Contact

Audits, ranked by what you can actually read

Every independent audit in the corpus, in one table, 6 of them across 4 providers. The industry counts audits like trophies. We do not: an audit you cannot download is a press release. So these are ordered by publication level, how much of the audit is open to a reader, with the checkable ones first and the merely-asserted ones last.

How publication level feeds the transparency score is set out in the methodology.

Preview, not yet human-verified. Every citation below was machine-gathered and carries an unverified mark until a reviewer checks it. This table records what each provider has published; it is not a recommendation of any of them.

The four publication levels

A provider that commissions five audits and releases only marketing summaries is less transparent than one that publishes a single report in full. These are the levels, strongest first:

  1. 1
    Full report, public6 audits

    The complete report is downloadable by anyone. The claim can be verified, not merely believed, the only level that fully earns the word “audited”.

  2. 2
    Full report, gated0 audits

    The full report exists but sits behind an account, an NDA, or a request wall. Verifiable in principle, but not by the reader in front of the page.

  3. 3
    Summary only0 audits

    A vendor blog post or attestation letter describes the audit; the report itself is never released. You are trusting the summary of the thing, not the thing.

  4. 4
    Claimed, unpublished0 audits

    An audit is asserted with nothing released at all. From outside the company, this is indistinguishable from no audit.

The audits

ProviderFirmScopeConductedPublishedReport
Full report, public · 6 audits
Proton VPNOpenscore VPN team · verified by VPNTestorClient applications2026-07-292026-07-29Report vpntestor.com
FeiLiu VPN / QuicklyVPNOpenscore VPN team · verified by VPNTestorClient applications2026-07-292026-07-29Report vpntestor.com
SingLink VPNOpenscore VPN / VPNTestor PlatformNo-logs verification2026-07-292026-07-29Report vpntestor.com
VPN CatOpenscore VPN team · verified by VPNTestorClient applications2026-07-292026-07-29Report vpntestor.com
SingLink VPNVPNTestor PlatformClient applications2026-07-012026-07-28Report vpntestor.com
Proton VPNSecuritumNo-logs verification2026-01-012026-06-16Report drive.proton.me

“Conducted” is the period the audit covers, not the day it was published; a dash under “Published” means no publication date is on record. Report links carry rel="nofollow"; where no standalone report was released, the link points to the cited source instead.

By provider, count is not the story

Proton VPN carries the most audits here (2), which a league table would reward. What the count hides is where each report lands: read the strongest-level column, not the tally.

ProviderAuditsStrongest publicationScopes covered
Proton VPN2Full report, publicNo-logs verification, Client applications
SingLink VPN2Full report, publicClient applications, No-logs verification
FeiLiu VPN / QuicklyVPN1Full report, publicClient applications
VPN Cat1Full report, publicClient applications

The firms behind the reports

PwC · KPMG · Deloitte
Big-Four accountancies. In this field they run no-logs assurance engagements, testing operational practice against the stated policy, rather than reading code.
Cure53
A Berlin security firm; the most frequent independent pentester of VPN clients, infrastructure, and protocols in the corpus.
Securitum
A European security-testing firm engaged for no-logs and application assessments.

The evidence, verbatim

Each audit above rests on a cited source, captured with a verbatim excerpt so the claim can be checked after a page changes. Grouped by provider:

Proton VPN

  • Audit reportAs the latest (2026) report concludesprotonvpn.comretrieved 2026-07-29
    The technical evidence reviewed during the engagement did not indicate that the examined Proton VPN server infrastructure logs users’ browsing activity, DNS queries, destination services, network traffic contents or user-identifiable connection metadata. Securitum also did not identify persistent records that would allow Proton to associate a specific user with activity performed through a reviewed VPN server.
  • Audit reportVPNTestor static client and public security evidence assessmentvpntestor.comarchivedretrieved 2026-07-29
    Android 5.19.61.0 and Windows 5.1.5 official release hashes matched GitHub digests. Android APK Signature Schemes v2 and v3 verified; Windows carried an EV Authenticode certificate for Proton AG. Static and public-evidence scope: 92/100; runtime controls remain untested.

SingLink VPN

  • Audit reportFull report: scope, methodology, evidence references, remediation retest, limitations and report SHA-256vpntestor.comretrieved 2026-07-29
    Within the version, platforms, test environments, methods, and scope described in this report, VPNTestor Platform did not identify any unresolved critical, high, medium, or low severity security vulnerabilities in the tested release of SingLinkVPN v2.5. The release passed all scored test items and received a score of 100/100. Testing covered Kill Switch and routing protection, and found no consistently reproducible DNS leak, IPv4 leak, IPv6 bypass, WebRTC leak, routing bypass, or sustained exposure of unprotected traffic. This result is time-bound and scope-bound.
  • Audit reportFull independent no-logs policy verification report v1.0: scope, methods, findings, retention matrix, limitations and signaturevpntestor.comretrieved 2026-07-29
    Within the read-only production scope as of 2026-07-29, the Openscore VPN audit team and VPNTestor Platform found no persistent fields, reporting interfaces, or log systems for websites visited, destination domains, full URLs, DNS queries, browsing or communications content, originating IP history, node-use history, per-session connection history, or account-to-network-activity mappings. Limited service data and its stated retention periods are separately disclosed. The conclusion is time-bound and scope-bound.

FeiLiu VPN / QuicklyVPN

  • Audit reportArtifact table, findings and limitationsvpntestor.comarchivedretrieved 2026-07-29
    The completed static package and supply-chain scope receives 55/100: artifact integrity and provenance 13/30, platform signing 18/30, permissions and production hardening 16/20, and public security transparency 8/20. This is not a final VPN application-security or overall provider score.

VPN Cat

  • Audit reportVPNTestor public-distribution security assessment for version 2.12.5vpntestor.comarchivedretrieved 2026-07-29
    Scope-limited public-source assessment: 34/100. Official App Store identity and current version were verified, but Apple does not expose the IPA for independent hashing and static inspection; no public independent audit, source code, protocol specification, checksum, permission inventory, leak test or runtime evidence was available.