publish these figures on a recurring schedule, broken down by country and request type, alongside a plain statement of how many requests resulted in data being handed over. Read together, an audit and a transparency report cover two different failure modes: the audit checks whether logs exist to be handed over, and the transparency report checks what actually happens when someone asks. A provider that publishes only one of the two is giving reviewers half of a genuinely useful picture.

Conclusion

The distance between “we don’t log anything” and a dated, scoped, independently examined assurance report is the entire distance this category of review exists to cover. Marketing language costs nothing to produce and reveals nothing about the underlying system. A named audit, a documented seizure outcome, or a transparent breakdown of exactly what limited data is retained, gives readers something they can actually check. Learning to tell the two apart is the single most useful skill in evaluating any VPN’s privacy claims.

By Foremy

Foremy

Leave a Reply

Your email address will not be published. Required fields are marked *