Every VPN provider says "no logs" somewhere on its homepage. Nearly none of them mean the exact same thing by it, and the phrase itself is close to meaningless without knowing specifically what isn't logged, what is, and how you'd ever find out if that changed. This isn't a pitch for any particular provider — it's a rundown of what to actually check, wherever you're comparing.

"No logs" almost never means zero data

A VPN that recorded literally nothing about your account or connections couldn't bill you accurately, prevent abuse, or even let you log in. What "no logs" realistically refers to is traffic logs: which websites you visited, what you did on them, and your DNS queries — the record of your actual browsing activity. That's the part that matters most for privacy, and it's the part a well-built VPN genuinely doesn't need to keep, since routing encrypted traffic doesn't require inspecting or recording its contents.

What providers commonly do still retain, and reasonably so, usually falls into a few buckets:

None of that is "traffic logging" in the sense that matters — connection metadata tells a provider that you connected to a server for 40 minutes, not what you did during those 40 minutes. But it's still data about you, so the honest version of a "no logs" page spells out exactly what falls in each category instead of leaving "no logs" to imply nothing is stored at all.

Why an independent audit matters more than the claim itself

Any provider can write "we don't log your traffic" on a webpage — it costs nothing and can't be disproven by looking at the page. The reason third-party no-logs audits exist is that they involve an outside security firm actually reviewing server configurations, source code, and infrastructure to verify the claim matches reality, rather than taking the provider's word alone. A handful of major VPN providers have completed these, some more than once, and a completed audit — ideally a recent one, since infrastructure changes — is a meaningfully stronger signal than the marketing copy on its own.

The absence of a completed audit isn't automatically disqualifying, especially for a newer or smaller provider where commissioning one is a real cost, but it is a real gap worth weighing, and how a provider talks about that gap tells you something too — a company that plainly says "we haven't had one done yet" is giving you more useful information than one that avoids the topic entirely.

Jurisdiction and legal exposure

Where a VPN provider is legally based, and where its servers physically sit, both matter, for a specific reason: they determine what a government or law enforcement body could legally compel the provider to hand over, and whether the provider could be forced to do so silently. Providers based in countries with mandatory data retention laws, or that are members of intelligence-sharing arrangements like the "5/9/14 Eyes" alliances, face different legal pressures than those based elsewhere. This is also exactly why traffic-content no-logging matters practically, not just philosophically — if a provider never has your browsing history in the first place, there's nothing to hand over even under a valid legal order, regardless of jurisdiction.

A trustworthy provider will generally disclose, plainly, where its servers are located and what legal entity (if any) operates the service — and be honest if that structure is still evolving rather than presenting an incomplete picture as more settled than it is.

Warrant canaries: useful, but understand their limits

A warrant canary is a periodically-republished statement like "we have never received a National Security Letter" — the idea being that if the statement disappears or stops being updated, that's an implicit signal something changed, since the provider may be legally barred from stating outright that it received a gag order but generally can't be compelled to keep affirmatively publishing a false one. It's a genuinely useful transparency tool, but it's not proof of anything by itself — it only tells you the provider is willing to make a checkable, falsifiable claim and keep it current, which you'd need to actually verify by checking back over time.

A red flag worth naming directly

One pattern worth watching for specifically: a provider that markets itself heavily on "military-grade encryption" and "100% no logs, guaranteed" in bold marketing language, but whose privacy policy — the actual legal document — is vague, generic, or contradicts the marketing claims when you read it closely. The marketing page and the privacy policy should say the same thing; if they don't, the privacy policy is the one that's actually binding, and it's the one worth reading before trusting the headline claim. This isn't unique to VPNs — it's a general pattern worth applying to any privacy-related product — but it comes up often enough in this specific space to call out.

Questions worth asking any provider

A provider that answers these directly — including admitting where a gap exists, like not yet having a completed audit — is giving you more real information than one that answers only with reassurance. That's the actual signal to look for, regardless of which VPN you end up choosing.