Contact

News

Proton VPN 2026 client and no-logs security assessment

·Openscore VPN team · verified by VPNTestor

Proton VPN · security audit · no-logs audit · Android · Windows

On 29 July 2026, the Openscore VPN team downloaded two versioned releases from Proton VPN's official GitHub organization, verified their published hashes and signing, and reviewed public source code, privacy documents, the 2026 Securitum no-logs audit and Proton's current transparency report. VPNTestor independently confirmed the record.

Result: 92/100 for the completed scope. Android 5.19.61.0 and Windows 5.1.5 passed the frozen artifact, signature and production-build checks performed here. Major clients are open source and the 2026 infrastructure no-logs report is public. This is a static client, supply-chain and public-evidence score—not the overall VPN score and not a substitute for runtime leakage or penetration tests.

Exact hashes, certificate identity, permissions, findings, scoring and exclusions are preserved in the machine-readable evidence record.

Frozen release artifacts

  • Android 5.19.61.0, package ch.protonvpn.android, 55,806,557 bytes, SHA-256 568b0f05…517633a.
  • Windows x64 5.1.5, 128,808,528 bytes, SHA-256 1e6600e4…cba1d9c.

Both local hashes matched the SHA-256 digests published with the official GitHub release assets. This establishes exact artifact consistency with that release channel.

Signing and production hardening

The Android APK passed APK Signature Scheme v2 and v3 verification. It targets Android API 35, is not debuggable, disables Android backup and declares a custom network-security configuration. The manifest requests package visibility and camera access in addition to expected VPN lifecycle permissions. Those can support per-app routing and QR import, but their runtime data flows were not exercised.

The Windows installer contains an Authenticode signature with an EV code-signing certificate issued to Proton AG, organization identifier CHE-354.686.492, chained through Sectigo and accompanied by a timestamp chain. macOS and iOS binaries were not frozen in this test run.

Open source and audit transparency

Proton VPN publishes active repositories for Windows, Android, iOS/macOS, Linux and its browser extension. The official GitHub organization is domain-verified and the reviewed repositories were updated during 2026. Open source enables inspection; it does not by itself prove that every store binary is reproducibly built from a particular commit.

Securitum's fifth annual no-logs review examined production server configurations and operating controls. Its published 2026 conclusion reports no evidence of logging browsing activity, DNS queries, destination services, traffic contents or user-identifiable connection metadata in the examined infrastructure. That scope supports a no-logs conclusion; it is not a universal application vulnerability audit.

Proton's transparency report, updated 14 July 2026, reports 47 legally binding Swiss orders through June 2026 and says all 47 were denied because identifying connection logs were unavailable. The count is a provider transparency publication, not independently re-created court data.

Static and public-evidence score: 92/100

  • Artifact integrity and provenance: 29/30.
  • Platform signing: 28/30.
  • Permissions and production hardening: 17/20.
  • Public security transparency: 18/20.

Deductions reflect the absence of independently frozen macOS/iOS artifacts in this run, broad Android permissions not runtime-validated, version-specific client audits that do not cover every current release, and reliance on the same GitHub channel for both assets and digests.

What this assessment does not prove

  • IPv4, IPv6, DNS, WebRTC and route leakage.
  • Kill Switch behavior under interruption, termination and network switching.
  • Account, session, dashboard and cross-account authorization.
  • Local runtime logging, credential storage and uninstall remnants.
  • Streaming availability, sustained speed and latency.
  • Infrastructure security outside Securitum's published no-logs scope.
Retest channel. Additional signed release manifests, current client audit reports, reproducible-build records or isolated runtime evidence can be sent to [email protected]. New evidence is dated and independently checked.

Every claim in this note rests on the site's published method. Read it in full on the methodology page, or return to the notebook.