Independent audit
An examination of a provider’s systems or policy by an external firm, published with the firm’s name, the date, and the scope.
Glossary
A VPN application whose source code is published, so anyone can inspect what it does.
It is the difference between trusting a claim about leak handling and being able to check it. A researcher can read the code; you benefit from the fact that they can.
Open source does not mean audited, and published source does not guarantee the binary you install was built from it. Reproducible builds close that gap and few providers offer them. It is a necessary condition for verification, not verification itself.
An examination of a provider’s systems or policy by an external firm, published with the firm’s name, the date, and the scope.
A provider’s commitment not to record which sites you visit, when you connected, or what address you connected from.
Terms are defined here because they appear in our scoring rubric or in provider reviews, not to fill a glossary.