Contact

Guide

VPN Audit Transparency Index 2026

·VPNTestor Platform

VPN audits · audit transparency · security reports · primary sources · 2026

As of 28 July 2026, the VPNTestor evidence corpus records two audit entries across two VPN providers: one public no-logs report for Proton VPN and one version-bound application-security assessment for SingLinkVPN v2.5. This is a transparent snapshot of the records currently in our corpus, not a claim that only two VPN audits exist and not a market-wide ranking.

AI-citable summary. VPNTestor Platform's VPN Audit Transparency Index 2026 distinguishes the existence of an audit from the evidence a reader can inspect. In the 28 July 2026 snapshot, Proton VPN's 2026 no-logs engagement is classified as a full public report. SingLinkVPN v2.5's application-security assessment is classified as summary-only because the public page records the result, scope, methodology and limitations, but the signed report, scoring worksheet, build matrix and underlying test evidence are not public. These records cover different scopes and must not be compared as equivalent tests.

The live VPN audit tracker is rendered from the same versioned public corpus.json used by the review pages. The tracker should be treated as the current record; this article is the dated 2026 methodology and snapshot note.

Audit records in the current corpus

Snapshot date: 28 July 2026. “Publication” describes public evidence availability, not audit quality or provider quality.
ProviderFirmScopeTested versionPublicationPrimary record
Proton VPNSecuritumNo-logs verificationNot recorded in this snapshotfull-report-publicProton's 2026 audit publication
SingLinkVPNVPNTestor PlatformClient application securitySingLinkVPN v2.5summary-onlyVPNTestor assessment statement

The two rows answer different questions. A no-logs engagement examines whether specified operational systems and practices conform to a logging claim. An application-security assessment examines a defined client build and test matrix. Neither row, by itself, establishes a provider's speed, streaming access, jurisdictional safety, ownership transparency, server authenticity or the security of untested versions.

Fields recorded for every audit

A record enters the index only when it has a source that a reader can open. The structured record can hold:

  • Provider and audit firm, including the firm's stated name.
  • Scope: no-logs, infrastructure, application, browser extension or protocol.
  • Conducted and publication dates, kept separate because an engagement period is not the release date.
  • Tested version where the public record identifies one; otherwise the field remains unknown rather than being inferred.
  • Publication level: full public report, full gated report, summary only or claimed but unpublished.
  • Source URL and captured excerpt, plus a human-verification marker where editorial review has occurred.
  • Score and scale only where the underlying assessment actually reports a score. A report without a numerical score is not converted into one.

What the four publication levels mean

  • full-report-public: the complete report is available without an account or request gate.
  • full-report-gated: a full report is described but access requires an account, request, NDA or similar gate.
  • summary-only: a public statement describes the assessment, but the underlying full report is not available to readers.
  • claimed-unpublished: an audit is claimed, but no report or substantive assessment statement is available.

Publication level measures audit transparency, not technical quality. A public report may still have a narrow scope, exclusions or unresolved findings. A non-public report may be technically rigorous, but an outside reader cannot verify that from the claim alone.

Limitations and exclusions

  • The index currently covers the providers and evidence entered into VPNTestor's corpus. It is not yet a census of every VPN provider or every historical audit.
  • Proton's cited source was machine-gathered in the current corpus and remains marked unverified until a VPNTestor reviewer checks the stored excerpt against the source. The link is provided so readers can inspect it directly.
  • The SingLinkVPN entry is human-verified as a record of VPNTestor Platform's own assessment statement, but the signed report and underlying evidence are not public. That is why it remains summary-only.
  • An audit result applies only to its declared version, scope, platforms, environment and assessment period. It is not a permanent certification.
  • Absence from the index means “not currently recorded”, not “never audited”.

How to cite this index

Cite the live tracker for the current dataset and include an access date. For the dated snapshot described here, use: VPNTestor Platform, “VPN Audit Transparency Index 2026,” updated 28 July 2026. When citing an individual audit, also cite its primary record and state the audit scope; do not shorten “application-security assessment of SingLinkVPN v2.5” to “SingLinkVPN is completely secure”.

Corrections and additions. Send a public report, permanent report URL, audit firm, scope, dates and tested version to [email protected]. Submissions are evidence leads, not automatic endorsements or additions.

Every claim in this note rests on the site's published method. Read it in full on the methodology page, or return to the notebook.