Whether you’re logging into online banking on airport Wi-Fi or managing sensitive work files abroad, a zero-logs VPN matters because it commits to never storing, logging or recording the browsing history, connection timestamps or IP addresses of its users – and NordVPN backs up its zero-logs policy promise with verifiable evidence.
Six independent ISAE 3000 audits have inspected NordVPN’s server configurations, technical logs and deployment systems across standard and specialty servers to prove that no user activity or connection metadata is ever stored. In our reader survey, conducted in July with 1,000 respondents, 67% of people associated NordVPN with being "reliable, trustworthy and good quality", a reputation that’s backed by NordVPN’s audited zero-logs infrastructure.
Summary
- No-log VPNs are important, because if data is recorded it can be shared, stolen or sold; NordVPN does not store any user activity or connection metadata
- A zero-log VPN should not record any of your online activity, and NordVPN's diskless, RAM-based servers don't allow hardware logging
- Six independent audits by "Big Four" auditors have verified NordVPN's no-logging policy
- Audits follow internationally agreed standards: the International Standard on Assurance Engagements 3000 (Revised) (ISAE 3000 (Revised)).
- Audits took a deep dive into NordVPN's systems, policies and procedures, and carried out detailed technical analysis and testing.
Why zero-logging matters when you use a VPN
A VPN’s zero-log policy matters because it prevents your private data from ending up in a database and ensures your browsing history and IP addresses can’t ever be stolen, sold or even legally requested. If details of your online activity are able to be recorded and stored, that data can be leaked, sold or requested by officials. But under NordVPN’s zero-logs standard, if it isn't stored in the first place, it can't be exposed.
There are good reasons why you need a strict zero-logs VPN like NordVPN to shield your online activity: for example, if you're a software developer you're not going to want your database queries or API access tokens recorded and potentially leaked; if you live under a repressive regime, you won't want a record of the political sites you might visit.
If a VPN provider doesn't have a clear zero-logging policy, preferably audited by reputable third parties, you should assume that online activities are being logged and that data may be sold, shared or handed over on request, or that identifying or sensitive data could be leaked in a security breach or targeted attack.
What does zero-logs actually mean?
A zero-log VPN won’t just claim to be zero-log; it’ll be able to prove it. It’ll be able to demonstrate, with reports from reputable third party auditors, that it does not record or store any of your online activities. It will be able to demonstrate that it is a blind data pass-through, fully designed so that no activity, timestamps, bandwidth usage or IP addresses are ever written to physical storage. The audit reports will demonstrate that the VPN provider is unable to see the files you download, the websites you visit, the data you enter into forms, your real IP address, or anything else.
If a VPN provider can’t provide independent audit reports, then claims of a no-log policy are just that: claims.
How independent auditors confirmed the effectiveness of NordVPN's zero-logs policy
Independent auditors confirmed NordVPN’s zero-logs claims with hands-on technical inspections of live server configurations, code, and diskless RAM-only infrastructure to approve that no logging happens. In 2025, NordVPN successfully passed its sixth independent audit of its no-log policy and practice. The audit was carried out by Deloitte Lithuania, one of the "Big Four" audit firms, in accordance with the International Standard on Assurance Engagements 3000 (Revised).
Previous NordVPN audits were carried out by the same firm in 2022, 2023 and 2024; prior to that the auditors were PriceWaterhouseCoopers, another Big Four auditor, in 2018 and 2020. Every single evaluation confirmed that NordVPN has been true to its zero logs policy, with no recorded or stored user activity, IP addresses, or traffic.
The purpose of the ISAE 3000 (Revised) standards is to ensure that an organisation's practice matches its policy. To assess that, auditors interview appropriate members of staff, review relevant policies and procedures, and carry out a range of technical tests to identify whether the policy is fully and effectively delivered or enforced and that there are sufficient safeguards in place.
What is the methodology of an ISAE 3000 assurance report?
The ISAE 3000 framework is an internationally recognized methodology to verify policy compliance with a combination of staff interviews, system architecture inspections and point-in-time testing of live networks. NordVPN’s 2025 audit consisted of the following:
- Server hardware and software audits: One of the most important parts of an audit is ensuring that the servers do what the VPN provider says they do, so if a VPN has a no-log policy that should be reflected in the configuration of the servers. Deloitte’s auditors reviewed standard VPN, double VPN, obfuscated servers and Onion over VPN servers to confirm that all user activity and metadata is systematically excluded from physical storage on NordVPN’s diskless, RAM-only servers.
- RAM-only server inspection: A service provider cannot hand over data that it doesn’t have in the first place, and that’s why RAM-only architecture is important. RAM-based servers don’t pass any data to long-term storage such as hard disks or solid state drives; they work entirely in volatile RAM, which is strictly temporary and will be flushed when a task is finished or the server power is cycled. Auditors will examine the server configuration, provisioning records and documentation to confirm that non-volatile storage is not used to record any customer traffic data.
- Employee interviews: There are two key reasons why auditors interview employees. The first is that the auditors need to confirm that staff across the organisation consistently apply privacy protocols in their work. And the second is that it isn’t physically possible to audit every server belonging to a large provider such as NordVPN, which has thousands of servers around the world. So in addition to inspecting multiple servers the auditors also inspect documentation and interview employees to ensure that the no-logs policy is understood and implemented effectively and consistently throughout the organisation.
- Publication of methodology and results: Deloitte found that NordVPN practiced what it promises: a full no-logging policy. Because the report is highly technical, NordVPN doesn't publish the full report for casual browsers, but you can download the full ISAE 3000 assurance report from your Nord Account dashboard. The report shows the precise, audited deployment processes of standard, Double VPN and obfuscated servers that confirmed all user activity and metadata is systematically excluded from physical storage.
With diskless servers, an audited no-logs policy and Panamanian jurisdiction, NordVPN delivers on its promise to keep your data and your browsing private. Click here to discover the best NordVPN plan for you.
Frequently asked questions
How does NordVPN's NordLynx protocol work?
NordLynx enhances the very fast WireGuard protocol with a dynamic double Network Address Translation implementation, double-NAT for short. The first layer of double-NAT assigns the same local IP address to every user of a server, which masks the individual users' identities. The second layer uses the dynamic NAT system to give each VPN tunnel session a unique IP address so that all your data packets go where they're supposed to without getting mixed up. User authentication is handled through a secure external database, so no identifiable data is ever stored on the VPN server.
Can I install NordVPN on my router?
Yes, many routers are NordVPN compatible. There are full instructions and a list of compatible routers on the NordVPN website. NordVPN also provides advice on how to use the service with any router that supports the OpenVPN protocol. The most common kind of router that can't run NordVPN is an ISP-supplied one, which you'd need to replace with a compatible one.
Is NordVPN recommended for professionals who work remotely?
Yes. NordVPN uses state of the art encryption to secure access to classified business files and data, keeping them safe from interception and protecting both your data and your privacy. With features including strong AES-256 encryption, Auto-connect and Kill Switch security and Meshnet private networking NordVPN delivers data and privacy protection that you can rely on, backed with a strict and independently verified no-logs privacy policy.
Where can I read NordVPN’s independent audit report?
You can read NordVPN’s independent audit report when you log in to your Nord account.
Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.