|Verified No Logs VPNs|
This guide examines all “no logs” VPN services that have been verified and proven to be true. (Updated with new information on August 20, 2019.)
What is the best no logs VPN service and which of them are actually trustworthy and proven?
This is a tough question. First, there are dozens of VPNs claiming to be “no logs” without any proof or verification whatsoever. In other words, you just have to take their word at face value.
Second, there have been a few “no logs” VPNs that have collected user data and provided the information to authorities and law enforcement. Here are three examples:
- PureVPN was caught logging customer data for the FBI
- IPVanish also collected logs on one of their users and provided the data to the FBI
- HideMyAss provided logs to authorities for a hacking case
There are surely other cases of this happening which have not come to light.
So how can you find a true no-logs VPN that is actually worth your trust?
Fortunately, there have been a handful of VPN services over the years that have had their ‘no logs’ policies tested under various circumstances. We will examine these different providers below and the exact circumstances under which their ‘no logs’ policies were verified.
Here are the best no logs VPN services:
1. ExpressVPN: Third-party audit & real-world verification
|Based in||British Virgin Islands|
|Support||24/7 Live chat|
Overview: ExpressVPN is based in the British Virgin Islands and it’s currently the top recommendation in my comparison of the best VPNs. It offers user-friendly VPN apps with excellent performance and security. ExpressVPN is also one of the few VPNs that work with Netflix, BBC iPlayer, and other streaming services.
In terms of speeds, ExpressVPN one of the fastest VPNs I’ve tested. I can routinely get around 150 Mbps on nearby servers (with a 160 Mbps connection). Check out the ExpressVPN review for a detailed analysis and all test results.
Now let’s examine how ExpressVPN’s no-logs policies have been tested and verified.
ExpressVPN implements TrustedServer and undergoes audit
In April 2019, ExpressVPN upgraded their server infrastructure so all VPN servers run in RAM-disk mode. They refer to this as the TrustedServer feature. This update ensures nothing can be stored on any VPN server as it does away with traditional hard drives. As they explained here, this is a major improvement from a privacy and security standpoint:
With our industry-first TrustedServer technology, our VPN servers run only on volatile memory (RAM), not on hard drives. Since RAM requires power to store data, this guarantees that all information on a server is wiped every time it is powered off and on again.
In contrast, the traditional and most common way of running servers relies very much on hard drives, which retain all data until they are erased and written over, a painstaking and error-prone process. This increases the risk that servers could inadvertently contain sensitive user information. If someone were to hack or seize the server, they could gain access to this data. Even worse, hackers who do find their way in might be able to install a backdoor that remains indefinitely.
Competitor Perfect Privacy also runs all servers in RAM-disk mode, which seems to be the safest and most secure setup.
In July 2019, ExpressVPN underwent a third-party audit from PricewaterhouseCoopers. This security audit verified the TrustedServer feature, no logs policy, and that all privacy protections are being adhered to correctly.
Lastly, ExpressVPN also decided to open source their browser extensions and subject them to a full security audit by Cure53. This again sets the bar high and shows ExpressVPN is committed to security, transparency, and safeguarding user data.
ExpressVPN server seized in Turkey
In December 2017, Turkish news outlets reported that Turkish authorities attempted to force ExpressVPN to provide customer data for an investigation into a political assassination. According to these reports, Turkish authorities allege that an unknown individual using ExpressVPN deleted evidence on social media related to the investigation.
While the Turkish news article falsely claims ExpressVPN is based in the US (when it’s in fact based in the British Virgin Islands), it does reveal that the authorities’ attempts to collect user data failed:
The prosecution’s contact with the company did not yield results as Express VPN stated that it is not subject to the rules of U.S. and EU laws.
After failing in their attempts to coerce data from ExpressVPN, the Turkish police then decided to physically seize ExpressVPN’s server, which they obtained from a data center in Turkey. However, this also did not reveal any information because ExpressVPN does not keep any logs on its servers – or otherwise.
ExpressVPN further clarified that all customer data was safe when they issued a statement on the case:
As we stated to Turkish authorities in January 2017, ExpressVPN does not and has never possessed any customer connection logs that would enable us to know which customer was using the specific IPs cited by the investigators. Furthermore, we were unable to see which customers accessed Gmail or Facebook during the time in question, as we do not keep activity logs. We believe that the investigators’ seizure and inspection of the VPN server in question confirmed these points.
Conclusion: As you can see above, ExpressVPN has gone above and beyond most VPN services in terms of securing customer data and validating their own servers, policies, and applications. Here’s a brief overview:
- All servers in their network were upgraded to run on RAM-disk, thereby making it impossible to store logs on the VPN server.
- An outside auditing firm (PWC) then audited the server network and privacy protections. This is in addition to the previous security audit of their browser extensions performed by Cure53.
- ExpressVPN’s logging claims were tested and verified when Turkish authorities seized an ExpressVPN server and were unable to obtain any data.
If you want to give ExpressVPN a test drive, see the ExpressVPN coupon for three months free.
2. NordVPN: Third-party logs audit
|Support||24/7 Live chat|
Overview: NordVPN is a no logs provider based in Panama that offers a wide selection of apps for a decent price. In the latest round of testing for the NordVPN review, it performed well in all categories. NordVPN’s VPN apps also have strong leak protection settings as well as advanced privacy features, such as double-hop VPN servers, Tor-over-VPN servers, and obfuscated servers.
NordVPN audited by PWC to verify no logs claims
In November 2018 NordVPN announced on its website that it had completed a full audit to verify their no-logs claims. The audit was conducted by PricewaterhouseCoopers and fully verified the no-logs policy.
NordVPN subscribers can get access to the full audit in the members area. I carefully examined the findings for this guide and can offer this overview:
- NordVPN was audited by PricewaterhouseCoopers. PWC had full access to examine NordVPN’s servers, interview employees, observer operations, inspect configurations, databases, and any other relevant aspect of the VPN service.
- NordVPN does not store connection logs, IP addresses, traffic logs, or any internet activity information.
Because NordVPN limits users to six connections per subscription, it does have a mechanism in place to verify the user’s account and ensure the device connection limit is not being exceeded. This is common for VPN services that implement connection limits (nearly every VPN service) and does not pose any threat to user privacy or security, nor violate the logging claims – ad the audit verified.
The audit confirmed NordVPN’s logging policy, which you can read on their website as follows:
NordVPN strictly keeps no logs of your activity online. That means we do not track the time or duration of any online session, and neither do we keep logs of IP addresses or servers used, websites visited or files downloaded. In other words, none of your private and secure data is logged and gathered at any time. As a result, we are not able to provide any details about your behavior online, even if you request it yourself.
NordVPN is based away from the EU and US jurisdiction and is not required to collect your personal data and information– it means nothing is recorded, monitored, stored, logged or passed to third parties.
3. VyprVPN: Third-party logs audit
|Support||24/7 live chat|
Overview: VyprVPN is a no logs VPN service based in Switzerland with very secure apps and excellent performance. It offers secure and user-friendly apps for many different devices and speed tests for the VyprVPN review were pretty good. VyprVPN is unique in that they physically own every server in their network (no rentals from third parties), which helps to ensure data security. They also offer the Chameleon protocol, which will get around VPN blocks and restrictions (important when using a VPN for China).
No logs transition: VyprVPN audited / advised by cybersecurity firm
In September 2018 VyprVPN began working with Leviathan Security Group to transition their service into a full “no logs” VPN service. The auditors examined all aspects of VyprVPN’s network to identify any areas where logs were maintained that could de-anonymize the user. After fixing a few issues, they re-tested everything and found VyprVPN to be in full compliance with their stated “no logs” policy.
VyprVPN’s security audit is available to the public here and can be referenced publicly. Here are a few sections:
We examined all components of the project according to the threat assessment described below. While vigilance against logging is necessary to complete the process of implementing “No Log”, we feel that this assessment achieved its goal of uncovering weaknesses in Golden Frog’s implementation. The project revealed a limited number of issues that Golden Frog quickly fixed. As a result, it can provide VyprVPN users with the assurance that the company is not logging their VPN activity.
Golden Frog worked to remediate all no-log-related findings concurrently with the assessment. Once it had completed this, we performed a retest and verified that all of the fixes were effective.
Before this change took place, VyprVPN logged connection data (including IP addresses) for 30 days. Now VyprVPN can be counted among the small number of verified no logs VPN services. See the VyprVPN review for more information and test results. You can also get a VyprVPN discount for 25% off annual plans.
4. Perfect Privacy: No logs VPN test
|Support||Email & forum|
Overview: Perfect Privacy is a premium, Switzerland-based VPN that offers advanced online anonymity and security features. It is a no logs service that does not restrict user accounts in any way. You get an unlimited number of connections to use with your subscription as well as very advanced privacy features and unlimited bandwidth. Privacy features include multi-hop VPN configurations, port forwarding, and an advanced advertisement and tracking blocker called TrackStop.
Perfect Privacy server seized in the Netherlands
In August 2016 Perfect Privacy announced that Dutch authorities had seized one of their servers in Rotterdam, Netherlands. Although the reason for seizing the server was never revealed, Perfect Privacy confirmed no customer data was obtained:
Since we are not logging any data there is currently no reason to believe that any user data was compromised.
…We can now conclude that no customer information was compromised due to the seizure. The Rotterdam location will continue to operate using the replacement servers.
To further protect customer data in the event of a server seizure, Perfect Privacy runs all their servers in RAM-disk mode, like ExpressVPN, as they explain on their log policy page:
Our infrastructure is built on this philosophy: All our services are running within strongly encrypted RAM disks so that it is technically impossible for data to be stored on hard drives. This also means that no data can be recovered if the power is disconnected.
Nobody can force us to log your data. If that were the case we would rather discontinue Perfect Privacy than to record your data and compromise your privacy.
While Perfect Privacy is a higher-priced service, it remains a great option for privacy and security, with a proven no logs policy and Switzerland jurisdiction.
5. Private Internet Access: No logs court cases
Overview: Private Internet Access is a United States-based provider that offers a cheap, simple, and user-friendly VPN service. While it’s not a bad service for the price, it does have some drawbacks. PIA is limited on features and I’ve also seen users complain about connections and support – discussed in the PIA review. Nonetheless, it may be worth considering if you don’t mind the US jurisdiction (Five Eyes) and some of the other minor drawbacks.
PIA logging claims verified in two court cases
Private Internet Access is somewhat unique in that its no logs claims have been verified in two separate US court cases. Since providing false information in a court of law is a serious offense, we can consider both of these cases to conclusively verify the “no logs” policy.
The first court case was from 2016 and it involved a man who allegedly made bomb threats while connected to PIA’s VPN. The FBI officially subpoenaed PIA demanding logs of the user, but they simply could not provide anything, as described in official court documents:
A subpoena was sent to London Trust Media [Private Internet Access] and the only information they could provide is that the cluster of IP addresses being used was from the east coast of the United States.
In a second case from June 2018, Private Internet Access was again subpoenaed in court for user logs and evidence related to a hacking case. As with the previous court case, Private Internet Access was not able to provide any data, because there were no logs available to hand over. Here is a brief summary from a news article discussing London Trust Media, which is the parent company of PIA:
John Allan Arsenault, general counsel for London Trust Media, a VPN company, testified about how many VPN companies, including his, intentionally don’t retain logs of internet activity of their clients so that they cannot be produced in response to subpoenas from law enforcement or others. London Trust Media operates the brand Private Internet Access (PIA), which owns several IP addresses used to hack Embarcadero Media.
Private Internet Access does not log user activity, such as what files they accessed or changes they made to a website.
Based on these two court cases, Private Internet Access can be considered a verified no logs VPN provider.
Check out the PIA review for in-depth test results and analysis.
Other verified VPN providers
Since first writing this guide, there have been a few other VPNs that have undergone audits to verify their privacy and security claims.
IVPN – First up is IVPN, a VPN provider based in Gibraltar. IVPN used Cure53 for the audit, which verified the privacy claims as follows: “Based on the findings, it is safe to say that all of the IVPN’s privacy statements could be verified as truthful within the defined scope.”
TunnelBear – TunnelBear is a VPN service based in Canada. It is now owned by the US cybersecurity company McAfee, although it still operates from Canada. It is important to note that TunnelBear does not claim to be a full “no logs” VPN service. Instead, they do keep some limited connection logs, but like other VPNs in this guide, they have undergone (and passed) a full audit. Similar to ExpressVPN and IVPN, TunnelBear also went with Cure53 for the audit.
I’ll update this guide as more VPNs undergo audits or some other verification test of their logging claims.
Conclusion on VPNs with no logs
With high-profile logging cases eroding user trust, such as with PureVPN and IPVanish, it is now more important than ever to verify that a VPN’s claims are actually true.
Another issue is that there’s no widely accepted definition of exactly what “no logs” even means.
In light of all these factors, it’s great to see that there are VPNs taking proactive steps to verify and audit their own policies. This helps to build trust and maintain a higher level of honesty in the industry.
While there will always be bad apples in the VPN world, there are still a small number of trustworthy VPNs that have properly earned the title of “no logs” services.
As a brief overview, here are the best no logs VPN services that have been publicly verified:
- ExpressVPN – Based in the British Virgin Islands; $6.67 per month
- NordVPN – Based in Panama; $3.49 per month
- VyprVPN – Based in Switzerland; $3.75 per month
- Perfect Privacy – Based in Switzerland; $8.95 per month
- Private Internet Access – Based in the United States; $3.49 per month
Last updated on August 20, 2019.