Who performed it
A named firm with a security practice — Cure53, Deloitte, KPMG, Securitum and similar — is a meaningfully different claim from "independently audited" with no name attached. The absence of a name is the finding.
Assurance firms and security research firms do different work. An assurance engagement tests whether a stated policy is being followed; a security audit tests whether the code does what it claims. A provider needs both, and many have only one.
What was in scope
This is where most misreading happens. Scopes seen in this market include: the no-logs policy, server configuration, desktop applications, mobile applications, browser extensions, and specific protocols.
An audit of a browser extension tells you nothing about server logging. An audit of the no-logs policy tells you nothing about whether the Windows client leaks. A provider with three audits of narrow scope may be less examined than one with a single broad engagement.
Avoid
- Treating "audited" as a binary property
- Accepting a summary blog post as the report when no report is linked
- Assuming an audit of one product covers the whole company
When it happened
Infrastructure, ownership and staff all change. An audit from four years ago describes a company that may no longer exist in the same form, particularly in a market with as much acquisition activity as this one.
Recurring audits are a stronger signal than a single one, because they demonstrate the provider is willing to be re-examined after making changes. A provider that audited once and never again has published a marketing asset.
What an audit cannot tell you
An audit happens with the provider’s cooperation, on systems the provider presents, at a time the provider agrees to. It is not an adversarial inspection and it cannot prove a negative.
That is not a reason to dismiss it. It is the only external evidence available, which is why it is weighted highest in our rubric. It is a reason to treat "no-logs verified" as language that overstates what happened.