NordVPN’s Audit Trail: Inside Six Rounds of Independent No-Logs Verification

0

A deep dive into NordVPN’s audit history with PwC and Deloitte, covering what each engagement examined and what six rounds of verification really tell you.

Few VPN providers have put their no-logs claim through as many independent rounds of scrutiny as NordVPN. Since 2018, the company has commissioned six separate no-logs assurance engagements from two different Big Four firms, making its audit history one of the most extensively documented in the industry. In this review, we walk through what those engagements actually covered, who performed them, and what the pattern tells you about NordVPN’s approach to verification.

A Six-Round Track Record, Not a Single Report

NordVPN’s audit trail began in 2018 with an engagement by PwC, which was repeated again in 2020. From 2022 onward, the company shifted to Deloitte Audit Lithuania, which has since completed four further rounds — in 2022, 2023, 2024, and most recently at the end of 2025, with results published in December of that year. That cadence, roughly once a year, is the detail worth paying attention to. A single audit is a snapshot; six audits across seven years, using two different Big Four firms, is closer to a documented history of consistent behavior.

Round Year Auditor
1st 2018 PwC
2nd 2020 PwC
3rd 2022 Deloitte Audit Lithuania
4th 2023 Deloitte Audit Lithuania
5th 2024 Deloitte Audit Lithuania
6th 2025 Deloitte Audit Lithuania

What the Engagements Actually Cover

Each of Deloitte’s recent engagements has followed the ISAE 3000 (Revised) framework, the internationally recognized standard for assurance work outside of financial statement audits. In practice, this means Deloitte’s practitioners are given a defined window of access to NordVPN’s live services, during which they interview employees and inspect server infrastructure, configuration settings, and deployment processes.

The 2024 round, for example, ran from mid-November to mid-December, covering standard VPN servers alongside specialized configurations such as Double VPN, Onion Over VPN, obfuscated servers, and P2P-optimized servers. The 2025 round followed a similar month-long fieldwork window at the end of the year, again examining the full range of server types rather than a single narrow slice of the infrastructure.

Why the Scope Matters

It would be easy for a provider to have a single, simple standard VPN server configuration audited while leaving specialized services unexamined. NordVPN’s audits have consistently included Double VPN, obfuscated servers, and P2P infrastructure alongside the standard offering, which matters because these are the configurations most likely to be used by higher-risk users who most need the no-logs claim to hold.

Point-in-Time, Not Permanent

It’s worth being precise about what these reports do and don’t promise. An ISAE 3000 engagement is a point-in-time assessment: it describes what the auditor observed during a specific access window, not a permanent guarantee that nothing will ever change afterward. This is exactly why the annual cadence matters more than any single report. A provider that repeats the process year after year is implicitly acknowledging that infrastructure evolves and that a years-old report shouldn’t be treated as current evidence.

Six engagements in seven years is a pattern of behavior, not a single marketing moment — and that consistency is the part worth weighing more heavily than any individual report.

Access and Transparency

NordVPN makes the full assurance reports available to users, though access requires logging into a Nord Account rather than being posted as an open PDF. That’s a middle ground worth noting: the summaries and press communications around each engagement are public, but the full technical report sits behind an account login. For readers comparing providers, this is a reasonable but not maximal level of transparency — some competitors publish full reports without requiring an account at all.

How This Fits Into NordVPN’s Broader Security Posture

The no-logs assurance engagements sit alongside other elements of NordVPN’s infrastructure that are relevant to a security review: RAM-only servers, which are wiped on every reboot rather than relying on disk storage that could theoretically retain data, and a network architecture spanning thousands of servers across dozens of countries. The company is registered in Panama, a jurisdiction outside the surveillance-sharing alliances often cited in VPN privacy discussions, while its parent company Nord Security is headquartered in Amsterdam with additional offices in Lithuania, the UK, and Panama.

What This Means for You as a User

  • Consistency over time is the strongest signal here — six audits across two firms and seven years, not one report from the past.
  • Scope has been broad, covering specialized server types rather than only the default configuration.
  • Full reports require an account login, which is more transparent than nothing but short of a fully public PDF.
  • Each engagement is a snapshot, so the recurring cadence matters more than treating any single year’s report as a permanent guarantee.

Our Take

NordVPN’s audit history is one of the more extensive in the consumer VPN market in terms of sheer repetition and duration. The involvement of two separate Big Four firms across six engagements, spanning both standard and specialized server configurations, gives this history more weight than a single report ever could. Readers should still treat each engagement as what it is — a snapshot of a defined access window — and continue watching for whether NordVPN keeps the cadence going in the years ahead. So far, the pattern has held.

As with any audit-based claim, we’d encourage readers to look at the underlying engagement details rather than the marketing summary alone, and to weigh no-logs assurance work like this alongside any separate penetration testing or source code review a provider has undergone for its apps and protocols.

How the Access Windows Have Evolved

One detail that stands out across NordVPN’s more recent Deloitte engagements is the length and placement of the access window. The 2023 round gave Deloitte’s practitioners roughly a week of access before the report was finalized in mid-December. The 2024 engagement extended that window considerably, running for about a month from mid-November through mid-December. The 2025 round followed a similarly extended fieldwork period at the close of the year, with the final assurance report issued in mid-December 2025. A longer access window doesn’t automatically mean a more thorough audit, but it does give practitioners more opportunity to observe configurations and deployment processes across a wider slice of the infrastructure, rather than a narrow snapshot.

What NordVPN’s Program Doesn’t Cover

It’s worth being clear-eyed about what these particular engagements are and aren’t. The Deloitte and PwC assurance reports are focused specifically on the no-logs claim and the infrastructure supporting it — server configuration, deployment processes, and technical logs. They are not, by themselves, penetration tests of NordVPN’s mobile or desktop applications, nor source code reviews of its proprietary protocol implementations. Readers evaluating NordVPN’s overall security posture should look for whether the company has separately commissioned that kind of technical, app-level testing, since a no-logs assurance report and an application security audit answer genuinely different questions.

Frequently Asked Questions

Is the NordVPN no-logs audit the same as a penetration test?

No. The Deloitte and PwC engagements are assurance engagements under the ISAE 3000 framework, focused on verifying that NordVPN’s infrastructure and controls align with its stated no-logs policy. A penetration test is a distinct exercise focused on finding exploitable software vulnerabilities, and is typically conducted by specialist offensive-security firms rather than assurance-focused accounting firms.

Can I read the full Deloitte report without being a NordVPN customer?

Based on NordVPN’s own communications, the full assurance reports are accessible after logging into a Nord Account, which generally requires being a registered user of the service. Summaries and press releases describing the findings are publicly available without an account.

Why did NordVPN switch from PwC to Deloitte?

NordVPN’s public communications don’t detail an explicit reason for the shift, which took place between the 2020 and 2022 engagements. Rotating between reputable assurance firms over time is not unusual in this space and can itself be viewed as a reasonable practice, similar to periodic auditor rotation in other industries.

Does a clean no-logs audit mean NordVPN is completely secure?

It means the specific claim under review — that the infrastructure does not collect identifying activity logs — held up under the auditor’s testing during the engagement window. It doesn’t address unrelated security questions such as application-level vulnerabilities, which would need to be evaluated through separate technical audits.

Where This Leaves NordVPN in a Crowded Field

Few consumer VPN providers can point to six completed no-logs assurance engagements spanning two Big Four firms and seven years. That depth of history is a genuine differentiator when comparing providers on trust and transparency grounds specifically. It shouldn’t be the only factor in a purchase decision, but among the available signals for evaluating a no-logs claim, a long and consistent audit trail like this one is about as strong as the market currently offers.

What to Watch For Going Forward

The pattern established over the past seven years suggests NordVPN will likely continue commissioning a fresh no-logs assurance engagement roughly once a year, and readers tracking the provider’s trustworthiness over time should watch for whether that cadence holds. A skipped year, a narrowing of scope back to only standard servers, or a shift away from naming a recognized Big Four firm would all be meaningful changes worth noting in any future review. Conversely, continued annual engagements covering the full range of specialized server types would reinforce the trend already visible across the first six rounds.

It’s also worth watching whether NordVPN expands its public disclosures to include more technical, app-level security audits alongside its no-logs assurance work, since that would round out the picture in the same way ExpressVPN’s parallel KPMG and Cure53 tracks do. A no-logs assurance history this long is a genuine asset, but pairing it with equally consistent penetration testing of the apps millions of people actually install on their phones and laptops would make the overall trust story even more complete.

Leave a Reply

Your email address will not be published. Required fields are marked *