KotoVPN

Guide · Updated August 13, 2026

How to read a VPN audit report

What does an "independently audited" VPN actually mean?

Short answer

Read three things: who performed it, what they were allowed to examine, and when. A report covering a browser extension is not a report covering the no-logs claim, and providers cite one as though it were the other routinely. The date matters as much as the scope, because an audit is a snapshot of a system that can change the next day.

Who performed it

A named firm with a security practice — Cure53, Deloitte, KPMG, Securitum and similar — is a meaningfully different claim from "independently audited" with no name attached. The absence of a name is the finding.

Assurance firms and security research firms do different work. An assurance engagement tests whether a stated policy is being followed; a security audit tests whether the code does what it claims. A provider needs both, and many have only one.

What was in scope

This is where most misreading happens. Scopes seen in this market include: the no-logs policy, server configuration, desktop applications, mobile applications, browser extensions, and specific protocols.

An audit of a browser extension tells you nothing about server logging. An audit of the no-logs policy tells you nothing about whether the Windows client leaks. A provider with three audits of narrow scope may be less examined than one with a single broad engagement.

Avoid

  • Treating "audited" as a binary property
  • Accepting a summary blog post as the report when no report is linked
  • Assuming an audit of one product covers the whole company

When it happened

Infrastructure, ownership and staff all change. An audit from four years ago describes a company that may no longer exist in the same form, particularly in a market with as much acquisition activity as this one.

Recurring audits are a stronger signal than a single one, because they demonstrate the provider is willing to be re-examined after making changes. A provider that audited once and never again has published a marketing asset.

What an audit cannot tell you

An audit happens with the provider’s cooperation, on systems the provider presents, at a time the provider agrees to. It is not an adversarial inspection and it cannot prove a negative.

That is not a reason to dismiss it. It is the only external evidence available, which is why it is weighted highest in our rubric. It is a reason to treat "no-logs verified" as language that overstates what happened.

Questions

Is a court case better evidence than an audit?
In one respect, yes: a subpoena that produces nothing tests the claim adversarially, which an audit cannot. It is also rarer and narrower, covering one moment and one request. Both are useful and neither is proof.
Why do you score an unaudited provider at zero rather than average?
Because absence of evidence is the finding. Scoring it as average would let a provider that has published nothing sit level with one that has been examined and passed, which inverts the incentive.
Do audits get paid for by the provider?
Yes, essentially always. That is normal for assurance work and it is also why scope and firm reputation carry the weight, rather than the existence of an engagement.

Terms used here

Independent audit

An examination of a provider’s systems or policy by an external firm, published with the firm’s name, the date, and the scope.

No-logs policy

A provider’s commitment not to record which sites you visit, when you connected, or what address you connected from.

Warrant canary

A regularly updated statement that a provider has not received a secret legal demand, whose disappearance implies that it has.

Related