3 September 2026
How do you verify a VPN's no-logs claim?
You can't verify a "no logs" claim by reading it. It's a sentence on a privacy policy page, and the only way to check it is to see what happens when the company gets breached, subpoenaed, or audited. Short of that, you're trusting a stranger's word.
That stopped being hypothetical this year. SplitVPN (formerly NotVPN) had connection logs for roughly 58 million records leak, spanning June 2025 through the exact date of the breach in July 2026, according to the breach listing on Have I Been Pwned and a writeup at Cyber Security News citing verification work by a Mysterium researcher. The company disputes that the leaked connection-log table is authentic, but confirmed everything else in it, email, IP, country, masked payment, device, is real, per their statement to TechRadar.
Here's the part that matters even if you take the dispute at face value: the leak wasn't browsing history. It was metadata, which device connected to which server, at what timestamp. That's not "no logs" in any useful sense, because that's exactly the data that ties an account back to a specific person at a specific moment. The affected users skewed toward Russia, Iran, India and Myanmar, the countries where people use a VPN to get around a block, not to watch a different country's Netflix catalogue. Metadata is precisely what deanonymizes that user if it ever gets out.
So what do you actually check, since you can't audit a sentence?
Is there a published third-party audit, and of what. An audit of "no logs" usually means an outside firm reviewed the server configuration and logging pipeline at a point in time and didn't find retained connection data. That's real evidence, but it's a snapshot, not a guarantee about next Tuesday's server config. Ask what was audited and when, not just whether the word "audited" appears on the homepage.
Is the client open source. If the code that runs on your device is public, you or anyone else can read what it actually sends, not what the marketing page says it sends. It doesn't prove what happens on the server side, but it removes one whole category of "we said one thing, the app does another." Pangea's client is GPLv3 for exactly this reason. We haven't been through a third-party audit yet, and we're not going to pretend otherwise.
Does signup require anything that could appear in a breach at all. An email address and a card number are two more fields sitting in a database somewhere, waiting for the next SplitVPN. A provider that lets you pay in Monero and never asks for an email skips creating that record in the first place. It's not a claim about server logs, it's a structural fact about what data exists to leak. Pangea offers that path for anyone who wants zero identity tied to the account at all.
One more thing worth watching, because it's checkable and most "trust us" pages aren't: a warrant canary, a signed statement republished on a schedule saying no warrant, gag order or similar notice has arrived. It only proves something as of the date it was last updated, and it's not a substitute for an audit. But it's the one part of the trust story you can actually go check yourself, every month, instead of taking on faith.
None of this makes a no-logs claim provable. It makes it checkable, which is different, and it's the only version of "trust us" worth anything. Ask it of whoever you're paying for a VPN. Us included.
