"Independently audited" is a badge every VPN wants and few explain. This tracker dates each provider's most recent audit, names the firm, and says what it actually covered — because a 2019 audit and a 2025 audit are not the same promise.
An audit is the best evidence a VPN can offer short of a courtroom test — but the badge hides three things that matter: when it happened, which firm did it, and what kind of audit it was. A no-logs assurance and a security penetration test answer completely different questions, and an audit from 2019 tells you nothing about the infrastructure running today. Here's the dated picture.
| VPN | Most recent audit | Firm | Year | Type |
|---|---|---|---|---|
| NordVPN | 6th no-logs assurance | Deloitte | 2025 | No-logs |
| ExpressVPN | 3rd no-logs + infra pentests | KPMG + Cure53 | 2025 | No-logs + pentest |
| Surfshark | 2nd no-logs + infra | Deloitte + Cure53 | 2025 | No-logs + pentest |
| Proton VPN | 4th no-logs; apps open-source | Securitum | 2025 | No-logs |
| CyberGhost | 3rd no-logs assurance | Deloitte | 2025 | No-logs |
| Private Internet Access | 3rd no-logs; apps open-source | Deloitte | 2025 | No-logs |
| IPVanish | 2nd no-logs assurance | Schellman | 2025 | No-logs |
| TunnelBear | Annual pentest (9th completed; 8th public) | Cure53 | 2024–25 | Pentest |
| Mullvad | Infrastructure pentest (4th) | Cure53 | 2024 | Pentest* |
As of June 2026. "No-logs" = ISAE 3000 assurance of the no-logging claim; "Pentest" = security/infrastructure test. Counts ("6th", etc.) are the provider's cumulative tally. *Mullvad deliberately runs infrastructure pentests rather than ISAE no-logs reports, on the basis that it collects almost nothing to log — see the note below.
Frequency beats a one-off. NordVPN's six audits and TunnelBear's nine annual pentests are worth more than a single audit a provider commissioned once and never repeated — the infrastructure changes constantly, so recurring verification is the signal.
Match the audit to the claim. A no-logs assurance is what you want if your concern is "do they keep records of me." A pentest is what you want if your concern is "can their servers be breached." Several providers tout one while implying the other; this table separates them.
The Mullvad asterisk is a feature, not a gap. Mullvad commissions infrastructure pentests rather than ISAE 3000 no-logs reports because its whole architecture is built to collect almost nothing — a stance that was, unlike any paper audit, proven by a real police raid in 2023. Don't read the absence of a Big-Four no-logs report as weakness; read it next to the raid.
As of mid-2026, the major providers are mostly well-audited and current — NordVPN, ExpressVPN, Surfshark, Proton, CyberGhost, PIA and IPVanish all carry 2025 no-logs assurances, and ExpressVPN and Surfshark add infrastructure pentests. The thing to watch isn't a missing badge but a stale one: if a provider's newest audit is from 2021, the relevant question is what changed since. Check the year, the firm, and the type — then weigh it against what's been proven under pressure.
VPNInsider.org · Living Resource · updated monthly · June 2026.