There is one thing about a VPN you cannot test. You can check that your IP is masked, that DNS does not leak, that the kill switch fires. All of that happens on your machine and you can watch it. What the provider writes down about you happens on their machines, and no amount of testing from your side will ever show it.
The claim that cannot be checked from here
"No logs" is the industry's universal promise, and its universality should already tell you something: a claim that every competitor makes, at no cost, carries no information by itself.
The Electronic Frontier Foundation puts it plainly in its Surveillance Self-Defense guide: "Remember that a claim is not a guarantee, so be sure you verify these claims." And more bluntly still: "Even if a company claims not to log connection data, this is not a guarantee of good behavior."
That is not cynicism. It is the correct description of an asymmetric situation. You are being asked to trust an absence, and an absence leaves no trace you can inspect.

What an independent audit does, and where it stops
Audits are the industry's answer, and they are genuinely worth something. A third party looks at configurations, servers, sometimes source code, and publishes what it found. The EFF acknowledges the value: an audit can "reveal otherwise unknown security vulnerabilities".
Then comes the sentence that most summaries leave out. "There's no certainty that the practices aren't changed after the audit, especially if compelled to do so by a government."
An audit is a photograph, not a film. It describes a scope, chosen in advance, at a moment, in a place. It does not follow the company afterwards, it does not cover what a court order might change next month, and it usually does not cover every server in every country. None of that makes audits worthless. It makes them evidence about a past state rather than a guarantee about a future one.
Reading a policy without pretending
If the claim cannot be verified, what remains is reading carefully. Three things repay attention.
What counts as a log. Connection metadata, timestamps, bandwidth totals and the number of simultaneous devices are all data, and a provider can retain some of them while truthfully saying it keeps no activity logs. The interesting question is never "do you keep logs" but "what exactly do you keep, and for how long".
Where the company answers to. Jurisdiction decides who can compel what, and with what obligation to tell you. A policy is written under a legal system, and the system can override the policy.
What the record shows. The EFF advises looking at actual reporting, noting that some providers "have been caught misleading or lying to their customers". Past behaviour is not proof of future behaviour, but it is the only empirical evidence available in a field built on unverifiable claims.
The advice that follows
The EFF's own conclusion is short and worth adopting: "Do not use a VPN that you do not trust." They add that they cannot vouch for any VPN or for any rating, which is a level of honesty rarely found on pages that rank for this query.
Practically, that means the decision is about trust and structure rather than about the marketing sentence. What is the company, where does it answer, what has it published, what has it done when tested. Our comparison of two providers built around minimal data looks at what that structure can look like in practice.
And for everything that is testable on your side, the complete security audit covers the nine checks you can actually run yourself.
The honest bottom line
A no-log claim is not worthless, and it is not proof. It is a promise whose value comes entirely from who is making it and what happens to them if it turns out to be false. Anyone telling you they verified a provider keeps no logs is describing something they cannot have done.
Secure your connection with NordVPN
Threat Protection blocks trackers & malware · kill switch · 30-day money-back



