AnonymFlow
securite-reseauINFO

No-Log VPN: What the Promise Is Actually Worth, and What an Audit Does Not Prove

Every VPN says it keeps no logs. It is the one claim you cannot verify from your side, whatever you test. What an audit really covers, why the EFF says a claim is not a guarantee, and how to decide without pretending you checked.

By Eric Gerard · Editor · AnonymFlow4 min readPhoto via Pexels

There is one thing about a VPN you cannot test. You can check that your IP is masked, that DNS does not leak, that the kill switch fires. All of that happens on your machine and you can watch it. What the provider writes down about you happens on their machines, and no amount of testing from your side will ever show it.

The claim that cannot be checked from here

"No logs" is the industry's universal promise, and its universality should already tell you something: a claim that every competitor makes, at no cost, carries no information by itself.

The Electronic Frontier Foundation puts it plainly in its Surveillance Self-Defense guide: "Remember that a claim is not a guarantee, so be sure you verify these claims." And more bluntly still: "Even if a company claims not to log connection data, this is not a guarantee of good behavior."

That is not cynicism. It is the correct description of an asymmetric situation. You are being asked to trust an absence, and an absence leaves no trace you can inspect.

Grey metal cabinet doors, each carrying a blank yellow card and a small printed label reading BIN 11, BIN 12, BIN 14, BIN 15. The labels tell you the drawers exist. They tell you nothing about what is inside, and you cannot open them.
Grey metal cabinet doors, each carrying a blank yellow card and a small printed label reading BIN 11, BIN 12, BIN 14, BIN 15. The labels tell you the drawers exist. They tell you nothing about what is inside, and you cannot open them.

What an independent audit does, and where it stops

Audits are the industry's answer, and they are genuinely worth something. A third party looks at configurations, servers, sometimes source code, and publishes what it found. The EFF acknowledges the value: an audit can "reveal otherwise unknown security vulnerabilities".

Then comes the sentence that most summaries leave out. "There's no certainty that the practices aren't changed after the audit, especially if compelled to do so by a government."

An audit is a photograph, not a film. It describes a scope, chosen in advance, at a moment, in a place. It does not follow the company afterwards, it does not cover what a court order might change next month, and it usually does not cover every server in every country. None of that makes audits worthless. It makes them evidence about a past state rather than a guarantee about a future one.

Reading a policy without pretending

If the claim cannot be verified, what remains is reading carefully. Three things repay attention.

What counts as a log. Connection metadata, timestamps, bandwidth totals and the number of simultaneous devices are all data, and a provider can retain some of them while truthfully saying it keeps no activity logs. The interesting question is never "do you keep logs" but "what exactly do you keep, and for how long".

Where the company answers to. Jurisdiction decides who can compel what, and with what obligation to tell you. A policy is written under a legal system, and the system can override the policy.

What the record shows. The EFF advises looking at actual reporting, noting that some providers "have been caught misleading or lying to their customers". Past behaviour is not proof of future behaviour, but it is the only empirical evidence available in a field built on unverifiable claims.

The advice that follows

The EFF's own conclusion is short and worth adopting: "Do not use a VPN that you do not trust." They add that they cannot vouch for any VPN or for any rating, which is a level of honesty rarely found on pages that rank for this query.

Practically, that means the decision is about trust and structure rather than about the marketing sentence. What is the company, where does it answer, what has it published, what has it done when tested. Our comparison of two providers built around minimal data looks at what that structure can look like in practice.

And for everything that is testable on your side, the complete security audit covers the nine checks you can actually run yourself.

The honest bottom line

A no-log claim is not worthless, and it is not proof. It is a promise whose value comes entirely from who is making it and what happens to them if it turns out to be false. Anyone telling you they verified a provider keeps no logs is describing something they cannot have done.

Editorial pick
4.6 / 5

Secure your connection with NordVPN

Threat Protection blocks trackers & malware · kill switch · 30-day money-back

Deloitte audit 202430-day guarantee14M+ users
See the offer
Everything you need to know.

Frequently asked questions

Can you verify that a VPN keeps no logs?

Not from your side. Everything you can test happens on your own machine: IP masking, DNS leaks, the kill switch. What a provider records happens on its infrastructure. The EFF states directly that a claim is not a guarantee and that a company claiming not to log connection data is not a guarantee of good behaviour.

Does an independent audit prove a VPN keeps no logs?

It proves something narrower and still useful. An audit can reveal otherwise unknown security vulnerabilities, but as the EFF notes, there is no certainty that practices are not changed after the audit, especially under government compulsion. An audit describes a chosen scope at a moment in time, not a permanent state.

What counts as a log?

More than browsing history. Connection metadata, timestamps, bandwidth totals and simultaneous device counts are all data a provider may retain while truthfully saying it keeps no activity logs. The useful question is not whether logs exist but exactly what is kept and for how long.

Does the provider's country matter?

Yes, because jurisdiction decides who can compel disclosure and whether the company may tell you about it. A privacy policy is written inside a legal system, and that system can override the policy. This is why jurisdiction appears in every serious discussion of no-log claims.

So how do you choose?

By deciding who you trust, which is what the EFF recommends when it says not to use a VPN you do not trust and that it cannot vouch for any provider or rating. Look at what the company is, where it answers, what it has published, and how it has behaved when actually tested. Treat the marketing sentence as the least informative part.