No-logs VPNs, and who checkedAuditors named, jurisdictions listed
Every provider claims no logs. Five of the seven we track name the outside firm that checked, and five state the law they operate under. Those are the two facts you can act on.
"No-logs" is on the front page of every VPN site, which makes it useless as a way of telling them apart. Two related facts are more useful because they can be checked: whether an outside organisation examined the claim and is named, and which country's law the provider operates under.
We collect both from the providers' own sites. Here is what that produces for the seven we track.
- Five of seven name the firm that examined their no-logs claim
- Three of those five were examined by Deloitte
- Mullvad names six separate organisations — the most in our set
- Five state their jurisdiction: Panama, the Netherlands, Sweden, the US, Canada
- Jurisdiction decides how a disclosure request is handled, whatever the policy says
What a no-logs policy is actually promising
There are two different things a provider might keep. Connection logs record that an account connected, when, and for how long — some providers keep a minimal version for billing and abuse handling. Activity logs record what travelled through: which sites, which addresses, which files.
Almost every provider claiming "no logs" means the second. Whether they also avoid the first varies, and it is the difference that matters if the question is whether a given account can be tied to a given session at a given time.
The whole record in one table
Three columns, all read from the providers' own sites: the country each operates under, the outside organisation that examined its no-logs claim, and how long you have to change your mind.
| VPN | Operates under | No-logs claim examined by | Money-back |
|---|---|---|---|
| ExpressVPN | Not published in our set | Not published in our set | 30 days |
| NordVPN | Panama | Deloitte | 30 days |
| Surfshark | the Netherlands | Deloitte | 30 days |
| CyberGhost | Not published in our set | Not published in our set | 45 days |
| Private Internet Access | the United States | Deloitte (Deloitte Audit Romania) | 30 days |
| Mullvad VPN | Sweden | Assured, Cure53, X41 D-Sec, Radically Open Security, Leviathan Security Group and NCC Group | 14 days |
| Windscribe | Canada | Packetlabs and Leviathan Security Group | 7 days |
Read by VPN LIFE from each provider's own site. "Not published in our set" means we have not been able to collect it, not that it does not exist.
Two of the seven publish none of it in the set we have collected, which is itself worth noticing when the same two appear at the top of most recommendation lists.
Why the auditor's name is the whole point
"Independently audited" with no name is not a claim you can check. With a name, you can find out who the firm is, what they were asked to examine, and when. Of the seven providers we track, five name one: Deloitte examined NordVPN, Surfshark and Private Internet Access (through Deloitte Audit Romania); Packetlabs and Leviathan Security Group examined Windscribe; and Mullvad names Assured, Cure53, X41 D-Sec, Radically Open Security, Leviathan Security Group and NCC Group.
One thing we cannot tell you from the providers' own pages is when each audit was last performed. A named audit from four years ago and one from last quarter read identically on a marketing page. We say so rather than implying the dates are current.
Jurisdiction decides what the policy is worth
A no-logs policy is a promise about what a company chooses to store. Jurisdiction determines what it can be compelled to do. The five providers that publish theirs operate under the law of Panama (NordVPN), the Netherlands (Surfshark), Sweden (Mullvad), the United States (Private Internet Access) and Canada (Windscribe).
Readers weigh these differently, and reasonably so. Some rule out any provider under US jurisdiction on principle. Others note that a company with nothing stored has nothing to hand over regardless of where it sits — which is the argument the audits are supposed to support. Both positions are defensible; what is not defensible is not knowing which country you are dealing with.
The provider that takes it furthest
Mullvad is worth separating out. You can open an account without giving an email address — the account is a randomly generated number — and pay in cash if you want to. Six separate outside organisations have examined it, more than anyone else here.
The trade-offs are real: it covers the fewest countries of the seven, its money-back window is 14 days rather than 30, and it does not list a kill switch by that name. If anonymity from the provider itself is the point, those are prices worth paying. If the point is streaming, they are not.
How much speed actually survives the tunnel
Every VPN site says a tunnel costs you speed. Almost none of them say how much. We measured it by hand rather than repeating a claim: 14 cities, 46 paired runs, comparing NordVPN and Surfshark against the same raw line in the same session. In the 11 cities where we also measured the bare line, the share that survived the tunnel ranged from 40% to 90%.
| City | Raw line | NordVPN | Surfshark | Paired runs |
|---|---|---|---|---|
| Tokyo | 780 Mbps | 444.9 Mbps (57%) | 399.9 Mbps (51%) | 9 |
| London | 790 Mbps | 712.6 Mbps (90%) | 713.5 Mbps (90%) | 9 |
| New York | 760 Mbps | 598.9 Mbps (79%) | 556.6 Mbps (73%) | 7 |
| Los Angeles | 530 Mbps | 358.8 Mbps (68%) | 305.8 Mbps (58%) | 5 |
Measured by VPN LIFE. Raw-line figures are rounded to the nearest 10 Mbps. Percentages are the share of the raw line that survived.
- 14 cities, 46 paired runs, measured by hand
- 11 of those cities also have the bare line measured
- 40% to 90% of the raw line survived
- We only name a winner in 4 cities — the rest have too few runs
The spread between cities is larger than the spread between providers. In London roughly nine tenths of the line survived on both services; in Tokyo it was closer to half. That is worth knowing before you blame the provider: "this VPN is slow" is usually "this route is slow".
We only call a winner in a city when we have five or more paired runs there and the gap is at least 10%. That threshold is met in 4 of the 14 cities — Tokyo and Los Angeles, where NordVPN averaged ahead, and London and New York, where the two were level. In the remaining ten cities we publish the numbers and say the sample is too small, rather than ranking on one run.
How much of the line survived the tunnel
How long you have to change your mind
![]()
![]()
![]()
![]()
![]()
![]()
![]()
The apps behind our measurements

The providers, and what each one publishes
We rank on what we can check. Each of the five below publishes a location in this use; the tables are our own counts and the providers' own published terms, not a summary of their marketing.
ExpressVPN: the widest spread of cities
ExpressVPN publishes more multi-city countries than anyone else in our set — 11 countries where you can pick between two or more locations, including 56 in the United States, 7 in the United Kingdom, 6 in Australia and 4 in Japan. If your problem is a blocked address rather than a missing country, that spread is the thing that gets you out of it. It is the most expensive option here, and it is the one we would pick for streaming.
| ExpressVPN | |
|---|---|
| Locations in this country | 4 cities |
| Countries covered | 112 of the 155 we count |
| Money-back window | 30 days |
ExpressVPN in use

NordVPN: the largest country list, and the one we measured
NordVPN covers more countries than anything else we track. It is also one of the two services we measured ourselves, so the retention figures above are its actual numbers rather than a claim. It operates from Panama, has been audited by Deloitte, allows 10 simultaneous connections, and lists obfuscated servers and a kill switch among its features — the two things that matter where VPN traffic is filtered.
| NordVPN | |
|---|---|
| Locations in this country | 2 cities |
| Countries covered | 149 of the 155 we count |
| Money-back window | 30 days |
| Operates under the law of | Panama |
| No-logs claim examined by | Deloitte |
| Features the provider names | Threat Protection, Double VPN, obfuscated servers, Meshnet, dedicated IP, kill switch and split tunnelling |
NordVPN in use

Surfshark: unlimited devices, and level with NordVPN in half our tests
Surfshark is the other service in our own measurements. In London and New York it was level with NordVPN; in Tokyo and Los Angeles it trailed by 11% and 17%. It places no limit on simultaneous connections, which makes it the sensible choice for a household rather than a person. Audited by Deloitte, operating from the Netherlands, with Camouflage Mode for networks that filter VPN traffic.
| Surfshark | |
|---|---|
| Locations in this country | 1 city |
| Countries covered | 100 of the 155 we count |
| Money-back window | 30 days |
| Operates under the law of | the Netherlands |
| No-logs claim examined by | Deloitte |
| Features the provider names | CleanWeb, Dynamic MultiHop, rotating IP, Camouflage Mode, kill switch and split tunnelling (Bypasser) |
Surfshark in use

CyberGhost: the longest money-back window, with a catch
CyberGhost's 45-day money-back guarantee is the longest here, and it is the reason it appears on most lists. Read the condition: 45 days applies to the six-month and two-year plans, and the monthly plan gets 14 days. It publishes 10 multi-city countries, with 11 locations in the United States, but only a single city in Japan — so it is a weaker choice if Japanese services are your target.
| CyberGhost | |
|---|---|
| Locations in this country | 1 city |
| Countries covered | 100 of the 155 we count |
| Money-back window | 45 days (six-month and two-year plans; 14 days on monthly) |
CyberGhost in use

Private Internet Access: unlimited connections, US jurisdiction
PIA places no limit on devices and publishes an Advanced Kill Switch, obfuscation, multi-hop and port forwarding. Its no-logs claim has been audited by Deloitte Audit Romania. The trade-off is jurisdiction: it operates from the United States, which some readers will rule out on principle. We list it because the rest of the record is strong and because it is one of only four providers with two or more cities in Japan.
| Private Internet Access | |
|---|---|
| Locations in this country | 2 cities |
| Countries covered | 92 of the 155 we count |
| Money-back window | 30 days |
| Operates under the law of | the United States |
| No-logs claim examined by | Deloitte (Deloitte Audit Romania) |
| Features the provider names | unlimited connections, PIA MACE ad and tracker blocking, Advanced Kill Switch, split tunnelling, multi-hop, obfuscation and port forwarding |
Private Internet Access in use

Frequently asked questions
Do VPNs really keep no logs?
Some have been tested in the least pleasant way — by a legal demand arriving and there being nothing to produce. Short of that, an audit by a named firm is the strongest evidence available, which is why we record the name rather than the adjective.
Is there a free no-logs VPN?
Providers with a free tier do make the claim. The difficulty is that a free service still has costs, and where the money comes from is not always stated. Of the providers we track, the one with a meaningful free tier also sells a paid product and publishes audits covering the same infrastructure.
Will a no-logs VPN make me anonymous?
No. It removes one link — your address as seen by the sites you visit. Accounts you sign in to, payment methods, browser fingerprints and the cookies you already carry are all untouched by it. Anyone selling a VPN as anonymity is selling something else.
Conclusion
If you take one thing from this page: ask who audited them and which country they operate under. Both answers are published by five of the seven providers we track, and a provider that publishes neither has told you something.
We collect these from the providers' own sites and republish them with the source attached.
Every figure on this page comes from our own daily collection or our own measurements. The files are published as open data under CC BY 4.0, and the method — including what the numbers do not prove — is on how we test.