Every VPN claims "no logs." An audit checks whether that looked true on the day the auditor visited. A police raid or a court order tests whether it's actually true. Only a handful of providers have faced that test — here's what happened.
"No-logs" is the industry's universal promise and its least verifiable one. A marketing page costs nothing to write; an audit is a useful snapshot but only covers the moment it was taken. The real proof is adversarial: a government shows up demanding data, and we find out whether the data exists. These are the documented cases — the closest thing the industry has to evidence — sorted by what they actually proved.
In April 2023, Sweden's national police arrived at Mullvad's Gothenburg office with a search warrant, intending to seize servers and customer data. They left empty-handed: Mullvad demonstrated that, by design, it holds no such data, and the police took nothing.1 This is the strongest real-world validation of a no-logs claim in the industry — not an auditor's opinion, but law enforcement walking away with nothing because there was nothing to take.
Turkish investigators seized an ExpressVPN server in January 2017 while probing the assassination of the Russian ambassador, hoping to identify who had used the VPN to wipe evidence. The server held no logs; ExpressVPN could not tell authorities which customer used the IPs in question, because it keeps no connection or activity logs.2 A genuine pass — worth noting it occurred before Kape acquired ExpressVPN in 2021, but the technical result stands.
Ukrainian authorities seized two Windscribe servers in 2021. No user activity logs were found — consistent with its policy — but the company candidly admitted those two servers were misconfigured: they weren't fully encrypted and stored an OpenVPN key on disk, which could in theory have allowed traffic interception.3 Windscribe disclosed the lapse openly and re-architected to keep keys in memory only. The no-logs claim held; the operational security didn't, and the honesty about it is exactly what you want to see.
While marketing a "zero-logs" policy, IPVanish (then under Highwinds, before its current ownership) provided detailed connection logs — source IPs and session times — to U.S. Homeland Security Investigations in a 2016 criminal case.4 The logs it swore it didn't keep, it kept and handed over. This is the cautionary tale that makes every other claim worth scrutinizing: a no-logs promise is only as good as the corporate will and the jurisdiction behind it. (IPVanish has since changed hands and now submits to independent audits.)
Often cited as a "Proton logged a user" failure, this case actually involved ProtonMail, not Proton VPN. Compelled by a legally binding Swiss order routed via Europol, ProtonMail logged the IP address of a French climate activist.5 Email contents stayed encrypted, and Proton notes it doesn't log IPs by default — but it shows that even an excellent, privacy-first provider operates under its home country's law. The lesson isn't "Proton is bad"; it's that jurisdiction and legal compulsion are real, and no provider is above them.
Two VPNs have faced a server seizure and come up empty — Mullvad and ExpressVPN — which is the only proof that counts. One — IPVanish — was caught keeping the logs it denied having. And the Proton case shows the ceiling: a provider can only refuse to hand over data it never collected, so the safest design is to collect almost nothing in the first place. That's why Mullvad, which collects the least, sits at the top of our rankings — and why we weight proven behavior over marketing every time.
VPNInsider.org · Industry Analysis · updated monthly · June 2026.