"Zero logs" is the most overused phrase in the VPN industry. Every provider claims it. Almost none of them fully deliver on it. Understanding what "no logs" actually means — and how to verify it — is the difference between real privacy and a false sense of security.
What Logs Can a VPN Keep?
VPN providers can log many different types of data. Most "no-log" claims only refer to one category — connection content — while quietly retaining others. Here's what they could be storing:
- Connection logs — when you connected, how long, from which IP
- Traffic logs — which sites you visited, what data you transferred
- DNS logs — domain lookups that reveal your browsing
- Bandwidth logs — how much data you used (often kept for billing)
- Device logs — which devices connected to your account
Providers That Got Caught
Several VPN providers that advertised "no logs" policies have been proven wrong when law enforcement came knocking:
PureVPN handed detailed connection logs to the FBI in 2017 despite claiming a no-logs policy. IPVanish provided logs to Homeland Security that directly led to a criminal conviction. HideMyAss gave logs to police that helped identify a hacker — again, while marketing themselves as a privacy-first service.
In each case, the logs existed. The privacy policy was marketing copy, not technical reality.
What a Real Zero-Log Policy Looks Like
A genuine no-log VPN doesn't store connection timestamps, originating IPs, traffic content, DNS queries, or bandwidth usage tied to individual accounts. The architecture itself makes logging impossible — or at least makes any stored data meaningless without a decryption key that only you hold.
The gold standard is a provider that has been independently audited by a third-party security firm, with the full audit report published publicly. Court cases where a provider genuinely couldn't hand over data also serve as real-world proof.
How to verify a VPN's no-log claim
- Look for published third-party audit reports from reputable security firms
- Check if they've been subpoenaed and what they were able to hand over
- Read the privacy policy carefully — look for phrases like 'aggregate data' or 'diagnostic data'
- Avoid providers headquartered in Five Eyes countries without additional verification
A VPN that actually keeps no logs
SoloFlight's strict no-logs policy means your activity is never stored, tracked, or sold. Cancel anytime, no questions.