← all articles

What a VPN audit report really proves

almost every vpn website has a badge somewhere that says “independently audited”. it sounds like a stamp of approval, as if a third party looked at the whole company and certified that your data is safe. it is not that. an audit report proves something much narrower, and once you know what, you can read the badge for what it is worth.

i run online businesses out of Singapore and i have bought, tested and dropped a lot of vpn services over the years. the audit badge is the single most over-trusted marketing signal in the category. this article explains what an audit is, what it checks, and what it quietly leaves out, so you can judge a report yourself in about ten minutes.

what it is

a vpn audit is a review done by an outside firm, paid for by the vpn company, that tests specific claims the company has made. the company decides the scope. the auditor checks those claims against evidence and writes a report saying what it found.

the most common claim audited is the “no-logs” policy: the promise that the vpn does not keep records of which sites you visit, what your real ip address is, or when you connect. other audits cover the apps (looking for security bugs), the server infrastructure, or the company’s internal controls.

the people doing the work are usually accounting or security consulting firms. the report is written under professional assurance standards. the big accounting-world frameworks are SOC 2 (published by the AICPA, see the AICPA’s overview of SOC reports) and ISAE 3000, an international standard for assurance engagements outside financial statements. you will see both named in vpn audit summaries.

the key word is “assurance”. the auditor gives a level of comfort about a stated claim. they do not guarantee anything about the future, and they do not certify the company as a whole.

how it works

an audit goes through roughly four steps. knowing them shows you where the gaps are.

  • scoping: the vpn company and the auditor agree what will be examined. this is the most important step and the one readers never see. a company can ask for a review of its no-logs claim on its servers, and not of its payment processor, its support tools, or its website analytics.
  • evidence gathering: the auditor interviews engineers, reads configuration files, looks at how servers are set up, and samples some machines. some audits include a live look at a few servers. others rely largely on documents and screenshots the company provides.
  • testing: for a no-logs audit, the auditor checks whether logging is switched off in the software, whether the servers write connection data to disk, and whether the company’s own processes would let staff retrieve it.
  • reporting: the auditor writes up findings. some firms publish the full report. most vpn companies publish a short summary or a letter, and keep the detailed report private.

two details matter a lot here. first, an audit covers a window of time, often a few weeks of fieldwork, with a report date. the findings describe how things stood then. second, auditors usually sample. they look at some servers, not all of them. if a vpn runs several hundred servers across dozens of countries, a sample of a handful tells you about those handfuls, plus the company’s stated process for the rest.

when a company says “audited”, the real sentence is closer to this: “in [month, year], [firm] reviewed [these systems] and found [these claims] consistent with what they saw.”

why it matters

so is an audit worthless? no. i look at them every time i evaluate a provider. here is what they are good for.

  • it raises the cost of lying: a company that has handed its infrastructure to a professional firm, under a named standard, with its reputation on the line, has more to lose from a false claim than one that only types “no logs” on a landing page.
  • it catches honest mistakes: auditors find real misconfigurations, such as logging left on after a debug session. a good report lists these findings and shows the fix. that is useful information about how the company behaves.
  • it lets you compare providers: a vpn that has been audited repeatedly, by different firms, with published results, is easier to trust than one with a single audit from three years ago and nothing since.
  • it shows how transparent the company is: publishing the full report, including the findings it did not enjoy, says more than the badge does. this is the part of the audit i weigh most.

if you are choosing a vpn to use on public wifi, for streaming, or to keep your browsing away from your isp, the audit is one input among several. for the things a vpn cannot do, see my explainer on what encryption does not hide.

common misconceptions

“audited means the vpn keeps no logs”

it means that a named firm, at a point in time, did not find evidence of logging on the systems it examined. that is a good sign, not a proof. proving a negative across an entire company is not something an audit can do. an auditor can show that logging was off on the servers they looked at. they cannot show that nobody added a logging tool next month.

“the audit covers the whole company”

almost never. the scope is chosen by the client. read the first page of the report for the section titled scope, or the equivalent. if it covers only the no-logs claim on servers, then the app code, the billing system, the customer database and the marketing trackers were not part of it. a vpn can pass a server-side no-logs audit and still know your email address, payment method and the device you signed up on, because that data lives in systems the audit never touched. i walk through this kind of gap in what a privacy policy actually commits a company to.

“an old audit is as good as a new one”

vpn companies change their software, hosting providers and staff all the time. a report from two or three years ago describes a different company. i look for a report within the last twelve months, and for a pattern of repeat audits rather than one report held up forever.

“audit equals independent”

the auditor is independent in the professional sense: they are not employees and they follow standards. but the vpn company hired and paid them, chose the scope, and often decides whether the report is published. that is a normal commercial arrangement, and it is also why the full published report beats the summary. the same thing applies to anyone grading their own homework with an outside marker. it is better than nothing, and it is not a court ruling.

how to read a report in ten minutes

here is the checklist i use. you do not need a security background.

  • find the date: when was fieldwork done, and when was the report issued?
  • find the scope: which systems, which claims, how many servers sampled?
  • find the auditor: a known firm, or an unknown one with no public track record?
  • find the findings: did they list problems and fixes? a report with zero findings is not automatically good. it can mean a shallow review.
  • check what is missing: does it cover the apps, the account database, payments, and the website? if not, ask what happens to that data.
  • see if the full report is public: a summary letter on the company’s own website is weaker than a full document.

some providers publish more than others. Mullvad, for example, writes about its audits and infrastructure openly on its blog, and that kind of public detail is what i would like every provider to do. i am not saying any one vpn is the right pick for you. i am saying that the habit of publishing is worth more than the badge.

the other things an audit cannot see

even a perfect audit leaves your own behaviour out. if you log into your google account while on the vpn, google knows it is you. if your browser has a distinctive fingerprint, sites can recognise it regardless of your ip address. this is the same reasoning that sits behind browser fingerprinting tests, which the team at antidetectreview.org covers in much more depth than i can here. the vpn hides your ip address from the sites you visit and your traffic from your local network. it does not make you anonymous.

the EFF’s surveillance self-defense guides are a good neutral place to see what a vpn does and does not do before you spend money on one.

where to go from here

if you want to keep going after this article, these are the next things i would read.

one last practical point. an audit is evidence about a company’s habits at a moment in time. treat it like a restaurant inspection certificate on the wall. it tells you the kitchen passed on a given day, and a certificate that is old, vague or missing should make you ask a few more questions before you eat there.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-10-03.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →