What Gets Examined When a VPN Says It Was Audited
A VPN audit is an outside party examining something the provider says about itself and publishing a view on it. The single word hides the important variable: audits differ enormously in what they were pointed at. An examination of a phone app, an examination of server configuration, and an examination of a retention claim are three unrelated exercises, and a badge saying “independently audited” does not tell you which one happened.
The several exercises that share the name
Sorting these first makes everything else easier, because each supports a completely different conclusion.
A review of the client software. Someone examines the application that runs on your device — how it handles configuration, whether it fails safely, whether it leaks outside the tunnel, what it reports home. This is genuinely useful and it says nothing about the servers.
A review of infrastructure configuration. Someone looks at how exit servers are built and provisioned: what is written to disk, what is enabled by default, how machines are rebuilt. Closer to the retention question, and still a review of arrangements rather than of what those arrangements produced.
An examination of a specific stated claim. The provider asserts something — commonly about what is and is not retained — and an assessor is engaged to test that assertion against systems and procedures. This is the exercise people imagine when they read “no-logs audit”, and it is the least common of the three.
A penetration test. Someone tries to break in from outside and reports what they found. It measures resistance to attack on the day, not data handling at all.
A general-purpose assurance engagement, performed against a framework designed for service companies in general rather than for this claim in particular. Such a report can be entirely legitimate and still not address the question you care about, because the framework was never about tunnels.
When a provider says it was audited, the first job is working out which of these you are being shown.
Scope is negotiated, and that is the informative part
Nearly all of these examinations are commissioned and paid for by the company being examined. That is ordinary — there is no other party with an incentive to fund one — and it is not by itself disqualifying. What follows from it is that the boundaries were agreed in advance, and the agreement is part of the deliverable.
Which means a narrow scope can produce a completely honest report that establishes very little. An examination covering servers in one region says nothing about the rest. One covering the desktop application says nothing about the mobile one. One covering a documented procedure says nothing about whether the procedure was followed on a Tuesday in a data centre nobody visited.
Scope is usually the least-quoted section and the one worth reading first. If you can only find a marketing page and no obtainable document, then what exists is an announcement, and an announcement is not evidence.
Why a point in time means less here than usual
Every audit describes a past state. In this particular market that limitation bites harder than it does elsewhere, for a reason rooted in how the services are built.
Exit capacity is frequently rented, provisioned automatically, and rebuilt often. Locations are added and dropped. Ownership changes. A configuration examined last year may not exist in any machine currently running. So the gap between the examination date and today is not a formality — it is the difference between a report about this service and a report about a service that used to be there.
Repetition is therefore worth more than depth. An examination redone on a published schedule creates a series that a reader can compare. A single examination cited indefinitely becomes weaker every month while the badge stays the same size.
What the summary leaves out
Published summaries are written for a general audience by the party being examined, and the pattern of what goes missing is consistent.
The scope boundaries go missing, since they make the claim smaller. The methodology goes missing — whether the assessor inspected running systems, reviewed configuration files, or interviewed staff about procedure, which are three very different levels of evidence. Findings and exceptions go missing, which is odd, because a report containing minor findings that were fixed is more credible than one implying nothing was found at all. And the assessor’s own caveats about what the engagement could not cover go missing, though those are usually written plainly in the document itself.
If the full report is obtainable, the sections to read are scope, methodology, findings, and date. If only a summary is obtainable, treat it as the provider’s account of the report rather than as the report.
Where the infrastructure puts a ceiling on scope
Scope is not only a matter of what the parties agreed to look at. Some of it is decided by what the provider is in a position to show anybody.
Exit capacity is frequently rented from hosting companies, and the physical machines, the hypervisor beneath them, and the network they sit on belong to a supplier. Address space is often leased rather than held, which means the ranges your traffic leaves from can be reassigned to somebody else’s business. An assessor engaged by the provider examines what the provider controls; the layers underneath are covered, if at all, by somebody else’s arrangements with somebody else’s assessor. A report can be thorough about the part it could reach and silent about the part that was never the provider’s to open.
The counterpart is worth knowing too. The properties an examination reports on the client side — whether the application leaks outside the tunnel, what it does when the connection drops, which resolver it hands your lookups to — are the ones you can establish on your own machine in a few minutes. Those are the least useful findings to take on trust, precisely because they are the ones that do not require trust.
So the honest statement of limits is a statement about boundaries rather than a list of caveats. An examination bounded in scope cannot show the absence of something outside that boundary, cannot describe layers the provider does not own, and describes conduct up to a date rather than conduct as a standing property.
Reading an audit claim without over-crediting it
An examined provider is, in general, more credible than an unexamined one — the exercise costs money and creates a record, and companies that submit to it tend to be the ones that invested in the practices behind it. That is a reasonable inference and it is not proof of anything.
The practical routine: find out which of the exercises above was performed, read the scope, check the date and whether it repeats, and note whether the claim in the report matches the claim on the landing page. Then set it beside the retention language itself, since an examination that never touched retention cannot support a retention promise — the phrasing to look for is in which words do the work in a VPN logging policy, and the reason retention is the one property you cannot test yourself is in what a no-logs VPN claim covers. The parts you can test, meanwhile, do not need anybody’s report: start with how to check for a VPN leak.