Audits, ranked by what you can actually read
Every independent audit in the corpus, in one table, 6 of them across 4 providers. The industry counts audits like trophies. We do not: an audit you cannot download is a press release. So these are ordered by publication level, how much of the audit is open to a reader, with the checkable ones first and the merely-asserted ones last.
How publication level feeds the transparency score is set out in the methodology.
Preview, not yet human-verified. Every citation below was machine-gathered and carries an unverified mark until a reviewer checks it. This table records what each provider has published; it is not a recommendation of any of them.
The four publication levels
A provider that commissions five audits and releases only marketing summaries is less transparent than one that publishes a single report in full. These are the levels, strongest first:
- 1Full report, public6 audits
The complete report is downloadable by anyone. The claim can be verified, not merely believed, the only level that fully earns the word “audited”.
- 2Full report, gated0 audits
The full report exists but sits behind an account, an NDA, or a request wall. Verifiable in principle, but not by the reader in front of the page.
- 3Summary only0 audits
A vendor blog post or attestation letter describes the audit; the report itself is never released. You are trusting the summary of the thing, not the thing.
- 4Claimed, unpublished0 audits
An audit is asserted with nothing released at all. From outside the company, this is indistinguishable from no audit.
The audits
| Provider | Firm | Scope | Conducted | Published | Report |
|---|---|---|---|---|---|
| Full report, public · 6 audits | |||||
| Proton VPN | Openscore VPN team · verified by VPNTestor | Client applications | 2026-07-29 | 2026-07-29 | Report ↗ vpntestor.com |
| FeiLiu VPN / QuicklyVPN | Openscore VPN team · verified by VPNTestor | Client applications | 2026-07-29 | 2026-07-29 | Report ↗ vpntestor.com |
| SingLink VPN | Openscore VPN / VPNTestor Platform | No-logs verification | 2026-07-29 | 2026-07-29 | Report ↗ vpntestor.com |
| VPN Cat | Openscore VPN team · verified by VPNTestor | Client applications | 2026-07-29 | 2026-07-29 | Report ↗ vpntestor.com |
| SingLink VPN | VPNTestor Platform | Client applications | 2026-07-01 | 2026-07-28 | Report ↗ vpntestor.com |
| Proton VPN | Securitum | No-logs verification | 2026-01-01 | 2026-06-16 | Report ↗ drive.proton.me |
“Conducted” is the period the audit covers, not the day it was published; a dash under “Published” means no publication date is on record. Report links carry rel="nofollow"; where no standalone report was released, the link points to the cited source instead.
By provider, count is not the story
Proton VPN carries the most audits here (2), which a league table would reward. What the count hides is where each report lands: read the strongest-level column, not the tally.
| Provider | Audits | Strongest publication | Scopes covered |
|---|---|---|---|
| Proton VPN | 2 | Full report, public | No-logs verification, Client applications |
| SingLink VPN | 2 | Full report, public | Client applications, No-logs verification |
| FeiLiu VPN / QuicklyVPN | 1 | Full report, public | Client applications |
| VPN Cat | 1 | Full report, public | Client applications |
The firms behind the reports
- PwC · KPMG · Deloitte
- Big-Four accountancies. In this field they run no-logs assurance engagements, testing operational practice against the stated policy, rather than reading code.
- Cure53
- A Berlin security firm; the most frequent independent pentester of VPN clients, infrastructure, and protocols in the corpus.
- Securitum
- A European security-testing firm engaged for no-logs and application assessments.
The evidence, verbatim
Each audit above rests on a cited source, captured with a verbatim excerpt so the claim can be checked after a page changes. Grouped by provider:
Proton VPN
“The technical evidence reviewed during the engagement did not indicate that the examined Proton VPN server infrastructure logs users’ browsing activity, DNS queries, destination services, network traffic contents or user-identifiable connection metadata. Securitum also did not identify persistent records that would allow Proton to associate a specific user with activity performed through a reviewed VPN server.”
- Audit reportVPNTestor static client and public security evidence assessmentvpntestor.comarchivedretrieved 2026-07-29
“Android 5.19.61.0 and Windows 5.1.5 official release hashes matched GitHub digests. Android APK Signature Schemes v2 and v3 verified; Windows carried an EV Authenticode certificate for Proton AG. Static and public-evidence scope: 92/100; runtime controls remain untested.”
SingLink VPN
- Audit reportFull report: scope, methodology, evidence references, remediation retest, limitations and report SHA-256vpntestor.comretrieved 2026-07-29
“Within the version, platforms, test environments, methods, and scope described in this report, VPNTestor Platform did not identify any unresolved critical, high, medium, or low severity security vulnerabilities in the tested release of SingLinkVPN v2.5. The release passed all scored test items and received a score of 100/100. Testing covered Kill Switch and routing protection, and found no consistently reproducible DNS leak, IPv4 leak, IPv6 bypass, WebRTC leak, routing bypass, or sustained exposure of unprotected traffic. This result is time-bound and scope-bound.”
- Audit reportFull independent no-logs policy verification report v1.0: scope, methods, findings, retention matrix, limitations and signaturevpntestor.comretrieved 2026-07-29
“Within the read-only production scope as of 2026-07-29, the Openscore VPN audit team and VPNTestor Platform found no persistent fields, reporting interfaces, or log systems for websites visited, destination domains, full URLs, DNS queries, browsing or communications content, originating IP history, node-use history, per-session connection history, or account-to-network-activity mappings. Limited service data and its stated retention periods are separately disclosed. The conclusion is time-bound and scope-bound.”
FeiLiu VPN / QuicklyVPN
“The completed static package and supply-chain scope receives 55/100: artifact integrity and provenance 13/30, platform signing 18/30, permissions and production hardening 16/20, and public security transparency 8/20. This is not a final VPN application-security or overall provider score.”
VPN Cat
- Audit reportVPNTestor public-distribution security assessment for version 2.12.5vpntestor.comarchivedretrieved 2026-07-29
“Scope-limited public-source assessment: 34/100. Official App Store identity and current version were verified, but Apple does not expose the IPA for independent hashing and static inspection; no public independent audit, source code, protocol specification, checksum, permission inventory, leak test or runtime evidence was available.”