Skip to content
VPNmine
PRIVACY AND LAW

What a VPN audit proves, and what it does not

An audit checks that specific systems matched specific claims on specific dates, within a scope the provider agreed with the auditor. It is meaningful evidence and it is not a guarantee about tomorrow, about systems outside the scope, or about anything the auditor was not shown.

4 min read

Illustration of a magnifying glass and a verified seal, joined by a dashed tunnel line on a dark grid.

An audit is the closest thing this industry has to evidence. A no-logs claim is a promise; an audit is a third party saying they looked. That is a genuine and meaningful difference, and it is also routinely oversold, so it is worth knowing what one actually establishes.

What an audit is

An independent firm examines systems and documentation against a defined scope and produces a report. For a VPN, that usually means one of:

  • A no-logs audit. The auditor inspects server configurations, code and processes to check whether the data the policy says is not retained is in fact not retained.
  • A security audit or penetration test. The auditor looks for vulnerabilities in applications and infrastructure.
  • A SOC 2 or ISO 27001 assessment. Broader organisational controls, aimed at enterprise buyers.

These answer different questions. A SOC 2 report says a company has processes; it does not say the VPN keeps no DNS logs.

The five limits

Scope. The provider and the auditor agree what will be examined. A report that covered the server fleet may not have covered the account database, the support desk, or the analytics on the website.

Time. An audit is a snapshot. Configuration on the days examined tells you about those days. Providers that repeat audits annually are making a stronger statement than those with one report from four years ago.

Access. Auditors see what they are shown. A thorough engagement includes unannounced server access and full code review; a light one is a document review with interviews. The report usually says which, in language easy to skim past.

The report's availability. Some providers publish the full report. Some publish a summary. Some publish a press release about a report nobody outside the company has read. Those are very different.

Whom it is addressed to. Audit reports are written for a client and often carry restrictions on reliance by third parties. That is normal professional practice and it means the document is evidence rather than a warranty to you.

How to read one

  1. Who performed it. A recognised firm with a security practice, or an unfamiliar name.
  2. What the scope statement says. This is the most informative section and the least read.
  3. When. Date of fieldwork, not date of publication.
  4. Whether the full report is available, or only a summary.
  5. Whether findings were disclosed. A report with no findings at all is unusual. A report listing findings and their remediation is a sign of a real engagement.

The court-record cases

The strongest evidence in this industry has not come from audits. It has come from cases where a provider was compelled to produce records and demonstrably had none — server seizures that yielded nothing, subpoenas answered with "we do not have that".

Those are not planned and cannot be bought, which is exactly what makes them persuasive. They are also rare, and their absence proves nothing.

Where VPNmine stands

VPNmine has not been independently audited. Saying so is the point of including this section in an article about audits: a provider writing about how to evaluate evidence should state what evidence it has, and the honest answer here is a published policy rather than a third-party report.

What exists is a privacy policy that lists what is stored as specifics rather than as a slogan, and terms naming the operator. Those are checkable claims. They are weaker evidence than an audit and stronger than a vague assurance, and pretending otherwise would be the exact behaviour this article is about.

What to do with all this

Treat an audit as one input. A provider with a recent, broad, published audit from a recognised firm has offered more than one without. A provider with a four-year-old summary of a narrow engagement has offered very little while appearing to offer a lot.

And note what the audit cannot cover regardless: what the hosting company logs at the infrastructure level, what the law of the jurisdiction requires, and what the provider does the day after the auditor leaves.

Why audits are not more common

They are expensive, they take weeks of engineering time, and they can produce findings the provider then has to publish or explain. A small operator can spend a meaningful share of a year's revenue on one.

That is context rather than an excuse. It explains why the providers with audits are mostly the large ones, and why the absence of an audit is not by itself evidence of anything — while its presence remains the strongest single signal available.

The gap an audit cannot close

Even a perfect audit tells you about the provider. It tells you nothing about the hosting company whose hardware the servers run on, the transit networks the traffic crosses, or the jurisdiction's ability to compel changes going forward.

A VPN moves trust rather than eliminating it: from your network operator to your VPN provider. An audit is evidence about the party you moved it to, which is useful precisely because that is the party you now depend on.

Sources

  1. AICPA — SOC 2 reporting
  2. ISO/IEC 27001 — information security management
  3. GDPR Article 5 — principles relating to processing

Try it on the network this was written from

VPNmine is a free no-logs VPN running its own WireGuard servers, with native apps for Windows, macOS, Android, iOS, Android TV and Apple TV. No ads, no card.

Get VPNmine