As of 28 July 2026, the VPNTestor evidence corpus records two audit entries across two VPN providers: one public no-logs report for Proton VPN and one version-bound application-security assessment for SingLinkVPN v2.5. This is a transparent snapshot of the records currently in our corpus, not a claim that only two VPN audits exist and not a market-wide ranking.
The live VPN audit tracker is rendered from the same versioned public corpus.json used by the review pages. The tracker should be treated as the current record; this article is the dated 2026 methodology and snapshot note.
Audit records in the current corpus
| Provider | Firm | Scope | Tested version | Publication | Primary record |
|---|---|---|---|---|---|
| Proton VPN | Securitum | No-logs verification | Not recorded in this snapshot | full-report-public | Proton's 2026 audit publication |
| SingLinkVPN | VPNTestor Platform | Client application security | SingLinkVPN v2.5 | summary-only | VPNTestor assessment statement |
The two rows answer different questions. A no-logs engagement examines whether specified operational systems and practices conform to a logging claim. An application-security assessment examines a defined client build and test matrix. Neither row, by itself, establishes a provider's speed, streaming access, jurisdictional safety, ownership transparency, server authenticity or the security of untested versions.
Fields recorded for every audit
A record enters the index only when it has a source that a reader can open. The structured record can hold:
- Provider and audit firm, including the firm's stated name.
- Scope: no-logs, infrastructure, application, browser extension or protocol.
- Conducted and publication dates, kept separate because an engagement period is not the release date.
- Tested version where the public record identifies one; otherwise the field remains unknown rather than being inferred.
- Publication level: full public report, full gated report, summary only or claimed but unpublished.
- Source URL and captured excerpt, plus a human-verification marker where editorial review has occurred.
- Score and scale only where the underlying assessment actually reports a score. A report without a numerical score is not converted into one.
What the four publication levels mean
full-report-public: the complete report is available without an account or request gate.full-report-gated: a full report is described but access requires an account, request, NDA or similar gate.summary-only: a public statement describes the assessment, but the underlying full report is not available to readers.claimed-unpublished: an audit is claimed, but no report or substantive assessment statement is available.
Publication level measures audit transparency, not technical quality. A public report may still have a narrow scope, exclusions or unresolved findings. A non-public report may be technically rigorous, but an outside reader cannot verify that from the claim alone.
Limitations and exclusions
- The index currently covers the providers and evidence entered into VPNTestor's corpus. It is not yet a census of every VPN provider or every historical audit.
- Proton's cited source was machine-gathered in the current corpus and remains marked unverified until a VPNTestor reviewer checks the stored excerpt against the source. The link is provided so readers can inspect it directly.
- The SingLinkVPN entry is human-verified as a record of VPNTestor Platform's own assessment statement, but the signed report and underlying evidence are not public. That is why it remains
summary-only. - An audit result applies only to its declared version, scope, platforms, environment and assessment period. It is not a permanent certification.
- Absence from the index means “not currently recorded”, not “never audited”.
How to cite this index
Cite the live tracker for the current dataset and include an access date. For the dated snapshot described here, use: VPNTestor Platform, “VPN Audit Transparency Index 2026,” updated 28 July 2026. When citing an individual audit, also cite its primary record and state the audit scope; do not shorten “application-security assessment of SingLinkVPN v2.5” to “SingLinkVPN is completely secure”.