What Is a "No-Logs" VPN Claim Actually Worth?

A no-logs claim is a promise, not a mechanism. Nothing about how a VPN works prevents the provider from recording what passes through it — the server sees both ends by necessity. “No logs” describes a policy the company says it follows, and the entire question is how much confidence that policy deserves.

Which means the useful skill isn’t finding the provider with the strongest claim. It’s knowing what kinds of evidence make a claim credible.

What “logs” can mean

The phrase covers several very different things, and providers are not always precise about which they mean:

Activity logs — the sites and services you connected to. This is what people mean when they worry about logging, and essentially every provider claims not to keep these.

Connection logs — timestamps, session duration, bandwidth used, the IP you connected from. Less obviously sensitive, but connection timing plus a source IP can be enough to link a session to a person, especially in combination with records from elsewhere.

Aggregate operational data — server load, total bandwidth, crash reports. Nearly every provider keeps some of this, and it’s genuinely necessary to operate a service.

Account data — email address, payment records, support tickets. Held by essentially everyone who takes payment, and it exists whatever the connection logging policy says.

So “no logs” almost never means “no data of any kind about you.” A policy worth reading distinguishes these categories explicitly. One that just says “we keep no logs” and stops has told you less than it appears to.

What a third-party audit does

Independent audits have become the standard credibility signal in this market, and they’re a genuine improvement over unverified assertion. They also have specific, knowable limits.

What an audit can establish: that at the time of examination, the systems and configurations the auditor was shown were consistent with the stated policy; that particular logging mechanisms were or weren’t present; that stated infrastructure practices appeared to be implemented.

What an audit cannot establish:

  • That the state persists. An audit is a point in time. Infrastructure changes daily; the audit doesn’t.
  • That the auditor saw everything. Scope is agreed in advance and paid for by the provider. A narrow scope can produce a genuine report that establishes very little.
  • That nothing could change under legal compulsion. A provider compelled to begin logging a specific user may be legally barred from disclosing it.
  • That the report says what the marketing says it says. This is the common one — a summary page claims far more than the actual document supports.

How to read one properly: find the actual report rather than the press release. Check who performed it and when. Check the scope section, which is the most informative part and the least quoted. Check whether it examined running production infrastructure or reviewed documentation and configuration. Check whether it’s repeated on a schedule or was a one-off.

An audited provider is generally more credible than an unaudited one. An audit is not proof, and treating it as proof is the mistake the marketing is designed to encourage.

Jurisdiction, and how much it matters

Providers advertise being based in privacy-favourable jurisdictions, and the argument gets more weight than it can bear.

The real part: the legal regime governing a provider determines what it can be compelled to do, what data retention rules apply, and what process is required to obtain data. These genuinely differ between countries.

The overstated part: jurisdiction of incorporation is not the whole picture. Servers sit in many countries and are subject to local law where they sit. Corporate ownership can span multiple jurisdictions. Payment processing happens somewhere. And a provider that genuinely holds no relevant data is protected by that fact regardless of jurisdiction, while one that holds data is exposed regardless of where it’s registered.

The practical reading: jurisdiction is one input, and it’s less important than whether the data exists in the first place.

Signals that carry real weight

Beyond the audit, things that make a claim more credible:

  • Specificity. A policy that enumerates what is and isn’t retained, and for how long, is more useful than a broad denial.
  • Repeated audits on a published schedule, rather than one audit cited indefinitely.
  • Published transparency reports covering data requests received and how they were handled.
  • Technical architecture that reduces what can be logged — for example diskless or RAM-only server designs, which limit what persists across a reboot. Note that this constrains persistence rather than eliminating the possibility of collection.
  • A documented response to a real legal demand. The most informative signal available, and rare by nature.

Signals that don’t

  • “Military-grade encryption.” Marketing language. It refers to widely used standard algorithms, and says nothing about logging.
  • Server and country counts. Unrelated to the claim.
  • Awards and badges from review sites that run affiliate programmes.
  • A long-established brand. Longevity is not evidence about data handling.
  • The claim itself, stated emphatically. Emphasis is free.

What to actually do

  1. Read the actual privacy policy, not the landing page, and check whether it distinguishes activity, connection, and account data.
  2. Find the audit report itself and read its scope section.
  3. Check the date and whether audits repeat.
  4. Note what account and payment data exists regardless of connection logging.
  5. Decide the real question: do you trust this company more than the party they’re replacing? That framing is the whole point of what a VPN actually protects against.
  6. If your risk involves a state actor, none of this is sufficient. Get advice from organisations that specialise in that threat model.