ExpressVPN’s Transparency Playbook: What Its KPMG and Cure53 Audits Reveal
How ExpressVPN’s dual-track audit program, spanning KPMG’s no-logs assurance work and Cure53’s technical penetration testing, holds up under scrutiny.
ExpressVPN has built one of the most audit-heavy transparency programs in the VPN industry, publishing dozens of independent assessments over the years across two distinct tracks: assurance engagements from KPMG covering its no-logs claim, and technical penetration tests and source code reviews from Cure53 covering its apps, browser extensions, and proprietary Lightway protocol. This review breaks down what each track actually examined and what the combined record tells you.
Two Tracks, Not One
Unlike a provider that publishes a single type of report, ExpressVPN’s transparency program deliberately runs two parallel tracks that answer different questions:
- KPMG’s no-logs assurance engagements, which test whether the company’s TrustedServer architecture and internal controls actually prevent the collection of activity and connection logs, as its privacy policy claims.
- Cure53’s penetration tests and source code audits, which examine specific apps — iOS, Android, desktop clients, browser extensions — and the Lightway protocol itself for exploitable vulnerabilities.
The distinction matters because a no-logs assurance report tells you about server-side infrastructure and policy compliance, while a penetration test tells you whether the software running on your own device has security flaws. A provider needs both kinds of scrutiny to make a complete case, and ExpressVPN is one of the few that has consistently commissioned both over multiple years.
The KPMG No-Logs Track
ExpressVPN’s relationship with KPMG began with an engagement examining its TrustedServer technology and privacy policy compliance, and has been repeated in subsequent years, including engagements dated September 2022, December 2023, and February 2025. Each of these has been conducted under the ISAE 3000 (UK) Type 1 framework, testing the design and implementation of controls rather than observing behavior continuously over a long period.
Across these rounds, KPMG’s published conclusions have consistently found that ExpressVPN’s TrustedServer architecture does not retain browsing history, traffic destinations, DNS queries, or connection logs tied to individual users. It’s worth being precise about the label here: a Type 1 engagement assesses whether controls are suitably designed and were implemented as described at a specific date, which is a narrower claim than a Type 2 engagement that would observe operation over an extended period.
Knowing the difference between a Type 1 snapshot and a Type 2 engagement over time isn’t pedantic — it changes exactly what the report is entitled to claim.
The Cure53 Technical Track
Alongside the KPMG engagements, ExpressVPN has commissioned a long series of Cure53 assessments covering individual products: its Android and iOS apps, its Chrome and Firefox browser extensions (audited a second time in mid-2024), its Keys password manager, and its Lightway protocol, which has now been through more than one independent review of its own.
These technical audits produce a different kind of output than the KPMG reports: a ranked list of findings by severity, along with the company’s response to each one. In the most recent browser extension audit, for example, Cure53 flagged a very small number of issues, describing one as medium severity, and reported that the extension’s overall security posture reflected well-implemented protections against the majority of serious threats. ExpressVPN has stated that it addressed the findings raised across its various app and protocol audits, sometimes declining specific cosmetic changes where fixing them would have degraded usability, decisions the auditors reportedly agreed with.
Why Repetition on the Technical Side Matters Even More
Source code changes constantly as features ship. A penetration test from two years ago says very little about a browser extension that has been rewritten since. ExpressVPN’s pattern of returning to Cure53 for repeat assessments of the same products — rather than a single audit early on and nothing since — is arguably the more important signal on this side of its program.
A Published Count That Keeps Growing
ExpressVPN has publicly referenced its running total of published third-party audit reports, citing counts in the high teens as of recent disclosures, spanning KPMG, PwC, Cure53, and other firms across its history. The company’s own account of its timeline includes a Cure53 review of its browser extension as early as November 2018, a PwC Switzerland review of its privacy policy and TrustedServer technology in mid-2019, and a steady cadence of further engagements in nearly every year since.
Snapshot of ExpressVPN’s audit program:
- No-logs assurance work handled by KPMG, following the ISAE 3000 (UK) Type 1 framework.
- Technical penetration testing and source code review handled primarily by Cure53.
- Coverage spans desktop apps, mobile apps, browser extensions, the Keys password manager, and the Lightway protocol.
- Full reports are generally published rather than kept behind an account login, once the relevant terms are acknowledged.
Where to Stay Cautious
A large volume of audits is a genuinely good signal, but volume alone shouldn’t be mistaken for perfection. Each Cure53 report still lists real findings, including at least one medium-severity issue in a recent review, and each KPMG engagement is explicitly scoped as a point-in-time Type 1 assessment rather than continuous monitoring. Readers should treat this history as strong evidence of an ongoing, serious commitment to third-party scrutiny — not as proof that the software is free of every possible flaw at every moment.
Our Take
What stands out about ExpressVPN’s program isn’t any single audit but the structure of the whole effort: two distinct firms testing two distinct claims, repeated across nearly every product line the company ships, with a growing public archive of the results. Few consumer VPN providers have matched both the breadth and the frequency of this approach. As with any audit history, the details matter more than the headline count — and readers comparing ExpressVPN against other providers should look at what was tested, when, and how the findings were resolved, rather than treating “audited” as a single undifferentiated stamp of approval.
The Lightway Protocol: A Second Look Under the Hood
ExpressVPN’s proprietary Lightway protocol has itself been through more than one independent review, a detail that matters because a custom protocol carries different risks than adopting an already widely-scrutinized open standard. Repeating the review of Lightway rather than relying on a single early audit reflects the same pattern seen elsewhere in ExpressVPN’s program: treating protocol security as an ongoing commitment tied to the protocol’s continued development, not a box checked once at launch and never revisited.
How the Transparency Report Fits Alongside the Audits
Separately from its security and no-logs audits, ExpressVPN has also published transparency reports detailing the volume and nature of legal data requests it receives from authorities. While a transparency report isn’t itself an independent audit, reading it alongside the KPMG no-logs findings gives a fuller picture: KPMG’s engagement addresses whether the infrastructure is technically capable of producing user data, while the transparency report addresses what has actually happened when authorities have asked for it. Together, they answer a more complete question than either document does alone.
Frequently Asked Questions
What’s the difference between KPMG’s and Cure53’s role at ExpressVPN?
KPMG examines whether ExpressVPN’s TrustedServer architecture and internal controls prevent the collection of activity logs, following the ISAE 3000 (UK) Type 1 framework. Cure53 performs penetration testing and source code review of individual products, such as specific apps, browser extensions, and the Lightway protocol, looking for exploitable vulnerabilities rather than policy compliance.
Does ExpressVPN publish every audit, even ones with negative findings?
Based on the company’s own public disclosures, it has published reports that include specific findings, including at least one medium-severity issue identified in a recent browser extension review, along with its response to each finding. That willingness to publish reports containing real findings, rather than only ones with a clean result, is itself a meaningful transparency signal.
Is a Type 1 assurance engagement as strong as a Type 2?
They test different things. A Type 1 engagement assesses whether controls are suitably designed and were implemented as of a specific date. A Type 2 engagement goes further, testing whether those controls operated effectively over an extended period. Neither is inherently invalid, but they support different strength of claims, and it’s worth checking which type any specific report uses before treating its conclusion as continuous assurance.
How often does ExpressVPN repeat these audits?
Based on the company’s published history, KPMG engagements have recurred roughly every one to two years, while Cure53 assessments of specific apps and the browser extension have also been repeated, including a second review of the browser extension roughly two years after the first. The overall cadence has generally trended toward more frequent audits over time rather than fewer.
Bottom Line
ExpressVPN’s dual-track audit program, spanning both assurance-style and offensive-security testing, repeated consistently across its major product lines, represents one of the more thorough transparency efforts in the consumer VPN space. Readers should still evaluate each report on its own scope and findings rather than treating the cumulative count as a substitute for reading the details — but the underlying structure of the program itself is a strong example of what a serious, ongoing commitment to third-party verification can look like.
What Would Make the Program Even Stronger
Even a program this extensive has room to grow. Extending Type 2 assurance engagements, which test controls over a sustained period rather than a single point in time, alongside the existing Type 1 work would strengthen the no-logs side of the claim further. Continuing to shorten the gap between successive Cure53 reviews of the same product, particularly for apps that ship frequent updates, would keep the technical side just as current as the underlying code. Neither gap undermines the value of what has already been published, but both are reasonable areas to watch as the program continues to evolve in future years.
