Education
VPN independent audits in 2026: PwC vs KPMG vs Cure53 vs Securitum compared
The single most overused word in VPN marketing in 2026 is “audited”. Few users know what was actually verified, by which firm, and how recently. This guide on VPN independent audits explains what an audit really checks, names the firms that do the credible work, and shows which providers have been audited by which firm in the publicly disclosed reports as of 2026.
The short answer
Five firms do the VPN audit work the security industry takes seriously: PwC, KPMG, Deloitte, Cure53, and Securitum. Each has audited at least one major VPN provider since 2020. They focus on different things. PwC, KPMG, and Deloitte verify operational claims (no-logs policy, server handling). Cure53 specializes in technical penetration tests of clients and infrastructure. Securitum focuses on application-level security and has audited Proton VPN annually since 2022.
An audit only verifies what is in scope on the day of the audit. Provider claims like “always no logs” extrapolate beyond what the report actually says.
Our research methodology
The audit references in this guide were pulled directly from the public report PDFs and transparency pages of NordVPN, ExpressVPN, Surfshark, and Proton VPN as of May 2026. Where a provider claims an audit, the original PDF was located and read where possible. Where the provider claims an audit but does not publish the full report, the claim is flagged as unverified. See our full research methodology for the broader sourcing approach.
What a VPN audit actually verifies (and what it does not)
A VPN audit is a point-in-time inspection. A team from the audit firm visits the provider offices and data center locations, reviews the technical configuration of servers, examines logging settings, interviews engineers, and reviews the source code of the VPN clients or internal tools where relevant. The output is a report stating whether the provider claim, typically “no logs of user activity”, matches what the auditors found in scope.
What an audit does not verify:
- What the provider does after the audit ends. Configurations can change.
- Servers and code that are out of scope. Audits often cover a sample, not the full network.
- Future behavior. An audit on May 1 does not say anything about how the provider behaves on May 15.
- Legal pressure. An audit does not stop a provider from being legally compelled to log if the local jurisdiction permits it.
The right way to read a VPN audit is as a snapshot: it verifies that at this date, with this scope, the provider claim matched the technical reality. Anything more is marketing. For the basics of how a VPN works, see our what is a VPN primer.
VPN independent audits: the five firms that matter
PwC (PricewaterhouseCoopers). Big Four firm. Has audited the NordVPN no-logs claim multiple times since 2018. Reports focus on internal procedures, log retention policies, and operational verification at server level.
KPMG. Big Four firm. Has audited ExpressVPN TrustedServer technology and the no-logs claim multiple times since 2019. Reports cover RAM-only server behavior, log handling, and internal data flows.
Deloitte. Big Four firm. Has audited NordVPN and Surfshark. Scope similar to PwC.
Cure53. Berlin-based independent security firm. Specializes in penetration testing, code review, and vulnerability discovery. Has audited NordVPN, ExpressVPN, and Surfshark on the technical side: browser extensions, apps, infrastructure components. Reports are typically more granular than Big Four no-logs audits.
Securitum. Polish security firm. Has audited Proton VPN annually since 2022. Reports cover the open-source VPN clients (Windows, macOS, iOS, Android, Linux) and protocol implementations.

NordVPN audits
According to the NordVPN transparency page as of May 2026, the provider has been audited by PwC multiple times and by Deloitte multiple times since 2018. The most recent no-logs audit publicly disclosed was conducted by Deloitte. Cure53 has separately reviewed NordVPN browser extensions and the Meshnet feature.
Scope of the latest no-logs audit: server configuration sample, internal monitoring tools, employee access procedures, and the operational definition of “log”. What it verifies: NordVPN does not record IP addresses, traffic data, connection timestamps, session info, or browsing data at the server or backend level for the sample inspected, in the period inspected. What it does not verify: behavior outside the scope window, customer support metadata, or marketing-side data collected through the website. For the broader assessment, see our NordVPN review.
ExpressVPN audits
The ExpressVPN transparency page lists multiple audits by KPMG (no-logs and TrustedServer) and several by Cure53 (apps, browser extensions, infrastructure). KPMG has audited the no-logs claim multiple times publicly disclosed between 2019 and 2024.
Distinctive feature audited: TrustedServer technology, which runs every server exclusively on volatile RAM with no persistent disk. KPMG verification specifically covers whether the boot process and runtime configuration prevent any session data from touching disk. Cure53 reports cover the Lightway protocol implementation, the Aircove router OS, and the browser extension code. For the full assessment, see our ExpressVPN review.
Surfshark audits
Surfshark has been audited by Deloitte (no-logs) and by Cure53 (browser extensions, apps). The most recent public no-logs audit was conducted by Deloitte. Scope: configuration review of representative servers, log retention verification.
Note: Surfshark has been part of the Nord Security group since 2022, but audit cycles for the two brands are conducted separately. This matters because some users assume the NordVPN audit covers Surfshark by extension. It does not.
Proton VPN audits
The Proton VPN transparency page documents annual audits by Securitum since 2022. The 2025 audit covered the full app stack (Windows, macOS, Linux, iOS, Android).
Distinctive scope: because all Proton VPN clients are open source, Securitum performs full source code review in addition to runtime testing. Reports are typically more granular at the client side than the Big Four audits, but less focused on the operational no-logs side. Proton has separately commissioned Mozilla Security Engineering to review the Proton Pass codebase, though this is not directly a VPN audit.
How to read an audit report
The four questions to ask when a provider says “audited”:
- Who did the audit? PwC, KPMG, Deloitte, Cure53, Securitum are the names to look for. “Audited by an independent firm” without a name is marketing, not evidence.
- What was the scope? No-logs only? Apps only? Servers only? Be skeptical of broad claims pinned to a narrow audit.
- When was the audit conducted? A 2021 audit does not say anything about 2026 operations. Look for the date inside the PDF, not just on the landing page.
- Is the full report public? If only a one-page summary or “we passed” badge is available, the value is much lower.
Which audits matter most: no-logs vs apps vs infrastructure
No-logs audits (PwC, KPMG, Deloitte) matter most for the privacy-first user. They verify that even if a government compels the provider to share logs, there are no logs to share.
App audits (Cure53, Securitum) matter most for the security-focused user. They verify that the client on your machine does not have buffer overflows, leak vectors, or hidden telemetry. App audits also cover protocol implementation, which connects to broader protocol choices, see our breakdown of WireGuard vs OpenVPN vs IKEv2.
Infrastructure audits (Cure53 server-side, Big Four operational reviews) matter for users in high-risk regions. A provider with a strong no-logs audit but no app audit is the most common configuration in 2026. Among the four covered above, ExpressVPN and Proton VPN currently have the broadest documented audit coverage based on their public transparency pages.

Red flags when a provider claims “audited”
- No firm named. “Independently audited” without naming the firm.
- No date. “Recently audited” without a date.
- No published report. A summary blog post, not the full PDF.
- Out-of-scope generalization. A 2021 server audit cited to justify 2026 marketing claims.
- Audit by a firm with no security reputation. Default to PwC, KPMG, Deloitte, Cure53, Securitum as the names to recognize.
If you cannot find the report PDF on the provider site within two clicks, the audit claim is treated by the security community as marketing only.
Audits cover the encryption in use today; for what comes next, read our post-quantum VPN explainer.
FAQ
Final word
A VPN audit is the single most concrete piece of evidence a provider can offer. But it is point-in-time, scope-limited, and only as strong as the firm performing it. The four providers covered above all maintain credible audit cadences as of 2026. Among them, ExpressVPN and Proton VPN currently lead on breadth of public audit coverage. NordVPN leads on no-logs audit frequency.
When a provider you are considering does not appear in this list, the question is not “are they good?” but “what have they actually proven, by whom, and when?” That question is sharpest with free services, where the business model is rarely documented anywhere; our guide to free VPN safety sets out what to look for. For the broader research approach behind every recommendation on this site, see our research methodology.
Published: May 31, 2026 · Author: Simon Phillips · Sources: public transparency pages and audit report PDFs of NordVPN, ExpressVPN, Surfshark, and Proton VPN (verified May 2026).
Top Picks