Can you trust any VPN that claims to have a “no logs” policy? This guide examines all “no logs” VPN services that have actually been verified and proven true.
What is the best no logs VPN service and which of them are trustworthy and proven?
This is a tough question. First, there are dozens of VPNs claiming to be “no logs” without any proof or verification whatsoever. In other words, you just have to take their word at face value. But herein lies the problem.
VPNs have been caught lying about their “no logs” claims
Over the past five years, I have identified a few dishonest “no logs” VPNs that have collected user data and provided the information to government agencies. Here are three examples:
- PureVPN claimed to be “zero logs” but was caught logging customer data for the FBI.
- IPVanish also claimed to be “no logs” but then collected logs and provided the data to the FBI.
- HideMyAss provided logs to US authorities for an alleged hacking case.
There are surely other cases of this happening that have not come to light. We only know about the examples above from court documents that were released to the public detailing how the VPNs gave up logs.
We recommend no-logs VPNs that have been verified
Fortunately, there have been a handful of VPN services that have had their no-logs claims tested and verified to be true. We will examine these VPN providers below and exactly how their logging policies have been verified.
Here are the best no logs VPN services in 2021:
1. NordVPN: Verified with two no-logs VPN audits
|Logs||No logs (audited)|
|Support||24/7 Live chat|
NordVPN is one of the leading VPN services on the market that excels in many areas. The company behind NordVPN, Nord Security, is comprised of a global team and strategically based in Panama, which is one of the best privacy jurisdictions in the world. Unlike the UK and United States, Panama is not a member of international spy alliances and also does not require mandatory data retention, allowing NordVPN to be a 100% no logs service.
NordVPN offers a wide selection of apps, excellent speeds, and more privacy and security features than most other VPNs. In the latest round of testing for the NordVPN review, it performed very well in all categories.
NordVPN now fully supports the WireGuard VPN protocol in all NordVPN apps, offering users faster speeds and upgraded security. We were able to hit 445 Mbps with NordVPN in testing out WireGuard vs OpenVPN speeds. This makes NordVPN the fastest VPN we have tested:
NordVPN uses the strongest encryption standards and also includes built-in leak protection (VPN kill switch) with all VPN apps. Additionally, NordVPN also offers these privacy and security features:
- Double-VPN servers to encrypt traffic over two different locations
- Tor-over-VPN servers that also encrypt traffic through the Tor network
- P2P servers for high-speed downloading and file sharing (NordVPN is ranked as the best VPN for torrenting)
- Obfuscated servers to hide VPN traffic to look like regular HTTPS encryption and also get around VPN blocks
- CyberSec feature to block ads, trackers, and malware domains
Here is the NordVPN desktop app for Windows that we tested:
NordVPN is easily one of the best VPNs you will find in terms of privacy features and performance. And for those who need a VPN for streaming, NordVPN has you covered. It fully supports all major Netflix regions, and is also a great VPN for BBC iPlayer, Hulu, Amazon Prime, Disney Plus, and more. They even have a dedicated app if you need a VPN for Firestick.
NordVPN audited by PWC to verify no logs claims (twice)
NordVPN has now undergone two separate no-logs audits performed by PricewaterhouseCoopers (PWC) AG in Switzerland. The auditors confirmed that NordVPN was fully compliant with its no logging policies. The first audit was conducted in 2019, with the second audit being done in 2020.
It appears that NordVPN may undergo annual no-logs audits for verification purposes, which is great to see. Here is an overview of the scope of the audits:
- NordVPN was audited by PricewaterhouseCoopers. PWC had full access to examine NordVPN’s servers, interview employees, observe operations, inspect configurations, databases, and any other relevant aspect of the VPN service.
- NordVPN does not store connection logs, IP addresses, traffic logs, or any internet activity information.
The audit confirmed NordVPN’s logging policy, which you can read on their website as follows:
NordVPN strictly keeps no logs of your activity online. That means we do not track the time or duration of any online session, and neither do we keep logs of IP addresses or servers used, websites visited or files downloaded. In other words, none of your private and secure data is logged and gathered at any time. As a result, we are not able to provide any details about your behavior online, even if you request it yourself.
NordVPN is outside of the EU and US jurisdiction and is not required to collect your personal data and information– it means nothing is recorded, monitored, stored, logged or passed to third parties.
In addition to the no-logs policies, NordVPN has also implemented big security upgrades and new features.
Server upgrades: RAM-disk and colocation
NordVPN was one of the first VPN providers to transition its entire network to run in RAM-disk mode, without any hard drives. By running in volatile memory (RAM), not a single VPN server has the capability to store any data. This also means that no third-party entity will be able to steal a NordVPN server and recover user data. It provides NordVPN users with a higher level of data security.
Another major development with NordVPN is that they are working to roll out a network composed entirely of self-owned servers (also known as colocated servers). A few locations are already live now, and more are coming online in the coming months. Here are the benefits of self-owned servers:
- NordVPN will have 100% control over the hardware
- No more relying on rental servers from third parties (what most other VPNs do)
- Higher level of data security for NordVPN users.
In short, NordVPN is making leaps and bounds in the areas of privacy and security on a network-wide level.
Security audits and Bug Bounty program
We’ve already talked about the two no-logs (privacy) audits that NordVPN completed. But that’s not all. NordVPN has also completed an in-depth security audit with Versprite. This audit included penetration testing and analysis of all NordVPN infrastructure, to include all data centers where NordVPN servers are located.
Lastly, NordVPN is one of the few VPNs to have a public Bug Bounty program. This rewards anyone for finding bugs, problems, or security issues that could affect NordVPN users. Most VPNs do not offer anything like this.
Conclusion: NordVPN’s no logs policies, favorable jurisdiction, strong security, and excellent performance make it a great choice for all types of users. It works well with all streaming services and also offers many privacy features. With the coupon below, NordVPN is one of the best values available for a no logs VPN.
- Big discounts only available for long-term subscriptions
Check out our in-depth NordVPN review for more info.
2. ExpressVPN: Third-party no-logs audit and verification
|Based in||British Virgin Islands|
|Logs||No logs (audited)|
|Support||24/7 Live chat|
ExpressVPN is another privacy-focused, no-logs VPN that is based in the British Virgin Islands. It offers excellent performance, strong security, and user-friendly VPN apps. And like NordVPN, ExpressVPN is also a great streaming VPN service. It is one of the few VPNs that work with Netflix, Hulu, Disney Plus, and most other streaming services.
In terms of speeds and security, ExpressVPN is a strong contender. They support the OpenVPN and IKEv2 protocols with an AES-256 cipher. They have also launched the Lightway protocol, which offers better speeds and reliability than OpenVPN and has many similarities to WireGuard. However, even with Lightway, ExpressVPN still came in second place with speeds our Surfshark vs ExpressVPN comparison.
Check out the ExpressVPN review for a detailed analysis and all test results.
Now let’s examine how ExpressVPN’s no-logs policies have been tested and verified.
ExpressVPN implements TrustedServer (RAM-disk servers)
Similar to NordVPN, ExpressVPN has also upgraded its network to run in RAM-disk mode. They call this the TrustedServer feature. And as they point out, this is a major improvement from a privacy and security standpoint:
With our industry-first TrustedServer technology, our VPN servers run only on volatile memory (RAM), not on hard drives. Since RAM requires power to store data, this guarantees that all information on a server is wiped every time it is powered off and on again.
In contrast, the traditional and most common way of running servers relies very much on hard drives, which retain all data until they are erased and written over, a painstaking and error-prone process. This increases the risk that servers could inadvertently contain sensitive user information. If someone were to hack or seize the server, they could gain access to this data. Even worse, hackers who do find their way in might be able to install a backdoor that remains indefinitely.
We see other VPN services have also adopted this server approach, including with NordVPN and Surfshark.
ExpressVPN has also passed a third-party audit that was conducted by PricewaterhouseCoopers. This security audit verified the TrustedServer feature, no logs policy, and that all privacy protections are being adhered to correctly. Very few VPNs have undergone third-party audits to verify logging policies.
Lastly, ExpressVPN also decided to open source their browser extensions and subject them to a full security audit by Cure53. Cure53 is a well-regarded cybersecurity firm based in Berlin that has also audited other VPNs, such as TunnelBear.
Turkish police seize ExpressVPN server (but no data)
In addition to audits, ExpressVPN has also passed a real-world test.
In December 2017, Turkish news outlets reported that police in Turkey attempted to force ExpressVPN to provide customer data for a criminal investigation. However, ExpressVPN did not have any logs to provide authorities, as they explained in a statement.
After failing in their attempts to coerce data from ExpressVPN, the Turkish police then decided to physically seize ExpressVPN’s server, which they obtained from a data center in Turkey. However, this also did not reveal any information because ExpressVPN does not keep any logs on its servers – or otherwise.
ExpressVPN further clarified that all customer data was safe when they issued a statement on the case:
As we stated to Turkish authorities in January 2017, ExpressVPN does not and has never possessed any customer connection logs that would enable us to know which customer was using the specific IPs cited by the investigators. Furthermore, we were unable to see which customers accessed Gmail or Facebook during the time in question, as we do not keep activity logs. We believe that the investigators’ seizure and inspection of the VPN server in question confirmed these points.
Conclusion: ExpressVPN is another solid choice for a no-logs VPN service that has been completely verified and proven true. It does well in many areas. However, as we pointed out in the ExpressVPN vs NordVPN comparison, ExpressVPN does not offer as many features as other leading VPNs. The speeds are also not on par with other leading VPNs, such as NordVPN, which uses the WireGuard protocol.
And while ExpressVPN does have an above average price, you can still take advantage of the coupon below.
- Above average prices
- Fewer features than other leading VPNs
- Average speeds (not as fast as NordVPN)
See our ExpressVPN review for more info and test results.
3. VyprVPN: No logs verified with audit
|Logs||No logs (audited)|
|Support||Chat and email|
VyprVPN is a no logs VPN service based in Switzerland with secure apps and good performance. It did well in speed tests for the VyprVPN review and has a pretty good reputation. VyprVPN is unique in that they physically own every server in their network (no rentals from third parties), which helps to ensure data security.
If you want a VPN to get around blocks, then VyprVPN is a great choice. It offers the Chameleon protocol, which will get around most VPN blocks and restrictions. This is important when using a VPN for China.
Following the lead of NordVPN, VyprVPN has now also implemented the WireGuard VPN protocol into their service. We were able to hit speeds of up to 300 Mbps, which we posted in the VyprVPN review. And while this is certainly fast, VyprVPN still came out behind in the VyprVPN vs NordVPN comparison.
No logs: VyprVPN audited / advised by cybersecurity firm
To verify the no logs policies, VyprVPN underwent an independent audit conducted by Leviathan Security Group. The auditors examined all aspects of VyprVPN’s network to identify areas where logs were maintained that could de-anonymize the user. After fixing a few issues, they re-tested everything and found VyprVPN to be in full compliance with their stated “no logs” policy.
VyprVPN’s security audit is available to the public here and can be referenced publicly. Here are a few sections:
We examined all components of the project according to the threat assessment described below. While vigilance against logging is necessary to complete the process of implementing “No Log”, we feel that this assessment achieved its goal of uncovering weaknesses in Golden Frog’s implementation. The project revealed a limited number of issues that Golden Frog quickly fixed. As a result, it can provide VyprVPN users with the assurance that the company is not logging their VPN activity.
Golden Frog worked to remediate all no-log-related findings concurrently with the assessment. Once it had completed this, we performed a retest and verified that all of the fixes were effective.
Before this change took place, VyprVPN logged connection data (including IP addresses) for 30 days. Now, VyprVPN can be counted among the small number of verified no logs VPN services.
- No cryptocurrency payment options
- Fewer features
- Requires full name for registration (not good for privacy)
See the VyprVPN review for more information and test results.
4. Perfect Privacy: Real-world verification of no logs
|Support||Email & forum|
Perfect Privacy is a Switzerland-based VPN that offers advanced online anonymity and security features. It is a no logs service that does not restrict user accounts in any way, giving you an unlimited number of connections. Privacy features include multi-hop VPN configurations, port forwarding, and a TrackStop feature to block ads, trackers, malware, and phishing domains.
From the beginning, Perfect Privacy has focused their service on privacy and anonymity, never keeping logs of any kind and not limiting VPN connections in any way.
The two main drawbacks with Perfect Privacy are the high prices and the lack of support for streaming services. While Perfect Privacy is not the best VPN for streaming, it does well in the areas of privacy and security. mm
Perfect Privacy server seized in the Netherlands
Even though Perfect Privacy has not undergone a third-party audit, like our other top recommendations, it has passed a real-world test. A few years ago, Perfect Privacy announced that Dutch authorities had seized one of their servers in Rotterdam, Netherlands. Although the reason for seizing the server was never revealed, Perfect Privacy confirmed no customer data was obtained:
Since we are not logging any data there is currently no reason to believe that any user data was compromised.
…We can now conclude that no customer information was compromised due to the seizure. The Rotterdam location will continue to operate using the replacement servers.
RAM-disk servers (no logs possible)
Just like with ExpressVPN and NordVPN, Perfect Privacy runs all their servers in RAM-disk mode. They explain the reasoning for this on their log policy page:
Our infrastructure is built on this philosophy: All our services are running within strongly encrypted RAM disks so that it is technically impossible for data to be stored on hard drives. This also means that no data can be recovered if the power is disconnected.
Nobody can force us to log your data. If that were the case we would rather discontinue Perfect Privacy than to record your data and compromise your privacy.
While Perfect Privacy does have some drawbacks, it remains a great option for privacy-focused users.
- Above average prices
- Limited support for streaming services
- No iOS app
Our Perfect Privacy review has more info and test results.
5. OVPN – A no-logs VPN in Sweden
|Support||Email and chat|
OVPN is a smaller VPN provider in Sweden that takes privacy very seriously. When it comes to logs, they have been a zero-logs VPN service from the beginning. In fact, they even have insurance to cover legal fees for court costs to fight any data requests. They also publish regular transparency reports documenting anything that could affect customer data and privacy.
Similar to NordVPN and Surfshark, OVPN offers double-hop VPN servers and also an ad-blocking feature. The desktop apps for Linux, Windows, and Mac OS all incorporate leak protection and strong encryption. And like NordVPN, OVPN supports WireGuard for even better speeds compared to other protocols.
OVPN wins court case proving no-logs claims
In September 2020, OVPN won a court battle proving that it does not keep any logs. The case centered around a movie company that was demanding user data and logs for a public IPv4 address, presumably for a copyright violation issue.
OVPN won the case by successfully proving that they do not have any logs to provide:
To summarize the verdict, the Rights Alliance and their security experts have not been able prove any weaknesses in OVPN’s systems that could mean that logs are stored. OVPN therefore wins the information injunction as our statements and evidence regarding our no log VPN policy have not been disproven. The movie companies also need to pay OVPN’s legal fees.
It’s also worth noting that OVPN uses only dedicated bare-metal servers running in RAM-disk mode. This further ensures there is no user data available for anyone to go after.
- Small server network
- Above average prices with a short refund window
- Limited support for streaming services
See the OVPN review for more info.
Other verified no logs VPN services
Since first writing this guide, there have been a few other VPNs that have undergone audits to verify their privacy and security claims.
1. IVPN: No logs VPN based in Gibraltar (audited)
First up is IVPN, a VPN provider based in Gibraltar. IVPN used Cure53 for the audit, which verified the privacy claims as follows: “Based on the findings, it is safe to say that all of the IVPN’s privacy statements could be verified as truthful within the defined scope.”
2. Private Internet Access: Two court cases proving no logs (but now under new ownership)
Private Internet Access is a United States-based VPN that offers a low-cost, simple, and user-friendly VPN service. While it remains a decent cheap VPN service, it does have some noteworthy drawbacks. Here were a few issues that I discussed in the PIA review.
- PIA sold out to Kape Technologies in November 2019. Kape is a company with a history of producing malware and adware. There are also some strange ties between Kape leadership and foreign surveillance agencies.
- PIA is based in the United States, a Five Eyes surveillance country.
- When it comes to Netflix and other streaming services, PIA is often blocked.
PIA’s no logs claims have been tested and proven in two separate court cases:
- In a 2016 court case, PIA was subpoenaed by the FBI for logs, but PIA testified in court that it had no logs to hand over. This is explained in official court documents.
- Once again, in 2018, another court case put PIA’s no-logs policy to the test. As explained in this news article, Private Internet Access officially testified that it did not have any logs it could hand over to authorities.
Unfortunately, even with these court cases, there’s no way to know if PIA is collecting logs today. In the United States, any business can be forced to collect user data for government, and there are examples of this happening with VPNs and private email services. (We’ll examine this more below.)
Note: PIA has really dropped in speeds recently, which we covered in the NordVPN vs PIA comparison report. This is not the best VPN if you value performance.
3. PureVPN: No-logs audit (after providing logs to authorities)
In an attempt to regain trust among the VPN community after the logging case a few years ago, PureVPN has undergone an audit of its own.
The auditing firm that PureVPN used was Altius IT based in California, which conducted the audit remotely (no on-site investigations). The audit concluded in June 2019 and verified that PureVPN now aligns with its no-logs policies. Whether or not PureVPN can be trusted, after already providing logs to authorities, is a question you must answer.
Jurisdiction and logging policies with VPN services
One thing to consider with any VPN service is jurisdiction: where the VPN is legally based.
Jurisdiction is an important factor to consider because it greatly affects the security of the VPN’s customers. A VPN must abide by the laws in the country in which it is legally based (incorporated). Many countries have laws that can undermine encryption and data security, for example:
Australia and access to encrypted data
Australia has a law that allows governments to force companies to provide access to encrypted data. We discuss this topic at length in our guide on VPNs for Australia. Here’s a brief synopsis of this law:
The Australian Parliament passed a contentious encryption bill on Thursday to require technology companies to provide law enforcement and security agencies with access to encrypted communications.
Privacy advocates, technology companies and other businesses had strongly opposed the bill, but Prime Minister Scott Morrison’s government said it was needed to thwart criminals and terrorists who use encrypted messaging programs to communicate.
Right now, the United States is considering similar legislation, which you can read about here.
United States can force companies to hand over logs
The US is also a hostile jurisdiction for privacy. Here, authorities can force companies to hand over data logs and provide access to user information. Here are three examples:
- Lavabit was forced to provide encryption keys to its email service. Rather than comply, the owner shut down the company.
- Riseup, a secure email and VPN service in Seattle, was forced to hand over user data to the FBI and also slapped with a gag order that prevented any disclosure.
- IPVanish, a “zero logs” VPN, provided user logs to the FBI for a criminal investigation.
Choose your VPN carefully and also consider jurisdiction. We recommend going with a VPN service in a safe privacy jurisdiction, such as Panama, the British Virgin Islands, Switzerland, and others.
Free VPNs caught collecting data logs
Free VPN services can also be problematic when it comes to VPN logs and data collection. Over the years, we have profiled the many reasons you may want to avoid a free VPN. One of the biggest issues is how free VPNs make money.
To cover the costs of server hosting, app development, and everything else, free VPNs typically make money off the user itself. To do this, they usually collect user data, which can then be sold to third parties, such as advertisers. This is actually a growing business model and there are numerous VPNs that utilize tracking or data collection tools. We discovered this in our Hotspot Shield VPN review. It was also the case in our Betternet review.
Free VPNs are often in the news for bad practices. One recent example highlighted free VPN apps that deliver financial malware to unsuspecting victims. If something is free, then you are likely the product. The only exception to this is the freemium business model, where you get a limited free version, but can update to a paid version. These are probably the best free VPN services.
Conclusion on VPNs with no logs
With high-profile logging cases eroding user trust, such as with PureVPN and IPVanish, it is now more important than ever to verify that a VPN’s claims are actually true.
To be sure, maintaining some connection logs is not necessarily a deal-breaker, especially if it is done in an honest and transparent manner, such as with VPN.ac. The problem, however, is that many VPNs simply use “no logs” as a marketing slogan, without any kind of verification.
Another issue is that there’s no widely accepted definition of exactly what “no logs” means.
In light of all these factors, it’s great to see that there are VPNs taking proactive steps to verify and audit their own policies. This helps to build trust and maintain a higher level of honesty in the industry.
While there will always be bad apples in the VPN world, there are still a small number of trustworthy VPNs that have properly earned the title of “no logs” services.
The table below includes the best no logs VPN services that have been proven and verified:
Updated with new information June 15, 2021.