All articles

What 'no-logs' actually means, and how to verify a VPN's claim

Nearly every VPN advertises a 'strict no-logs policy.' The phrase is doing a lot of work with very little verification behind it most of the time. Here's what logging actually means, and how to check whether a claim holds up.

By JohnAugust 16, 20265 min read

"No-logs policy" is the single most repeated phrase in VPN marketing, and it's also one of the hardest claims for a customer to actually verify. Here's what it means when it's true, and how to tell the difference between a real no-logs provider and a page of reassuring text.

The two-line summary

"Logging" isn't one thing — providers can log connection metadata, usage/activity data, or nothing at all, and the marketing phrase "no logs" doesn't distinguish between these by default. The only way to actually verify a claim is independent audits, a track record under real legal pressure, or both.

The different kinds of "logs"

Activity logs — which websites you visited, what you did. This is the log type that matters most for privacy, and reputable providers genuinely don't keep this.

Connection logs — timestamps of when you connected and disconnected, sometimes bandwidth used, sometimes the IP you connected from. Some providers calling themselves "no-logs" keep a limited version of this for abuse prevention or troubleshooting, auto-deleted after a short window.

Aggregate/anonymized data — statistics about server load or total usage that aren't tied to an individual account. Generally considered acceptable even under a strict no-logs claim, since it can't be traced back to you.

A provider's privacy policy should specify which of these — if any — it keeps, and for how long. Vague language ("we may collect some information to improve our service") is worth reading closely; specific language ("we retain no connection or activity logs; aggregate bandwidth statistics are deleted after 24 hours") is a stronger sign of a policy someone actually thought through.

Why the claim alone isn't enough

Any company can write "we don't log" on a page. There's no independent authority that automatically verifies this the way, say, a financial audit verifies a company's books — unless the company chooses to pay for one and publish it. So the claim by itself carries very little weight; what backs it up matters far more.

How to actually verify a no-logs claim

Independent audits. A number of VPN providers have commissioned third-party security firms to audit their infrastructure and confirm no-logs claims, publishing the resulting report. Look for the audit firm's name and a real report, not just a badge graphic on the homepage.

Proven under legal pressure. The strongest evidence is a provider whose servers were seized, subpoenaed, or otherwise legally compelled to produce data — and had nothing useful to hand over because there was genuinely nothing logged. This has happened publicly to a handful of VPN providers over the years and is searchable public record; it's stronger evidence than any self-published audit.

Server architecture. Some providers run RAM-only servers — meaning all data is wiped on every reboot, with no persistent disk to log to even if they wanted to. This is a structural guarantee rather than a policy promise, and it's disclosed by providers who've built it because it's a meaningful differentiator.

Jurisdiction. Where a company is legally based affects what a government can compel it to do, and for how long it can be legally required to stay silent about a request. See how to choose a VPN for how jurisdiction factors into the broader decision.

Red flags

  • A privacy policy that's vague about what "logs" specifically excludes.
  • No audit, and the company has been operating long enough that one would be expected.
  • A business model that doesn't obviously make money from subscriptions (see free VPN vs. paid VPN for why this matters).
  • Ownership hidden behind shell companies with no public information about who actually runs the service.

Quick FAQ

Does a no-logs VPN mean I'm anonymous? No. It means the VPN provider itself isn't recording what you do. Websites you log into still know it's you; your traffic is still visible to the VPN provider in real time even if they don't retain it afterward.

Can a no-logs VPN still be forced to start logging? In some jurisdictions, yes — a government could theoretically compel a provider to log a specific target going forward, under a court order. This is different from having historical logs to hand over, and it's part of why a provider's operating history and jurisdiction both matter.

Are RAM-only servers strictly better than disk-based ones with a strong policy? They're a meaningful additional guarantee, but a provider with disk-based servers and a genuinely enforced, audited no-logs policy can be just as trustworthy in practice. RAM-only is one strong signal among several, not the only one that matters.

How often should a VPN provider re-audit? Security practices and infrastructure change over time, so a single audit from several years ago is weaker evidence than an ongoing pattern of regular, recent audits.

TL;DR

"No-logs" isn't self-verifying — check what specifically is excluded, whether an independent audit backs the claim, and whether the provider has actually been tested by a real legal request. A vague policy with no audit history is a claim, not a guarantee.