This guide examines all “no logs” VPN services that have been verified and proven to be true. (Updated with new information on December 7, 2019.)
What is the best no logs VPN service and which of them are actually trustworthy and proven?
This is a tough question. First, there are dozens of VPNs claiming to be “no logs” without any proof or verification whatsoever. In other words, you just have to take their word at face value.
Second, there have been a few “no logs” VPNs that have collected user data and provided the information to authorities and law enforcement. Here are three examples:
- PureVPN was caught logging customer data for the FBI (but later completed a privacy audit)
- IPVanish also collected logs on one of their users and provided the data to the FBI
- HideMyAss provided logs to authorities for a hacking case
There are surely other cases of this happening that have not come to light.
So how can you find a true no-logs VPN that is actually worth your trust?
Fortunately, there have been a handful of VPN services over the years that have had their ‘no logs’ policies tested under various circumstances. We will examine these different providers below and the exact circumstances under which their ‘no logs’ policies were verified.
Here are the best no logs VPN services:
1. ExpressVPN: Third-party audit & real-world verification
|Based in||British Virgin Islands|
|Support||24/7 Live chat|
Overview: ExpressVPN is based in the British Virgin Islands and it’s currently the top recommendation in my comparison of the best VPNs. It offers user-friendly VPN apps with excellent performance and security. ExpressVPN is also one of the few VPNs that work with Netflix, BBC iPlayer, and other streaming services.
In terms of speeds, ExpressVPN one of the fastest VPNs I’ve tested. I can routinely get around 150 Mbps on nearby servers (with a 160 Mbps connection). Check out the ExpressVPN review for a detailed analysis and all test results.
Now let’s examine how ExpressVPN’s no-logs policies have been tested and verified.
ExpressVPN implements TrustedServer (RAM-disk servers)
In April 2019, ExpressVPN upgraded their server infrastructure so all VPN servers run in RAM-disk mode. They refer to this as the TrustedServer feature. This update ensures nothing can be stored on any VPN server as it does away with traditional hard drives. As they explained here, this is a major improvement from a privacy and security standpoint:
With our industry-first TrustedServer technology, our VPN servers run only on volatile memory (RAM), not on hard drives. Since RAM requires power to store data, this guarantees that all information on a server is wiped every time it is powered off and on again.
In contrast, the traditional and most common way of running servers relies very much on hard drives, which retain all data until they are erased and written over, a painstaking and error-prone process. This increases the risk that servers could inadvertently contain sensitive user information. If someone were to hack or seize the server, they could gain access to this data. Even worse, hackers who do find their way in might be able to install a backdoor that remains indefinitely.
Competitor Perfect Privacy also runs all servers in RAM-disk mode, which seems to be the safest and most secure setup.
Third-party no logs audit
In July 2019, ExpressVPN underwent a third-party audit from PricewaterhouseCoopers. This security audit verified the TrustedServer feature, no logs policy, and that all privacy protections are being adhered to correctly. Very few VPNs have undergone third-party audits to verify logging policies.
Lastly, ExpressVPN also decided to open source their browser extensions and subject them to a full security audit by Cure53. Cure53 is a well-regarded cybersecurity firm based in Berlin that has also audited other VPNs, such as TunnelBear.
Turkish authorities try to collect logs, then seize ExpressVPN server
Lastly, in December 2017, Turkish news outlets reported that Turkish authorities attempted to force ExpressVPN to provide customer data for a criminal investigation. According to these reports, Turkish authorities allege that an unknown individual using ExpressVPN deleted evidence on social media related to a political assassination.
While the Turkish news article falsely claims ExpressVPN is based in the US (when it’s in fact based in the British Virgin Islands), it does reveal that the authorities’ attempts to collect user data failed:
The prosecution’s contact with the company did not yield results as Express VPN stated that it is not subject to the rules of U.S. and EU laws.
After failing in their attempts to coerce data from ExpressVPN, the Turkish police then decided to physically seize ExpressVPN’s server, which they obtained from a data center in Turkey. However, this also did not reveal any information because ExpressVPN does not keep any logs on its servers – or otherwise.
ExpressVPN further clarified that all customer data was safe when they issued a statement on the case:
As we stated to Turkish authorities in January 2017, ExpressVPN does not and has never possessed any customer connection logs that would enable us to know which customer was using the specific IPs cited by the investigators. Furthermore, we were unable to see which customers accessed Gmail or Facebook during the time in question, as we do not keep activity logs. We believe that the investigators’ seizure and inspection of the VPN server in question confirmed these points.
Conclusion: As you can see above, ExpressVPN has gone above and beyond most VPN services in terms of securing customer data and validating their own servers, policies, and applications. Here’s a brief overview:
- ExpressVPN’s entire network was upgraded to run on RAM-disk, thereby making it impossible to store logs on any VPN server.
- An outside auditing firm (PWC) then audited the server network and privacy protections. This is in addition to the previous security audit of their browser extensions performed by Cure53.
- ExpressVPN’s logging claims were tested and verified when Turkish authorities seized an ExpressVPN server and were unable to obtain any data.
If you want to give ExpressVPN a test drive, see the coupon below for three months free.
2. NordVPN: Passed third-party logs audit, upgraded security
|Support||24/7 Live chat|
Overview: NordVPN is a no logs provider based in Panama that offers a wide selection of apps for a decent price. In the latest round of testing for the NordVPN review, it performed well in all categories. NordVPN’s VPN apps also have strong leak protection settings as well as advanced privacy features, such as double-hop VPN servers, Tor-over-VPN servers, and obfuscated servers.
NordVPN audited by PWC to verify no logs claims
In November 2018, NordVPN announced on its website that it had completed a full audit to verify their no-logs claims. The audit was conducted by PricewaterhouseCoopers and fully verified the no-logs policy.
NordVPN subscribers can get access to the full audit in the members area. I carefully examined the findings for this guide and can offer this overview:
- NordVPN was audited by PricewaterhouseCoopers. PWC had full access to examine NordVPN’s servers, interview employees, observer operations, inspect configurations, databases, and any other relevant aspect of the VPN service.
- NordVPN does not store connection logs, IP addresses, traffic logs, or any internet activity information.
Because NordVPN limits users to six connections per subscription, it does have a mechanism in place to verify the user’s account and ensure the device connection limit is not being exceeded. This is common for VPN services that implement connection limits (nearly every VPN service) and does not pose any threat to user privacy or security, nor violate the logging claims – as the audit verified.
The audit confirmed NordVPN’s logging policy, which you can read on their website as follows:
NordVPN strictly keeps no logs of your activity online. That means we do not track the time or duration of any online session, and neither do we keep logs of IP addresses or servers used, websites visited or files downloaded. In other words, none of your private and secure data is logged and gathered at any time. As a result, we are not able to provide any details about your behavior online, even if you request it yourself.
NordVPN is based away from the EU and US jurisdiction and is not required to collect your personal data and information– it means nothing is recorded, monitored, stored, logged or passed to third parties.
Additional NordVPN security upgrades following security incident
In November 2019, news broke that NordVPN suffered a security incident where someone obtained an expired TLS key for a single server in Finland. Even though no user data was affected (or decrypted) by this event, some still were referring to it as the “NordVPN hack“.
Even though no user data was affected by this incident, NordVPN decided to update security measures as follows:
- Upgrade the entire server network to run in RAM-disk mode (projected completion 2020)
- Undergo another security audit (projected completion 2020)
Conclusion: NordVPN’s no logs policies, favorable jurisdiction, and solid performance make it a great VPN for torrenting. It is also one of the cheapest VPNs available with the current discounted pricing:
3. VyprVPN: Verified with third-party audit
|Support||24/7 live chat|
Overview: VyprVPN is a no logs VPN service based in Switzerland with secure apps and excellent performance. It did well in speed tests for the VyprVPN review and has a pretty good reputation. VyprVPN is unique in that they physically own every server in their network (no rentals from third parties), which helps to ensure data security. VyprVPN also offer the Chameleon protocol, which will get around VPN blocks and restrictions (important when using a VPN for China).
No logs transition: VyprVPN audited / advised by cybersecurity firm
In September 2018 VyprVPN began working with Leviathan Security Group to transition into a full “no logs” VPN service. The auditors examined all aspects of VyprVPN’s network to identify areas where logs were maintained that could de-anonymize the user. After fixing a few issues, they re-tested everything and found VyprVPN to be in full compliance with their stated “no logs” policy.
VyprVPN’s security audit is available to the public here and can be referenced publicly. Here are a few sections:
We examined all components of the project according to the threat assessment described below. While vigilance against logging is necessary to complete the process of implementing “No Log”, we feel that this assessment achieved its goal of uncovering weaknesses in Golden Frog’s implementation. The project revealed a limited number of issues that Golden Frog quickly fixed. As a result, it can provide VyprVPN users with the assurance that the company is not logging their VPN activity.
Golden Frog worked to remediate all no-log-related findings concurrently with the assessment. Once it had completed this, we performed a retest and verified that all of the fixes were effective.
Before this change took place, VyprVPN logged connection data (including IP addresses) for 30 days. Now VyprVPN can be counted among the small number of verified no logs VPN services. See the VyprVPN review for more information and test results. You can also get a VyprVPN discount for 25% off annual plans.
4. Perfect Privacy: No logs VPN test
|Support||Email & forum|
Overview: Perfect Privacy is a premium, Switzerland-based VPN that offers advanced online anonymity and security features. It is a no logs service that does not restrict user accounts in any way. You get an unlimited number of connections and unlimited bandwidth to use with your subscription as well as very advanced privacy features. Privacy features include multi-hop VPN configurations, port forwarding, and an advanced advertisement and tracking blocker called TrackStop.
Perfect Privacy server seized in the Netherlands
In August 2016 Perfect Privacy announced that Dutch authorities had seized one of their servers in Rotterdam, Netherlands. Although the reason for seizing the server was never revealed, Perfect Privacy confirmed no customer data was obtained:
Since we are not logging any data there is currently no reason to believe that any user data was compromised.
…We can now conclude that no customer information was compromised due to the seizure. The Rotterdam location will continue to operate using the replacement servers.
RAM-disk servers (no logs possible)
To further protect customer data in the event of a server seizure, Perfect Privacy runs all their servers in RAM-disk mode, like ExpressVPN, as they explain on their log policy page:
Our infrastructure is built on this philosophy: All our services are running within strongly encrypted RAM disks so that it is technically impossible for data to be stored on hard drives. This also means that no data can be recovered if the power is disconnected.
Nobody can force us to log your data. If that were the case we would rather discontinue Perfect Privacy than to record your data and compromise your privacy.
While Perfect Privacy is a higher-priced service, it remains a great option for privacy and security, with a proven no logs policy and Switzerland jurisdiction.
Other verified no logs VPN services
Since first writing this guide, there have been a few other VPNs that have undergone audits to verify their privacy and security claims.
1. IVPN – No logs VPN based in Gibraltar (audited)
First up is IVPN, a VPN provider based in Gibraltar. IVPN used Cure53 for the audit, which verified the privacy claims as follows: “Based on the findings, it is safe to say that all of the IVPN’s privacy statements could be verified as truthful within the defined scope.”
2. Private Internet Access – Two court cases proving no logs (but new ownership)
Private Internet Access is a United States-based provider that offers a cheap, simple, and user-friendly VPN service. While it’s not a bad service for the price, it does have some noteworthy drawbacks, which are also discussed in the PIA review.
- PIA sold out to Kape Technologies in November 2019. Kape is a company with a history of producing malware and adware. There are also some strange ties between Kape leadership and foreign surveillance agencies.
- PIA is based in the United States, a Five Eyes surveillance country.
PIA’s no logs claims have been tested and proven in two separate court cases:
- In a 2016 course case, PIA was subpoenaed by the FBI for logs, but PIA testified in court that it had no logs to hand over. This is explained in official court documents.
- Once again, in 2018, another court case put PIA’s no-logs policy to the test. As explained in this news article, Private Internet Access officially testified that it did not have any logs it could hand over to authorities.
Unfortunately, the recent news about PIA being acquired by Kape Technologies is unsettling. Check out the PIA review for in-depth test results and analysis.
3. PureVPN – No-logs audit (after providing logs to authorities)
In an attempt to regain trust among the VPN community after the logging case a few years ago, PureVPN has undergone an audit of its own.
The auditing firm that PureVPN used was Altius IT based in California, which conducted the audit remotely (no on-site investigations). The audit concluded in June 2019 and verified that PureVPN now aligns with its no-logs policies. Whether or not PureVPN can be trusted, after already providing logs to authorities, is a question you must answer.
I’ll update this guide as more VPNs undergo audits or some other verification test of their logging claims.
Conclusion on VPNs with no logs
With high-profile logging cases eroding user trust, such as with PureVPN and IPVanish, it is now more important than ever to verify that a VPN’s claims are actually true.
Another issue is that there’s no widely accepted definition of exactly what “no logs” means.
In light of all these factors, it’s great to see that there are VPNs taking proactive steps to verify and audit their own policies. This helps to build trust and maintain a higher level of honesty in the industry.
While there will always be bad apples in the VPN world, there are still a small number of trustworthy VPNs that have properly earned the title of “no logs” services.
As a brief overview, here are the best no logs VPN services that have been proven and verified:
- ExpressVPN – Based in the British Virgin Islands; $6.67 per month
- NordVPN – Based in Panama; $3.49 per month
- VyprVPN – Based in Switzerland; $3.75 per month
- Perfect Privacy – Based in Switzerland; $8.95 per month
Last updated on December 7, 2019 with new information.