How to Actually Evaluate a VPN's Privacy Claims — Digital Moat
Digital Moat · Deep Dive

How to Actually Evaluate a VPN's Privacy Claims

Every VPN says it protects your privacy. Here's how to check whether that's actually true — for any provider, not just the ones on this page.

A VPN sits between you and the entire internet. Every site you visit, every connection you make, passes through it before going anywhere else. That's the whole point — but it also means you're taking the provider's word for it that they're not logging, selling, or leaking what they see. So the real question isn't "does this VPN claim to protect my privacy" — every single one does. It's: how would you actually know if that claim were true?

What a no-logs audit actually checks

An independent audit means an outside firm — typically a Big Four accounting firm or a specialized security auditor — is brought in to examine whether a company's actual infrastructure matches what it publicly claims. For a "no-logs" VPN claim specifically, auditors typically inspect server configurations, internal monitoring tools, and employee access procedures, checking whether the company is technically capable of logging identifying information like IP addresses, timestamps, or browsing activity — and whether it actually does.

This matters because a "no-logs" promise sounds absolute, but in practice it can mean different things. Some providers mean they don't keep browsing activity or source IP addresses. Others still retain short-lived operational data, crash diagnostics, or account-level billing records. An audit is one of the few ways to check which version of "no logs" you're actually getting.

Worth knowing: an audit is a snapshot, not a permanent guarantee. It reflects the company's practices during the period examined — which is exactly why providers that repeat audits regularly (rather than pointing to one audit from years ago) are giving you a stronger, more current signal.

Why open-source code is a different, complementary signal

Audits examine a company's servers and internal processes — things you can't inspect yourself no matter how curious you are. Open-source code is different: it's the actual software running on your own device, made publicly viewable so that any security researcher, hobbyist, or academic can inspect it, any time, not just on whatever schedule a paid audit happens to occur.

That's the real value of open source — it turns "trust us" into "verify it yourself, or trust that thousands of independent people already could." But it's worth being precise about what it covers: open-source client code tells you about the app on your phone or laptop. It doesn't tell you what's happening on the company's servers, which is exactly what an audit is for. The strongest combination is both together, not one instead of the other.

The gap that actually matters: how public is the report?

Here's a distinction that's real, but often gets stretched further than it deserves in marketing comparisons: some providers publish full audit report PDFs openly on their website, for anyone to read without an account. Others publish summary letters publicly and make the complete report available to existing customers, sometimes requiring a free account login to view it.

That's a genuine difference in transparency — but it's not the same as "audited vs. not audited." A provider that gates its full report behind a free login isn't hiding anything meaningful; it's just choosing a different distribution method than a provider that posts the PDF openly. When you see a comparison chart with a stark checkmark on one side and an X on the other for "published audit," look closer at what's actually being compared — the honest version is usually a matter of degree, not a binary.

A checklist for evaluating any VPN's claims

  • ✓ Has it been independently audited, and how recently? A single audit from years ago is weaker evidence than a company that repeats the process regularly.
  • ✓ Who conducted the audit? A named, reputable firm (a Big Four accounting firm, a recognized security auditor) carries more weight than an unnamed or in-house review.
  • ✓ Can you actually read the report, even if it requires a free account? Or is the claim unsupported by any accessible documentation at all?
  • ✓ Is the client app open-source, allowing independent inspection of what's actually running on your device?
  • ✓ What jurisdiction is the company based in, and does that jurisdiction have data retention laws that could compel logging?

None of these questions require you to be a security expert — they just require knowing what to actually ask, instead of taking a marketing page's checkmarks at face value.

Where This Applies
Want a VPN that holds up to this checklist?
NordVPN is our pick — six independent audits since 2018, publicly verifiable results, and a Panama jurisdiction outside data-retention-law reach.
See our full VPN breakdown →

Digital Moat may earn a commission if you subscribe through links on this site, at no additional cost to you. See our Affiliate Disclosure for details.
Haven't checked your own Digital Moat Score yet? Take the free 2-minute assessment →