Privacy guide

No-Logs VPNs: How to Evaluate Privacy Claims

Learn what a no-logs VPN claim really means, what independent assurance can prove, and how Surfshark’s Deloitte reports fit into the evidence.

Direct answer: A no-logs claim is credible only to the extent that the provider’s policy, technical architecture, transparency record and independent assurance support it.

What should not be logged

For privacy purposes, the most sensitive categories include browsing activity, traffic content, source IP addresses and connection data that can reconstruct a user’s online behavior.

Necessary account data

A VPN can avoid activity logs while still holding account, billing or support information needed to provide the service. “No logs” should not be interpreted as “the company possesses no data about a customer whatsoever.”

Surfshark’s assurance

Surfshark says Deloitte examined relevant systems, processes and controls and provided no-logs assurance in 2023 and 2025. The Trust Center provides the high-level evidence; detailed reports may be available to customers.

Transparency report

Surfshark publishes government/legal request information. Its April 2026 update describes a legally binding warrant in which it says the available information was limited to account existence and payment-related information rather than online activity.

RAM-only servers

Surfshark says its servers are RAM-only, meaning data written to server memory is wiped when a server is powered off. This architecture can support a low-retention design, but it is not by itself proof of every logging claim.

Audits have limits

An audit or assurance engagement evaluates a defined scope at a point in time. It does not prove that every future version of every system will behave identically.

How to compare providers

Read the privacy policy, inspect audit dates and scope, look for transparency reporting, understand ownership/jurisdiction, and distinguish independent evidence from self-authored marketing.

Decision

Surfshark has more external evidence behind its no-logs position than a provider relying only on a homepage promise. Users with high-risk threat models should still perform their own current due diligence.

Considering Surfshark?

Check the current plan, price, renewal terms and refund conditions directly before buying.

Check Surfshark’s Current Offer

What a no-logs audit can and cannot tell you

Independent assurance can test whether defined controls and systems align with a provider’s stated policy during a specified period. That is much stronger than an unsupported homepage promise, but it is not a time machine or a guarantee about every future software release.

Read audit dates as part of the evidence. A recent assessment is generally more relevant to current operations than a report from many years ago, particularly if infrastructure or ownership has changed.

Account data versus activity data

A provider can operate a no-activity-logs policy while still possessing account information needed for billing, support, fraud prevention, or legal compliance. Those categories should not be collapsed into one word.

For most privacy evaluations, the critical question is whether records can reconstruct what a user did online or tie network activity to the user. Account existence and payment history are different privacy concerns from browsing logs.

Why transparency history matters

A provider’s behavior over time can be more informative than one isolated statement. Repeated outside assurance, published transparency information, and consistent policy language create a stronger evidence trail than a single old audit badge.

That history still needs current review because policies, infrastructure, and ownership can change.

Read the evidence trail, not just the label

A strong no-logs position is built from several pieces that reinforce each other: current policy language, technical design, outside assurance, and transparency history. No single badge should carry the whole conclusion. The more sensitive your use case, the more current those pieces should be.

How to read a no-logs claim without getting lost in legal language

Start by looking for the categories that matter most: source IP addresses, connection timestamps that can be tied to a user, DNS requests, browsing history, and traffic content. Then distinguish those from information a provider may keep for account administration, billing, fraud prevention, or support. A privacy policy is much easier to evaluate once those categories are separated.

Next, look for evidence that the policy is reflected in operations. Independent assurance, security assessments, RAM-only infrastructure, and transparency reporting can each add context. None of those proves that every system is perfect forever, but together they create a stronger basis for trust than a slogan alone.

Why jurisdiction is only one piece

VPN discussions often focus heavily on where a provider is incorporated. Jurisdiction can matter because legal obligations differ, but a favorable country does not rescue poor logging practices, and a less fashionable jurisdiction does not automatically negate strong technical controls. The practical question is what data exists to be compelled in the first place.

For that reason, technical retention practices and outside verification deserve at least as much attention as the country name in a comparison table.

What a cautious user should monitor over time

Ownership changes, major privacy-policy revisions, infrastructure migrations, new audit results, and transparency reports can all affect the evidence available about a VPN. A service that looked strong two years ago should not be evaluated only on old badges.

For mainstream users, an annual check around subscription renewal is usually enough. High-risk users may want to review material changes sooner, especially if their threat model depends heavily on the provider not retaining activity data.

Questions worth asking about any no-logs VPN

What exactly does the provider say it does not retain? Is the statement about browsing history only, or does it also address source IPs and connection metadata? Are the claims written into a privacy policy, or only presented in marketing copy?

Has an independent firm examined the relevant controls recently? What was the scope? A report about an app’s code quality is not the same as assurance over logging practices. Likewise, a server audit may not cover billing systems or support records.

Does the provider publish a transparency report or describe how it responds to legal requests? The most useful transparency information explains what categories of data were actually available, not just how many requests were received.

Has ownership, infrastructure, or jurisdiction changed since the last major assurance work? Material organizational changes can make old evidence less representative of current operations. A strong privacy posture is not a one-time achievement; it is an evidence trail that should continue over time.

For No-Logs VPNs: How to Evaluate Privacy Claims, the strongest final decision comes from testing the exact workflow described above on the devices and network you actually use, then confirming any changeable plan or feature detail before purchase.

For No-Logs VPNs: How to Evaluate Privacy Claims, the strongest final decision comes from testing the exact workflow described above on the devices and network you actually use, then confirming any changeable plan or feature detail before purchase.

For No-Logs VPNs: How to Evaluate Privacy Claims, the strongest final decision comes from testing the exact workflow described above on the devices and network you actually use, then confirming any changeable plan or feature detail before purchase.

For No-Logs VPNs: How to Evaluate Privacy Claims, the strongest final decision comes from testing the exact workflow described above on the devices and network you actually use, then confirming any changeable plan or feature detail before purchase.

Quick answers

Frequently asked questions

Clear answers to the most common questions about this topic.

Is this feature necessary for everyone?

No. VPN settings should match the user’s actual privacy, security, access and performance needs rather than being enabled simply because they exist.

Does using a VPN make me anonymous?

No. A VPN can encrypt network traffic to the VPN server and mask a public IP address, but accounts, cookies, browser fingerprints, malware and endpoint security remain separate.

Does Surfshark support unlimited devices?

Surfshark currently advertises unlimited simultaneous device connections under one subscription.

Are Surfshark features identical on every platform?

No. Surfshark’s own support documentation lists platform-specific availability, so verify the exact feature on the operating system you use.

How current is this guide?

Product facts were checked against current Surfshark documentation and independent material on September 12, 2026. Volatile details should always be rechecked before purchase.

Does no logs mean the provider has no account data?

No. Billing, support, and account records are different from online activity logs.

Why are audits useful?

They provide outside evidence that defined controls matched stated practices during a particular scope and period.

Why are audits not absolute proof?

Systems, policies, and organizations change. An audit is point-in-time evidence rather than a guarantee about all future behavior.

What else should I look for?

Transparency reporting, current privacy policy language, infrastructure design, ownership changes, and the recency of independent assurance all matter.