VPN 'No-Logs' Claims vs. What Independent Audits Actually Found
What the published third-party audits of PureVPN's and CyberGhost's no-logs policies actually covered, and what a no-logs claim still can't prove on its own.

Photo: BalticServers.com · CC BY-SA 3.0 · source
Every VPN provider claims a “no-logs policy.” Almost none of them let an outside party check that claim against their actual server configuration. The ones that do publish an audit are worth taking seriously — but it helps to know exactly what an audit like this checks, and what it still leaves as a matter of trust.
What the published audits actually examined
PureVPN’s no-logs policy was reviewed by Altius IT, a California-based independent information systems auditing firm founded in 1993, whose staff hold CISA, CRISC, and CISSP certifications. The audit’s stated conclusion was that Altius IT “did not find any evidence of system configurations and/or system/service log files that independently, or collectively, could lead to identifying a specific person and/or the person’s activity when using the PureVPN service” — a direct check of server configurations and logging behavior against the no-logs claim.
CyberGhost’s no-logs policy was examined by Deloitte, one of the Big Four accounting and assurance firms, under the International Standard on Assurance Engagements 3000 (Revised) — the same audit framework used for formal assurance engagements generally, not a VPN-specific standard. The scope covered CyberGhost’s VPN server network and management systems, its no-logs policy and implementation, and its change-management, configuration-management, and incident-management processes. CyberGhost’s own page is explicit that it cannot publish excerpts from the Deloitte report under the terms of the engagement — readers who want the underlying findings have to request the report from Deloitte directly.
What an audit like this can and can’t establish
An audit of this kind checks a provider’s server configuration and stated policies at one point in time, against a defined scope the provider itself sets with the auditor. That’s meaningfully more verification than a marketing claim alone — a third-party firm with professional liability at stake reviewed actual systems, not just a privacy-policy PDF. It is not the same as a continuous, real-time guarantee. A provider’s infrastructure changes after an audit concludes; a later audit (or none at all) is the only way to know whether the same configuration still holds a year later.
It’s also worth noting what these audits were not designed to test: they don’t verify what happens if a government legal order compels a provider to log a specific user going forward, and they don’t independently confirm jurisdiction-related claims (where a company is legally headquartered, and what data-retention laws apply there) beyond what the provider discloses. SafetyDetectives’ 2026 roundup of audited no-logs VPNs treats a completed, named, third-party audit as a meaningful floor for trust — better than an unaudited claim — while still recommending readers check how recent the audit is and whether the provider has published more than one over time, since a single audit from several years ago says less about current infrastructure than a recurring audit cadence does.
What to actually check before trusting a “no-logs” claim
- Is the auditor named and reputable, or is “independently audited” doing all the work in a single vague sentence with no firm attached?
- How recent is the audit, and has the provider repeated it as infrastructure changed?
- What was in scope — was it the no-logs policy specifically, or a broader security review that only touches on logging in passing?
- Is the provider’s jurisdiction disclosed, since a completed audit doesn’t override what a provider is legally required to retain or hand over in the country where it’s incorporated.
A published, named, third-party audit is a real signal — it’s meaningfully more accountable than a policy page alone. It’s just not the end of the question, and providers that treat “audited” as a marketing checkbox rather than an ongoing practice are giving you less assurance than the word implies.
An audited no-logs policy is only one factor in picking a provider — see also VPN kill switches, explained.