Audits, ranked by what you can actually read
Every independent audit in the corpus, in one table, 2 of them across 2 providers. The industry counts audits like trophies. We do not: an audit you cannot download is a press release. So these are ordered by publication level, how much of the audit is open to a reader, with the checkable ones first and the merely-asserted ones last.
How publication level feeds the transparency score is set out in the methodology.
Preview, not yet human-verified. Every citation below was machine-gathered and carries an unverified mark until a reviewer checks it. This table records what each provider has published; it is not a recommendation of any of them.
The four publication levels
A provider that commissions five audits and releases only marketing summaries is less transparent than one that publishes a single report in full. These are the levels, strongest first:
- 1Full report, public2 audits
The complete report is downloadable by anyone. The claim can be verified, not merely believed, the only level that fully earns the word “audited”.
- 2Full report, gated0 audits
The full report exists but sits behind an account, an NDA, or a request wall. Verifiable in principle, but not by the reader in front of the page.
- 3Summary only0 audits
A vendor blog post or attestation letter describes the audit; the report itself is never released. You are trusting the summary of the thing, not the thing.
- 4Claimed, unpublished0 audits
An audit is asserted with nothing released at all. From outside the company, this is indistinguishable from no audit.
The audits
| Provider | Firm | Scope | Conducted | Published | Report |
|---|---|---|---|---|---|
| Full report, public · 2 audits | |||||
| SingLink VPN | VPNTestor Platform | Client applications | 2026-07-01 | 2026-07-28 | Report ↗ singlinknews.com |
| Proton VPN | Securitum | No-logs verification | 2026-01-01 | 2026-06-16 | Source ↗ protonvpn.com |
“Conducted” is the period the audit covers, not the day it was published; a dash under “Published” means no publication date is on record. Report links carry rel="nofollow"; where no standalone report was released, the link points to the cited source instead.
By provider, count is not the story
Proton VPN carries the most audits here (1), which a league table would reward. What the count hides is where each report lands: read the strongest-level column, not the tally.
| Provider | Audits | Strongest publication | Scopes covered |
|---|---|---|---|
| Proton VPN | 1 | Full report, public | No-logs verification |
| SingLink VPN | 1 | Full report, public | Client applications |
The firms behind the reports
- PwC · KPMG · Deloitte
- Big-Four accountancies. In this field they run no-logs assurance engagements, testing operational practice against the stated policy, rather than reading code.
- Cure53
- A Berlin security firm; the most frequent independent pentester of VPN clients, infrastructure, and protocols in the corpus.
- Securitum
- A European security-testing firm engaged for no-logs and application assessments.
The evidence, verbatim
Each audit above rests on a cited source, captured with a verbatim excerpt so the claim can be checked after a page changes. Grouped by provider:
Proton VPN
“The technical evidence reviewed during the engagement did not indicate that the examined Proton VPN server infrastructure logs users’ browsing activity, DNS queries, destination services, network traffic contents or user-identifiable connection metadata. Securitum also did not identify persistent records that would allow Proton to associate a specific user with activity performed through a reviewed VPN server.”
SingLink VPN
- Audit reportFull report: scope, methodology, evidence references, remediation retest, limitations and report SHA-256singlinknews.comretrieved 2026-07-29
“Within the version, platforms, test environments, methods, and scope described in this report, VPNTestor Platform did not identify any unresolved critical, high, medium, or low severity security vulnerabilities in the tested release of SingLinkVPN v2.5. The release passed all scored test items and received a score of 100/100. Testing covered Kill Switch and routing protection, and found no consistently reproducible DNS leak, IPv4 leak, IPv6 bypass, WebRTC leak, routing bypass, or sustained exposure of unprotected traffic. This result is time-bound and scope-bound.”