Cannot Versus Will Not: Two Kinds of VPN Guarantee

Every privacy guarantee is one of two things: a party that cannot do something, or a party that can and says it will not. The first class is enforced by mathematics, by physics, or by the absence of the data. The second is enforced by intention, and intentions are subject to legal compulsion, acquisitions, policy revisions, misconfiguration, insider access, and simply changing one’s mind.

Sorting claims into those two boxes is the most portable evaluation skill on this site, because it works on claims that have not been invented yet and about companies you have never heard of. You do not need to know whether a provider is trustworthy. You need to know which of its promises would still hold if it were not.

The class that holds: cannot

The local network cannot read tunnelled payloads. As of writing, the ciphers in mainstream use are not breakable by the café, the hotel, or the person on the next table, regardless of what any of them intends. This is the strongest guarantee in the whole arrangement, and it is the one nobody markets hard, because it is unglamorous and universal.

The local network cannot see which destinations you request while the tunnel carries them. Not “agrees not to look” — the information is not present in a usable form. This is why what a VPN actually changes on public Wi-Fi is a real if modest benefit.

Your VPN provider cannot read content that was already encrypted to its destination. A session between your browser and a bank is not decrypted by an intermediate hop, so the provider’s honesty is not what protects that content — if everything is already encrypted, what is a VPN for works through what remains visible anyway.

Nobody can produce data that was never created. This is the important one, because it is the only route by which a logging claim can enter the strong class. A record that does not exist cannot be handed over, subpoenaed, stolen in a breach, or sold by a future owner.

The class that depends on conduct: will not

Almost everything else, including most of what appears in marketing:

  • retention limits and deletion timelines
  • “we do not inspect traffic”
  • “we do not sell or share data”
  • restrictions on which staff can access which systems
  • contractual limits on what a hosting company or support vendor may keep
  • a warrant canary, a transparency report, an ethics statement
  • the promise that the policy will not quietly change

These are not worthless. A company that writes them down has committed publicly, can be held to them commercially and sometimes legally, and has usually built internal process around them. But every one of them describes a capability that exists and a decision not to exercise it, which means every one of them can be revisited by whoever is making decisions next year. The weaknesses of the better examples are set out in warrant canaries and transparency reports.

The middle: capability reduced, not removed

Most infrastructure claims live here, and they are the ones most often described as if they were in the strong class.

Diskless or RAM-only servers. They constrain what persists across a restart. They do not constrain what is visible while the machine is running, and a process can hold in memory whatever someone configured it to hold — the full reading is in what a RAM-only server claim guarantees.

Multi-hop inside one company. Splitting the entry and exit across two machines divides knowledge between two systems under one management, so it raises the effort required and does not create a second party who would have to be compelled separately.

Shared exit addresses. Many subscribers behind one address genuinely destroys some information, which is why the design matters. Timing and volume narrow it again, per what survives a tunnel.

Contracts with sub-processors. A promise about somebody else’s conduct, which is a “will not” one step further from you — see the parties a no-logs promise cannot speak for.

Middle-class claims are worth paying for. They are not worth relying on as though they were absolute.

Three questions that classify any claim

If the company decided tomorrow to stop honouring this, what would it have to change? A configuration flag or an internal policy means “will not”. A redesign, a re-architecture, or a new supplier means something closer to “cannot”.

If a court ordered compliance, could it comply? If yes, the guarantee is a policy. If the honest answer is “we would have to start collecting from now on”, then historical data is genuinely out of reach and only future data is exposed — a meaningful and often overlooked distinction.

If an attacker had complete access to the running system for a month, what would they find? This question ignores everyone’s good intentions, which is exactly what makes it useful.

Why the strong class is rare

Because it costs more. Not collecting data means giving up troubleshooting information, abuse handling, capacity planning and product analytics, and building the systems that let you operate without them. Writing a paragraph promising not to misuse data costs a paragraph.

The predictable result is that the most confident language attaches to the weakest class of guarantee, and the genuinely structural properties get one line in a feature list. When you find a provider whose documentation is boring and specific about what its systems do not receive, that is the unusual case, and it is worth more than any adjective.

Applying it to the decision

Be honest about where a commercial VPN lands. Against the local network and your ISP it gives you a cannot: those observers lose the information, whatever they want. Against the provider itself, almost everything is a will not — and that is the trade, stated plainly in what your VPN provider can see. You are moving a question from a party with structural visibility to a party with a policy, and whether that is an improvement depends entirely on which party you would rather have holding the record.

That trade is fine for the ordinary threat models: a network operator, an ISP, a commercial data market. It is not fine when the consequence of the “will not” failing is serious harm, because a policy is not a defence against a party that can compel the policy-holder — the reasoning in why a commercial VPN is not enough against a state adversary, where the correct step is specialist advice rather than a stronger promise.

So read every claim twice and ask which box it belongs in. It will not tell you which provider is best. It will tell you which sentences would survive somebody else owning the company, and that is a far more useful thing to know than a comparison table.