Industry Analysis

Court-Tested No-Logs: Which VPNs Actually Proved It

Every VPN claims "no logs." An audit checks whether that looked true on the day the auditor visited. A police raid or a court order tests whether it's actually true. Only a handful of providers have faced that test — here's what happened.

By the VPN Insider editorial desk · Sourced; see references. June 2026.

"No-logs" is the industry's universal promise and its least verifiable one. A marketing page costs nothing to write; an audit is a useful snapshot but only covers the moment it was taken. The real proof is adversarial: a government shows up demanding data, and we find out whether the data exists. These are the documented cases — the closest thing the industry has to evidence — sorted by what they actually proved.

The passes

✓ Passed — the gold standard

Mullvad — Swedish police raid, 2023

In April 2023, Sweden's national police arrived at Mullvad's Gothenburg office with a search warrant, intending to seize servers and customer data. They left empty-handed: Mullvad demonstrated that, by design, it holds no such data, and the police took nothing.1 This is the strongest real-world validation of a no-logs claim in the industry — not an auditor's opinion, but law enforcement walking away with nothing because there was nothing to take.

✓ Passed — seized and came up empty

ExpressVPN — Turkey, Karlov assassination, 2017

Turkish investigators seized an ExpressVPN server in January 2017 while probing the assassination of the Russian ambassador, hoping to identify who had used the VPN to wipe evidence. The server held no logs; ExpressVPN could not tell authorities which customer used the IPs in question, because it keeps no connection or activity logs.2 A genuine pass — worth noting it occurred before Kape acquired ExpressVPN in 2021, but the technical result stands.

The mixed result

~ Partial — no user logs, but a real lesson

Windscribe — Ukraine server seizure, 2021

Ukrainian authorities seized two Windscribe servers in 2021. No user activity logs were found — consistent with its policy — but the company candidly admitted those two servers were misconfigured: they weren't fully encrypted and stored an OpenVPN key on disk, which could in theory have allowed traffic interception.3 Windscribe disclosed the lapse openly and re-architected to keep keys in memory only. The no-logs claim held; the operational security didn't, and the honesty about it is exactly what you want to see.

The failure

✗ Failed — the promise was false

IPVanish — handed logs to Homeland Security, 2016

While marketing a "zero-logs" policy, IPVanish (then under Highwinds, before its current ownership) provided detailed connection logs — source IPs and session times — to U.S. Homeland Security Investigations in a 2016 criminal case.4 The logs it swore it didn't keep, it kept and handed over. This is the cautionary tale that makes every other claim worth scrutinizing: a no-logs promise is only as good as the corporate will and the jurisdiction behind it. (IPVanish has since changed hands and now submits to independent audits.)

The instructive non-VPN case

~ A limit worth understanding

Proton — Swiss order, 2021

Often cited as a "Proton logged a user" failure, this case actually involved ProtonMail, not Proton VPN. Compelled by a legally binding Swiss order routed via Europol, ProtonMail logged the IP address of a French climate activist.5 Email contents stayed encrypted, and Proton notes it doesn't log IPs by default — but it shows that even an excellent, privacy-first provider operates under its home country's law. The lesson isn't "Proton is bad"; it's that jurisdiction and legal compulsion are real, and no provider is above them.

What this all proves

Two VPNs have faced a server seizure and come up empty — Mullvad and ExpressVPN — which is the only proof that counts. One — IPVanish — was caught keeping the logs it denied having. And the Proton case shows the ceiling: a provider can only refuse to hand over data it never collected, so the safest design is to collect almost nothing in the first place. That's why Mullvad, which collects the least, sits at the top of our rankings — and why we weight proven behavior over marketing every time.

References

  1. Mullvad Blog, "Mullvad VPN was subject to a search warrant. Customer data not compromised," April 2023. mullvad.net
  2. Comparitech, "ExpressVPN server seized in Turkey turns up no info in assassination case" (2017); ExpressVPN statement on the Andrey Karlov investigation. comparitech.com · expressvpn.com
  3. Windscribe Blog, "Ukrainian server seizure — a commentary and state of the industry," 2021. windscribe.com
  4. TorrentFreak, "No-logging VPN IPVanish led Homeland Security to a Comcast user" (2018, on 2016 events). torrentfreak.com
  5. TechCrunch, "ProtonMail logged IP address of French activist after order by Swiss authorities," September 2021. techcrunch.com
Independent · affiliate-funded · rankings not for sale. This page reports documented, sourced events and labels them as passes, failures, or mixed results on the facts. We may earn a commission via some links; it never touches this analysis. Verified June 2026.

VPNInsider.org · Industry Analysis · updated monthly · June 2026.