---
title: "2026 SingLinkVPN Independent No-Logs Policy Verification Report"
slug: "singlinkvpn-no-logs-verification-2026"
locale: "en"
publishedAt: "2026-07-29T04:30:00.000Z"
reportVersion: "1.0"
auditDate: "2026-07-29"
---

# 2026 SingLinkVPN Independent No-Logs Policy Verification Report

**Independent No-Logs Policy Verification Report**

| Report information | Details |
| --- | --- |
| Service reviewed | SingLinkVPN |
| Audit organization | VPNTestor Platform |
| Audit team | Openscore VPN |
| Lead auditor | James Robert Smith |
| Nature of audit | Independent third-party technical verification of the no-logs policy |
| Audit method | Read-only inspection of the production environment |
| Audit reference date | July 29, 2026 |
| Report version | 1.0 |
| Signature status | James Robert Smith signed the final-report hashes with an Ed25519 key |
| Overall conclusion | Passed |

---

## 1. Executive summary

VPNTestor Platform and **Openscore VPN**, acting as an independent third party, performed a read-only technical inspection of SingLinkVPN's production environment, central backend data structures, reporting interfaces, node configuration, protocol configuration, and related retention rules as of July 29, 2026.

During this audit:

- No production data was modified;
- No node addresses were exported;
- No server keys were exported;
- No user account data was copied;
- No production database was exported;
- No internal interface, token, or security configuration was disclosed.

The integrity-protected central traffic-accounting schema contains no fields for persistently recording the following destination activity:

- Websites visited by users;
- Destination domains;
- Full URLs;
- DNS query records;
- Browsing content;
- Network communication content;
- Original connection IP addresses;
- The specific VPN node used by a user;
- The start and end time of an individual connection;
- Session records capable of associating a user account with specific network activity.

SingLinkVPN processes a limited amount of account and metering data required to provide the service. This includes cumulative traffic values, daily traffic totals, temporary online-device status, virtual email addresses, order numbers, customer-support information, and remote-diagnostic data voluntarily submitted by users.

This data does not contain websites, domains, URLs, DNS queries, or communication content accessed by users. The audit also found no evidence that it is used to create browsing histories or network-activity profiles.

Based on the production read-only inspection, confidential audit workpapers, and public integrity materials, the audit team concludes:

> **Within the audit scope and reference date stated in this report, SingLinkVPN's implemented system design is consistent with its strict no-activity-logs policy. No evidence was found that SingLinkVPN records, retains, or provides users' specific network activity.**

### Public evidence package and integrity verification

On July 29, 2026, the audited party separately submitted version 1.0 of a public cryptographic evidence package. VPNTestor verified the integrity of the submitted files. “The files have not changed since signing” must, however, remain distinct from “the underlying facts have been independently reproduced by a third party.”

- [Download the public evidence ZIP](/downloads/no-logs/SingLinkVPN-NoLogs-Public-Evidence-v1.0.zip)
- [Download the ZIP SHA-256 file](/downloads/no-logs/SingLinkVPN-NoLogs-Public-Evidence-v1.0.zip.sha256)
- [Download the Ed25519 signature](/downloads/no-logs/SingLinkVPN-NoLogs-Public-Evidence-v1.0.zip.sha256.sig)
- [Download the Ed25519 public key](/downloads/no-logs/signing-public-key.pub)

| Integrity item | VPNTestor verification result |
| --- | --- |
| ZIP SHA-256 | `cec6229913b967728e993cac7be4727377af6549ea9d9e0be7aa8251ea0838ba`, matching the submitted value |
| Internal manifest | SHA-256 checks passed for all 9 public files |
| Outer ZIP signature | Ed25519 verification passed |
| Internal manifest signature | Ed25519 verification passed |
| Signing-key fingerprint | `SHA256:alFQcUWiqNXUXP1CYb7R/AFmOG56709x11bzwGrtTC0`, matching the submitted value |

The signing key is the audited party’s evidence-signing key, not an audit-signing key belonging to VPNTestor or Openscore VPN. A valid signature proves only that the files have not changed since signing; it does not independently establish the truth of the operator’s statements.

The package publicly supports four types of material: minimization of fields in the central traffic-accounting tables, the configured two-month retention period and observed date range for traffic aggregates, short application-level TTLs for online state, and a sanitized aggregate node inventory. Source-code hashes become probative only after an auditor privately obtains the corresponding source files and recalculates the hashes.

The public package supports central traffic-field minimization, the two-month aggregate-retention configuration and observed date range, short application-layer TTLs for online state, and a sanitized aggregate node inventory. The audit team separately reviewed private source code, production queries, node and infrastructure configuration, backups, support controls, and diagnostic-cleanup mechanisms in a restricted read-only environment. Those sensitive workpapers are not public because they contain security configuration, internal structure, and restricted production information, but they are included in this independent audit conclusion.

### Complete audit workpapers and signature status

The audited party subsequently submitted a repackaged v1.0 audit-workpaper archive. VPNTestor verified the ZIP, the manifest covering 52 files, the outer checksum-file signature, and the internal manifest signature. Both signatures were created with the audited party’s evidence-signing key and establish integrity only.

- [Download the complete audit-workpaper ZIP](/downloads/no-logs/SingLinkVPN-NoLogs-Audit-Workpapers-v1.0.zip)
- [Download the workpaper ZIP SHA-256](/downloads/no-logs/SingLinkVPN-NoLogs-Audit-Workpapers-v1.0.zip.sha256)
- [Download the workpaper integrity signature](/downloads/no-logs/SingLinkVPN-NoLogs-Audit-Workpapers-v1.0.zip.sha256.sig)
- [Download the final Simplified Chinese report](/downloads/no-logs/SingLinkVPN-NoLogs-Independent-Verification-Report-2026-v1.0-zh-Hans.md)
- [Download the final English report](/downloads/no-logs/SingLinkVPN-NoLogs-Independent-Verification-Report-2026-v1.0-en.md)
- [Download the SHA-256 manifest for both final reports](/downloads/no-logs/SingLinkVPN-NoLogs-Independent-Verification-Report-2026-v1.0.sha256)
- [Download the James Robert Smith Ed25519 signature](/downloads/no-logs/SingLinkVPN-NoLogs-Independent-Verification-Report-2026-v1.0.sha256.sig)
- [Download the James Robert Smith Ed25519 public key](/downloads/no-logs/James-Robert-Smith-Ed25519-Public-Key.pub)

| Workpaper integrity item | Verification result |
| --- | --- |
| ZIP SHA-256 | `9e3f92e301199e216006a3e276581cd90b0df93746b469d094581c814286132f`, matching the submitted value |
| Internal manifest | SHA-256 passed for all 52 files |
| ZIP checksum-file signature | Ed25519 verification passed |
| Internal manifest signature | Ed25519 verification passed |
| Signing-key fingerprint | `SHA256:alFQcUWiqNXUXP1CYb7R/AFmOG56709x11bzwGrtTC0` |

The published workpapers are sanitized materials prepared for external integrity review. They exclude node addresses, server keys, internal interfaces, access tokens, backend screenshots, user data, and configuration that could affect production security. Restricted evidence not published on the website was reviewed by the audit team in the read-only environment; “not public” does not mean “not verified.”

On July 29, 2026, James Robert Smith used an Ed25519 signing key to sign the SHA-256 manifest for both final reports. The public-key fingerprint is `SHA256:P0NcmbNqWFxSf8SbmQMIJRUYpRQXetoY9VDysZvt8IU`, allowing public verification that the report files have not changed since signing.

## 2. Audit independence statement

This report was performed independently by VPNTestor Platform. The Openscore VPN team conducted the technical testing and audit, and VPNTestor Platform independently reconfirmed the result.

The auditors are not members of SingLinkVPN’s internal product, development, operations, or management teams. They do not participate in the audited system’s day-to-day operation, data processing, node maintenance, or privacy-policy development.

For this inspection, the auditors received only the restricted read-only access required to complete the audit and followed these principles:

- Do not modify production data;
- Do not obtain production keys;
- Do not export node addresses;
- Do not copy the user database;
- Do not access user communication content;
- Do not perform destructive testing against the production service;
- Do not publish configurations that could affect node security.

This is an independent third-party technical verification report. It is not a SOC 2 report, an ISO certification, a financial assurance report, or a government compliance certification.

The audit method referenced general principles for privacy-information management and log governance. [ISO/IEC 27701:2025](https://www.iso.org/standard/27701) provides requirements and guidance for privacy information management systems, while [NIST SP 800-92](https://csrc.nist.gov/pubs/sp/800/92/final) addresses methods for log generation, protection, review, and retention. Referencing these frameworks does not mean that SingLinkVPN or the audit organization is certified under them.

## 3. Audit definition of “no logs”

In this report, “no logs” means:

> **SingLinkVPN does not record, store, or persist data that reveals websites visited by a user, destination domains, full URLs, DNS queries, browsing content, network communication content, original IP addresses, or specific connection activity.**

“No logs” does not mean that a VPN service processes no data at all.

The system may process limited service data to provide subscriptions, traffic metering, device-count limits, order lookup, customer support, and remote diagnostics requested by a user.

This report divides data into three categories.

### 3.1 User activity data that must not be recorded

SingLinkVPN’s no-logs policy prohibits persistent storage of:

- Websites visited;
- Destination domains;
- Full URLs;
- Webpage paths;
- DNS queries;
- Browsing content;
- Communication content;
- Application network content;
- Original IP addresses;
- Long-term mappings between VPN-assigned IP addresses and accounts;
- Specific nodes used;
- Start and end times of individual connections;
- Connection-duration history;
- Session mappings that identify user activity.

### 3.2 Limited service data

To provide normal service, the system processes:

- Cumulative user upload traffic;
- Cumulative user download traffic;
- Daily upload and download traffic;
- Last-used status;
- Temporary online-device status;
- Virtual email addresses used for registration;
- Order numbers;
- Customer-support tickets;
- SingChat conversations;
- Remote-diagnostic information voluntarily submitted by users.

This data does not include a user’s specific destinations or browsing content.

### 3.3 Temporary transport state

While providing real-time data forwarding, VPN nodes temporarily process the following in memory:

- Current connection state;
- Temporary sessions required for data forwarding;
- Temporary network buffers;
- Real-time routing state;
- Protocol handshake state.

These states are used only to complete the current connection and transmission. They are not written to persistent activity logs and are automatically released after disconnection.

## 4. Audit scope

### 4.1 Network and node scope

As of July 29, 2026, the inspection identified:

| Item | Quantity |
| --- | ---: |
| Total logical records | 206 |
| Visible logical configurations | 105 |
| Hidden logical configurations | 101 |
| Distinct host aliases | 33 |
| Unique IP endpoints after DNS resolution | 28 |
| Unresolvable host aliases | 0 |
| SingLink logical records | 119, including 105 visible records |

These figures come from a sanitized aggregate snapshot generated and signed by the audited party at `2026-07-29T05:06:41Z`. VPNTestor verified file integrity and reran the aggregate queries in a restricted read-only session with consistent results. Host aliases, endpoint addresses, and production query output are not disclosed publicly.

Logical records, visible configurations, host aliases, and resolved endpoints are different statistical dimensions and must not be added together as a total node count. The value 105 means “visible logical configurations.” It must not be described as 105 physical servers or 105 unique IP addresses.

This aggregate inventory does not establish node-local logging behavior. The report also provides no financial or legal assurance regarding data-center ownership, legal ownership of servers, or registration ownership of IP addresses.

### 4.2 System scope

The audit scope included:

- Central account administration;
- User data-reporting interfaces;
- Node-configuration systems;
- Protocol-configuration systems;
- User traffic-metering systems;
- Online-device limit systems;
- Order and after-sales lookup systems;
- The SingChat customer-support system;
- Remote-diagnostic logging systems;
- Local logging policies on VPN nodes;
- DNS query processing;
- Cloud-service and CDN logging configurations;
- Data query and export capabilities;
- Automatic cleanup and destruction rules.

## 5. Audit methodology

The audit team primarily used the following non-destructive technical methods.

### 5.1 Data-structure inspection

The team inspected fields in the central administration system and related databases to determine whether they contained:

- Domain fields;
- URL fields;
- DNS query fields;
- Original IP fields;
- Node-usage history fields;
- Connection-time history fields;
- Communication-content fields;
- Browsing-history fields.

### 5.2 Reporting-interface inspection

The team inspected the data types submitted by clients and nodes to the central administration system to determine whether reporting interfaces included:

- User destinations;
- DNS queries;
- Original IP addresses;
- URLs;
- Network content;
- Node-access history.

### 5.3 Configuration inspection

The team inspected:

- Node logging configurations;
- Application logging configurations;
- DNS logging configurations;
- Cloud-service logging configurations;
- CDN access-log configurations;
- Data-retention configurations;
- Automatic cleanup jobs;
- Administrative export functions.

### 5.4 Data sampling

Without exporting the production database, the team performed read-only sampling of existing data to confirm that the data actually stored by the system was consistent with its database fields and documented policies.

### 5.5 Deletion-rule inspection

The team examined automatic deletion and cleanup rules for different categories of limited service data, including:

- Daily traffic records;
- Customer-support conversations;
- Remote-diagnostic data;
- Virtual email and order records;
- Temporary device state;
- Temporary node transport state.

## 6. Overall audit results

| Data category | Third-party verification result | Conclusion |
| --- | --- | --- |
| Websites, destination domains, URLs, and browsing content | No corresponding fields were found in the central backend, reporting interfaces, or inspected data structures | Passed |
| DNS query logs | No DNS queries were found written to persistent logs or associated with user accounts | Passed |
| Original IP records | No persistent storage of users' original IP addresses was found in the central backend or node systems | Passed |
| Node-usage records | No per-user history of specific node usage was found | Passed |
| Connection start, end, and duration | No per-connection history was found | Passed |
| Total user traffic | Only cumulative upload/download values and last-use state are stored; no destination data is included | Passed |
| Daily traffic statistics | Only daily upload/download totals are stored and automatically deleted after about two months | Passed |
| Online devices | Used only to enforce device-count limits and maintained as temporary state | Passed |
| Virtual email addresses and order numbers | Used only for subscriptions and after-sales inquiries and cleaned on a three-month cycle | Passed |
| Customer-support tickets and SingChat | Automatically removed from the active system after the conversation ends | Passed |
| Remote-diagnostic logs | Created only at the user's request and automatically deleted after 14 days | Passed |
| Local VPN-node logs | No persistent access, connection, DNS, or communication logs were found | Passed |
| Cloud-provider and CDN logs | No persistent cloud or CDN logs recording user VPN activity were found | Passed |
| Database backups | No backup data containing user network-activity logs was found | Passed |
| Administrator query and export | The backend has no capability to query or export user network-activity logs | Passed |

These conclusions rely on both public sanitized materials and restricted production evidence privately reviewed by the audit team. Sensitive workpapers are not published to avoid exposing nodes, keys, internal interfaces, access controls, and production security configuration.

## 7. User access-activity audit

The audit team inspected the central administration data-reporting interfaces and related data structures.

Within the inspected scope, the following fields were not found:

- Visited domains;
- Destination websites;
- Full URLs;
- Webpage paths;
- HTTP request content;
- Browsing content;
- Communication bodies;
- Application network content;
- Search content.

The audit team also found no data structure capable of establishing this relationship:

```text
User account
→ a particular time
→ a particular node
→ a particular domain or website
```

The existing central administration data therefore cannot be used to reconstruct which websites or network services a particular user accessed.

**Audit result: Passed.** The public package shows the sanitized structure and integrity materials. The audit team reproduced the production queries and reviewed the relevant data structures in a restricted read-only environment. Sensitive query output is not public.

## 8. Original IP and connection-log audit

The audit found no evidence that SingLinkVPN’s central administration persistently stores the original IP address used before a user connects to the VPN.

It also found no per-connection history containing:

- Original IP address;
- VPN-assigned IP address;
- Node used;
- Connection start time;
- Connection end time;
- Connection duration;
- Session ID;
- Source port;
- Destination port;
- Mapping between an original IP address and an account.

The system contains a “last used” status field, but it is used for account and service-state management. It does not include the corresponding destination, node, original IP address, or connection details.

This field alone cannot be used to reconstruct a user’s browsing activity.

**Audit result: Passed.** The audit team reviewed the central control plane, relevant subsystems, and node configurations in a restricted read-only environment and found no persistent user source-IP history. The public package contains only a sanitized summary; sensitive configurations and query output are not public.

## 9. DNS query-log audit

The inspection found no evidence that SingLinkVPN writes users’ DNS queries to the central administration system or any other persistent activity log.

No evidence was found of storage for:

- Domains queried by users;
- DNS request-time history;
- Mappings between DNS results and accounts;
- Mappings between DNS queries and original IP addresses;
- Mappings between DNS queries and specific nodes.

DNS resolution is used only to complete real-time network connections and does not create a database of user DNS history.

**Audit result: Passed.** The audit team reviewed the central control plane, DNS handling, and relevant node configurations in a restricted read-only environment and found no DNS queries persisted or linked to user accounts. The public package contains only a sanitized summary.

## 10. User traffic-statistics audit

SingLinkVPN stores the following per user:

- Cumulative upload traffic;
- Cumulative download traffic;
- Last-used status;
- Daily total uploads;
- Daily total downloads.

This data is used to:

- Calculate free traffic allowances;
- Enforce plan traffic limits;
- Display a user’s current usage;
- Prevent reuse of traffic allowances;
- Handle user traffic inquiries.

Traffic statistics do not contain:

- The website to which traffic was sent;
- The domain accessed;
- The URL used;
- Packet content;
- User browsing content;
- DNS queries;
- Specific application names.

The system can therefore determine how much traffic an account used, but traffic statistics cannot establish what content the user accessed.

### Daily traffic retention

Daily upload and download totals are stored per user. The code and production cleanup rules are configured to delete them automatically after approximately two months.

This is daily aggregated metering data, not a per-connection log.

**Audit result: Passed.** The two-month retention configuration, daily schedule, observed date range, and relevant execution records were reviewed. The public package contains only evidence sanitized to avoid exposing production security information.

## 11. Online-device status audit

SingLinkVPN temporarily processes a user’s current online-device status to:

- Enforce device-count limits;
- Prevent use beyond the device entitlement of a plan;
- Determine whether a current device remains in a valid session.

The signed evidence package states that node-reported online IP state uses a 120-second application cache, the per-user online connection map uses a 300-second cache, and stale node components are pruned after 100 seconds.

The audit team also inspected the related persistence and backup configuration and found no use of temporary online-device state to create a long-term connection history.

**Audit result: Passed.**

## 12. Virtual email and order-number audit

SingLinkVPN’s account system processes:

- Virtual email addresses used for registration;
- Order numbers;
- Plan and subscription status;
- The minimum records required for after-sales inquiries.

This data is used only to:

- Look up subscriptions;
- Verify orders;
- Recover accounts;
- Resolve payment issues;
- Provide after-sales support.

Virtual email addresses and order numbers do not contain browsing activity. Related historical records are automatically cleaned on a three-month cycle, and users may request permanent account deletion.

The database fields, cleanup jobs, and execution state were reviewed in the restricted read-only environment. Sensitive runtime records are not public.

**Audit result: Passed.**

## 13. Customer-support ticket and SingChat audit

Customer-support tickets and SingChat may contain information voluntarily entered by users, including:

- Problem descriptions;
- Error information;
- Device information;
- Screenshots;
- Correspondence.

This is customer-support information voluntarily submitted by a user, not browsing logs automatically collected by the VPN.

SingChat and related support systems use a post-conversation automatic-deletion mechanism. Completed conversations are not subsequently used for:

- User profiling;
- Advertising analysis;
- Browsing-history analysis;
- Network-activity tracking;
- Long-term archiving of customer-support content.

The audit team inspected the cleanup mechanism and sampled state in the restricted read-only environment. Ticket content, backend screenshots, and execution records are not published because they contain user-private and internal security information.

**Audit result: Passed.**

## 14. Remote-diagnostic log audit

Remote diagnostics are used only when a user voluntarily requests after-sales support or technical assistance.

Their purposes include:

- Analyzing connection failures;
- Inspecting client status;
- Identifying node-configuration issues;
- Improving troubleshooting accuracy.

The remote-diagnostic project is open source and uses the following controls:

- Does not run as continuous background monitoring by default;
- Is generated only after a user voluntarily consents or submits it;
- Is not used to create browsing-activity records;
- Is not used for advertising or user profiling;
- Is retained for no more than 14 days;
- Is automatically cleaned and destroyed when the retention period expires.

The audit team inspected the diagnostic data structure, purpose limitation, retention configuration, and cleanup mechanism and confirmed that the maximum 14-day retention rule applies to diagnostic material voluntarily submitted by users. Individual records and internal job configuration are not public.

**Audit result: Passed.**

## 15. Local VPN-node logging audit

A strict no-activity-logs policy requires VPN nodes not to persistently store:

- Websites visited by users;
- Destination domains;
- Full URLs;
- DNS queries;
- Original IP addresses;
- User communication content;
- Node-usage history;
- Session mappings;
- Packet content;
- Connection logs capable of identifying browsing activity.

Nodes process only the temporary state required for real-time transmission in memory, including:

- Current protocol sessions;
- Data-forwarding buffers;
- Temporary routes;
- Network-connection state;
- Handshake state.

The audited party’s technical statement is:

> **SingLinkVPN nodes maintain only the temporary in-memory session state required to provide real-time forwarding. They do not write user destinations, DNS queries, communication content, or session mappings capable of identifying user network activity to persistent storage. When a connection ends, the related temporary state is automatically released.**

This is different from deleting logs that were already recorded.

SingLinkVPN’s approach is:

> **Do not generate user activity logs in the first place, rather than record them and delete them later.**

The audit team reviewed node logging policies and sampled runtime state in the restricted environment. Node addresses, process inventories, system-log configuration, resolver configuration, and crash-dump policies are sensitive infrastructure material and are not publicly disclosed.

**Audit result: Passed.**

## 16. Cloud-provider, CDN, and infrastructure-log audit

A no-activity-logs policy requires cloud platforms, CDNs, and infrastructure components not to create persistent records capable of identifying user VPN activity, including:

- Mappings between users’ original IP addresses and VPN accounts;
- Domains accessed by users;
- Full URLs;
- DNS queries;
- Node communication content;
- User browsing histories;
- VPN session-activity profiles.

Normal system-availability monitoring may include non-user-activity metrics such as CPU, memory, and disk utilization. Those metrics must be distinguished from metadata capable of identifying or reconstructing user network activity.

The audit team inspected the relevant provider configurations, retention policies, and access permissions in a restricted environment and found no persistent logs capable of identifying or reconstructing user VPN activity. Provider consoles, account identifiers, and internal configuration are not public.

**Audit result: Passed.**

## 17. Database-backup audit

If the production database does not collect the following data, its routine database backups should not contain those fields:

- Websites;
- Domains;
- URLs;
- DNS queries;
- Original IP addresses;
- Browsing content;
- Connection histories;

The audit team inspected backup scope, retention rules, and relevant data structures and found no user network-activity logs in backups. Limited account and order data remains subject to its applicable retention and deletion rules. Backup locations, recovery credentials, and internal disaster-recovery configuration are not public.

**Audit result: Passed.**

## 18. Administrator access and export-permission audit

A strict no-activity-logs design requires the administration system to have no function to query or export:

- Websites visited by a particular user;
- DNS queries made by a particular user;
- Full URLs accessed by a particular user;
- The history of specific VPN nodes used by a particular user;
- A particular user’s original IP history;
- A particular user’s browsing content;
- A particular user’s communication content.

Administrators and customer-support personnel can view only the limited account and order information required to provide the service and only within their authorized scope. Using restricted read-only access, the audit team inspected role permissions, query capabilities, and export interfaces and found no capability to query or export user network-activity logs. The permission matrix and backend interface are not public.

**Audit result: Passed.**

## 19. Data-retention and automatic-cleanup matrix

The following table summarizes the data-processing and automatic-cleanup rules verified in this audit. The public package provides a sanitized summary, while sensitive production execution records were reviewed by the audit team in the restricted read-only environment.

| Data type | Recorded? | Purpose | Retention period |
| --- | --- | --- | --- |
| Websites visited | No | Not applicable | 0 |
| Destination domains | No | Not applicable | 0 |
| Full URLs | No | Not applicable | 0 |
| DNS queries | No | Not applicable | 0 |
| Browsing content | No | Not applicable | 0 |
| Network communication content | No | Not applicable | 0 |
| Original IP history | No | Not applicable | 0 |
| Node-usage history | No | Not applicable | 0 |
| Individual connection history | No | Not applicable | 0 |
| Cumulative upload and download totals | Yes | Plan and traffic metering | Processed according to the account service cycle |
| Last-used status | Yes | Account-state management | Does not form connection history |
| Daily traffic total | Yes | Daily allowance calculation | Approximately 2 months |
| Online-device status | Temporarily processed | Device-count limits | During the session |
| Virtual email address | Yes | Registration and after-sales support | Approximately 3-month cleanup cycle |
| Order number | Yes | Subscription and after-sales support | Approximately 3-month cleanup cycle |
| Customer-support tickets and SingChat | Voluntarily submitted by user | Customer support | Deleted after the conversation ends |
| Remote-diagnostic data | Voluntarily submitted by user | Troubleshooting | Maximum 14 days |
| Temporary node-session state | Temporarily processed | Real-time forwarding | Released after disconnection |

## 20. Summary of the no-logs technical design

SingLinkVPN’s no-logs design can be summarized in four principles.

### 20.1 Do not collect

For websites, domains, URLs, DNS queries, original IP addresses, and browsing content, the system does not create corresponding data fields or persistent reporting interfaces.

### 20.2 Process in memory

VPN nodes process only the temporary session state required for real-time forwarding in memory and automatically release it when a connection ends.

### 20.3 Minimize metering data

The traffic system stores only the aggregate values required to provide plan and allowance functions. It does not store traffic destinations or content.

### 20.4 Automatically destroy

Daily traffic, customer-support information, diagnostic information, and limited account information have separate cleanup cycles to prevent indefinite retention.

## 21. Audit conclusion

Based on the independent third-party read-only production review as of July 29, 2026, VPNTestor Platform concludes:

1. No evidence was found that SingLinkVPN records or persists websites visited, destination domains, full URLs, or browsing content.
2. No evidence was found that SingLinkVPN records or persists user DNS queries.
3. No user source-IP history was found in the central control plane or node systems.
4. No activity-linkage record was found connecting an account, a specific node, connection timing, and a destination.
5. No evidence was found that VPN nodes write user activity or communication content to persistent logs.
6. No data capable of reconstructing user network activity was found in cloud-provider, CDN, or database-backup systems within scope.
7. The administration interface has no function for querying or exporting user network-activity logs.
8. Traffic totals, daily usage, online-device state, virtual email, orders, support data, and user-submitted diagnostics are limited service data and do not contain specific destinations or communication content.
9. Limited service data is subject to purpose restrictions and automatic cleanup periods.
10. SingLinkVPN's implemented system design is consistent with its strict no-activity-logs policy.
11. The public evidence package, complete workpapers, and integrity signatures all verified; restricted evidence not published publicly was reviewed in the read-only environment.
12. James Robert Smith signed the SHA-256 manifest for both final reports with Ed25519, enabling public verification of file integrity.

### Final audit opinion

> **Within the scope stated in this report and the production environment as of July 29, 2026, no evidence was found that SingLinkVPN records, retains, monitors, or provides specific user network activity. The audit supports SingLinkVPN's claim that it does not log websites, destination domains, full URLs, DNS queries, source IPs, browsing content, or communication content. The result of this independent third-party no-logs policy technical verification is: Passed.**

## 22. Report limitations

This report applies only to:

- The audited systems identified in the report;
- The production-environment state as of July 29, 2026;
- The technical scope for which read-only access was provided;
- The services and node configurations identified in this report.

This report does not constitute:

- A permanent guarantee covering all future versions;
- Legal compliance advice;
- A SOC 2 assurance report;
- ISO certification;
- A financial audit;
- Legal assurance regarding data-center or IP ownership.

Verification should be repeated after a material change to the system, code, third-party suppliers, or data-processing practices.

The public evidence package is a sanitized subset intended for external integrity checks and cannot display all restricted production evidence. The audit team reviewed the private-source version, production queries, nodes and resolved endpoints, persistence and backups, cloud and CDN controls, support systems, and diagnostic cleanup mechanisms in a read-only environment. Withholding sensitive evidence from publication does not change the audit conclusion within the stated scope.

## 23. Signature page

**Audit organization:** VPNTestor Platform  
**Audit team:** Openscore VPN  
**Lead auditor:** James Robert Smith  
**Report type:** Independent Third-Party Technical Verification Report of the No-Logs Policy  
**Service reviewed:** SingLinkVPN  
**Report version:** 1.0  
**Audit reference date:** July 29, 2026  
**Audit conclusion:** Passed

### Signature status

**Signed — on July 29, 2026, James Robert Smith used an Ed25519 key to sign the SHA-256 manifest for both final reports.**

Signing-public-key fingerprint: `SHA256:P0NcmbNqWFxSf8SbmQMIJRUYpRQXetoY9VDysZvt8IU`

The signature verifies file integrity and the signing act for this version.
