A no-log VPN provider protects your privacy because there is no activity log linking to your online activity. In theory, if no logs are collected, it means there’s no record that you used the service. In reality, vetting VPN providers claiming not to log your online activity is difficult.
What Is a VPN Audit?
A VPN audit is where a VPN provider submits their software and backend workings to an independent auditor. The independent auditor can then evaluate whether the log-less claims of the VPN provider hold up to scrutiny.
VPN auditing is a very new process. Only a few VPN services have completed any form of vetting and even then, not all VPN services go through the same auditing process.
It’s important to note that the VPN services that allow independent audits are taking a positive step forward, and pushing the VPN industry forward with it. There will always be VPN services that do not open up to thorough vetting. Logging, advertising, and potential data resale are built into the product, or local laws simply do not allow for an alternative.
Not all VPN audits are the same, however.
“There is a deliberate muddying of the water at times from the slightly less ethical providers about what they have done when they communicate to their users,” said Simon Migliano, Head of Research at PrivacyCo.
“There seems to be a tendency to use the term ‘independent security audit’ as a catchall for ‘hey, now you can trust us,’ which I don’t think is a good thing.”Simon Migliano, Head of Research at PrivacyCo
But if a VPN provider is the only source for the “independent security audit”, it raises questions about the legitimacy of the report.
The Best No-Log VPN Services
Figuring out the best no-logs VPNs is difficult. We rate them according to user reviews and independent audits.
Mullvad is a long-time favorite of the VPN Proof team. The Swedish VPN service has a long-standing commitment to privacy and regularly scores high marks on reviews of no-logs VPN providers.
Mullvad keep “no activity logs, do not ask for personal information, and even encourage anonymous payments.” In that, you can pay for your Mullvad VPN subscription using Bitcoin or Bitcoin Cash. In short, Mullvad users can keep their identity secret even from their provider, adding to its privacy focus.
You can connect to Mullvad servers located in 36 different countries, with over 400 servers available across 59 cities. A larger number of servers can help users bypass geo-blocking techniques used by Netflix and other streaming-video services.
Mullvad wasn’t the very first no-log VPN service to agree to an audit, but it was very soon after. Cybersecurity firm, Cure53, noted that the Mullvad audit was only an analysis of the front-end service, rather than the back-end (where logging would take place). Still, Cure53 was positive about Mullvad and remain certain that the service does not take identifying logs.
Another consideration of a Mullvad subscription is its geolocation. Sweden is a 14-eyes country, which is the extension of the five-eyes surveillance network. As such, it maintains close ties with five-eyes security programs. Still, there is no indication that this has any bearing on Mullvad’s previous or ongoing operation.
You can read our Mullvad VPN review for more information on the service.
It is surprising that one of the biggest VPN services remains committed to privacy. ExpressVPN is a no-log VPN service with hundreds of active servers in 94 countries. Furthermore, ExpressVPN is based in the British Virgin Islands, which has no formal data-protection laws, but a strong history of protecting the data of companies incorporated there. While the British Virgin Islands falls under the United Kingdom’s domain, British overseas territories are reported to be independent of the Five Eyes legal control.
In mid-2019, ExpressVPN underwent a third-party VPN audit with PricewaterhouseCoopers. The audit covered ExpressVPNs no-logs policy, their TrustedServer VPN option, and all front and backend security and privacy options. The PricewaterhouseCooper audit team confirmed that each of these services worked correctly and that ExpressVPN is a no-log VPN service.
Another boon for ExpressVPN’s no-log policy was the seizure of several of its servers located in Turkey. After the Turkish authorities alleged that an ExpressVPN connection was used to delete evidence, the Turkish police confiscated the ExpressVPN servers. However, absolutely no information was found on the servers due to ExpressVPN’s no-log policy.
Finally, ExpressVPN turned their browser extensions open source voluntarily, allowing anyone to vet the code. Again, nothing was found to breach user privacy or indeed, keep a log of user activity.
Like ExpressVPN, Surfshark operates out of the British Virgin Islands, offering the same data protection. In terms of age, Surfshark is a relative VPN newcomer. In its short existence, Surfshark has won many admirers and users for its no-log policy, an unlimited number of devices, and CleanWeb technology.
The Surfshark network comprises over 800 servers across more than 50 countries, giving you great choice. Surfshark is also strong technically, offering AES-256 encryption over the OpenVPN protocol amongst other secure options. However, it is known to fall under the ownership of Kape Technologies.
Surfshark underwent a third-party VPN audit around the same time as Mullvad, with similarly positive results regarding logging and privacy features.
You can find out more about Surfshark’s features in our review.
Recommended VPN: Surfshark
For all of NordVPN’s well-documented issues and security leaks, the extremely popular VPN service also chose to undergo multiple VPN audits. Like ExpressVPN, NordVPN opted for PricewaterhouseCoopers for their audit process, rather than Cure53.
NordVPN provided PricewaterhouseCoopers with full access to servers, internal processes, employee interviews, databases, source code, and more. The result was extremely positive, with PricewaterhouseCoopers confirming that NordVPN is a true no-log VPN service.
Another NordVPN positive is its location. NordVPN is based in Panama, a country with extensive data-privacy laws. Even if NordVPN did keep logs, the company would not have any compulsion to provide them under existing Panamanian data protection.
VyprVPN isn’t as well known as some of the no-log VPN services on this list, but it does have one important thing in common. You guessed it: VyprVPN passed a third-party VPN audit regarding activity logs.
VyprVPN didn’t start life claiming not to keep VPN logs. It was quite the opposite, with VyprVPN clearly stating that their service maintained logs for security and other purposes. However, that changed in early 2019 when VyprVPN began working with Leviathan Security Group to move to a logless service.
The result is that VyprVPN joins the esteemed ranks of guaranteed no-log VPN services.
Are There Any Free No-Log VPNs?
There are, but none of these have bothered with independent audits. That more or less means that they are logging your data in order to sell it to third-party marketing agencies. Of all of those companies, only Windscribe (our Windscribe review) has publicly announced an intent to eventually have an independent audit of their logs policy.
Recommended VPN: Windscribe VPN
Can You Trust No Log VPN Providers?
A VPN claiming to take no VPN logs is making a brave assertion. Anyone can slap “no-log VPN” on their sales page and hope that people buy the product without checking if that claim holds up.
VPN providers know that the vast majority of people cannot audit the technology. Therefore, consumers rely on website reviews to understand if a VPN is truly log-free. Unfortunately, there are numerous sites happy to take a payment from a VPN provider in return for a positive review, regardless of the state of the VPN service.
So, can you trust a no-log VPN provider?
You can, mostly. You can’t fully trust any VPN provider. But you have some degree of confidence in the log-free VPN providers on our list.
Are you in a pinch and need a free VPN service? Check out how you can safely use a free VPN service without compromising your privacy and security.
We earn commission if you purchase items using an affiliate link. We only recommend products we trust. See our affiliate disclosure.