Living Resource

VPN Audit Tracker: Who Was Audited, By Whom, When

"Independently audited" is a badge every VPN wants and few explain. This tracker dates each provider's most recent audit, names the firm, and says what it actually covered — because a 2019 audit and a 2025 audit are not the same promise.

By the VPN Insider editorial desk · Sourced; see references · Updated monthly. June 2026.

An audit is the best evidence a VPN can offer short of a courtroom test — but the badge hides three things that matter: when it happened, which firm did it, and what kind of audit it was. A no-logs assurance and a security penetration test answer completely different questions, and an audit from 2019 tells you nothing about the infrastructure running today. Here's the dated picture.

Two kinds of audit, often blurred: a no-logs assurance (firms like Deloitte, KPMG, Securitum, using the ISAE 3000 standard) checks whether the provider's systems are configured not to keep logs, at a point in time. A security / infrastructure pentest (firms like Cure53) hunts for vulnerabilities in the apps and servers. The best providers do both; many do one and imply the other.

The tracker

Fresh (2025–26) Aging (2023–24) Stale (pre-2023 / none public)
VPNMost recent auditFirmYearType
NordVPN6th no-logs assuranceDeloitte2025No-logs
ExpressVPN3rd no-logs + infra pentestsKPMG + Cure532025No-logs + pentest
Surfshark2nd no-logs + infraDeloitte + Cure532025No-logs + pentest
Proton VPN4th no-logs; apps open-sourceSecuritum2025No-logs
CyberGhost3rd no-logs assuranceDeloitte2025No-logs
Private Internet Access3rd no-logs; apps open-sourceDeloitte2025No-logs
IPVanish2nd no-logs assuranceSchellman2025No-logs
TunnelBearAnnual pentest (9th completed; 8th public)Cure532024–25Pentest
MullvadInfrastructure pentest (4th)Cure532024Pentest*

As of June 2026. "No-logs" = ISAE 3000 assurance of the no-logging claim; "Pentest" = security/infrastructure test. Counts ("6th", etc.) are the provider's cumulative tally. *Mullvad deliberately runs infrastructure pentests rather than ISAE no-logs reports, on the basis that it collects almost nothing to log — see the note below.

How to read it

Frequency beats a one-off. NordVPN's six audits and TunnelBear's nine annual pentests are worth more than a single audit a provider commissioned once and never repeated — the infrastructure changes constantly, so recurring verification is the signal.

Match the audit to the claim. A no-logs assurance is what you want if your concern is "do they keep records of me." A pentest is what you want if your concern is "can their servers be breached." Several providers tout one while implying the other; this table separates them.

The Mullvad asterisk is a feature, not a gap. Mullvad commissions infrastructure pentests rather than ISAE 3000 no-logs reports because its whole architecture is built to collect almost nothing — a stance that was, unlike any paper audit, proven by a real police raid in 2023. Don't read the absence of a Big-Four no-logs report as weakness; read it next to the raid.

One caveat we won't hide: almost every audit here was commissioned and published by the VPN itself. The firms (Deloitte, KPMG, Cure53, Securitum, Schellman) are independent and reputable, but the provider chooses the scope and the timing and controls the announcement. An audit is a meaningful signal, not a guarantee — which is why we weight it alongside court-tested behavior and real-user sentiment, never on its own.

Bottom line

As of mid-2026, the major providers are mostly well-audited and current — NordVPN, ExpressVPN, Surfshark, Proton, CyberGhost, PIA and IPVanish all carry 2025 no-logs assurances, and ExpressVPN and Surfshark add infrastructure pentests. The thing to watch isn't a missing badge but a stale one: if a provider's newest audit is from 2021, the relevant question is what changed since. Check the year, the firm, and the type — then weigh it against what's been proven under pressure.

References

  1. NordVPN, no-logs assurance engagement (Deloitte, 2025; 6th audit). nordvpn.com
  2. ExpressVPN, "KPMG 2025 no-logs policy audit" (plus Cure53 TrustedServer pentests). expressvpn.com
  3. Surfshark, "Deloitte verifies no-logs policy again" (2025). surfshark.com
  4. Proton VPN, "No-logs audit" (Securitum, 2025). protonvpn.com
  5. CyberGhost, "Privacy audit 2025" (Deloitte). cyberghostvpn.com
  6. Private Internet Access, "Security audit 2025" (Deloitte). privateinternetaccess.com
  7. IPVanish, "Affirms no-log commitment with latest independent audit" (Schellman, 2025). businesswire.com
  8. TunnelBear, "Completes 8th annual independent security audit" (Cure53). tunnelbear.com
  9. Mullvad, "Fourth infrastructure audit completed by Cure53" (2024); audits index. mullvad.net
Independent · affiliate-funded · rankings not for sale. Audit dates and firms verified from provider announcements and corroborating coverage, June 2026. We may earn a commission via some links; it never touches this tracker. Audits are point-in-time signals, not guarantees.

VPNInsider.org · Living Resource · updated monthly · June 2026.