Back to Blog
Privacy 6 min readApril 20, 2026

Zero Logs: What It Actually Means and How to Verify It

"Zero logs" is the most overused phrase in the VPN industry. Every provider claims it. Almost none of them fully deliver on it. Understanding what "no logs" actually means — and how to verify it — is the difference between real privacy and a false sense of security.

What Logs Can a VPN Keep?

VPN providers can log many different types of data. Most "no-log" claims only refer to one category — connection content — while quietly retaining others. Here's what they could be storing:

  • Connection logs — when you connected, how long, from which IP
  • Traffic logs — which sites you visited, what data you transferred
  • DNS logs — domain lookups that reveal your browsing
  • Bandwidth logs — how much data you used (often kept for billing)
  • Device logs — which devices connected to your account

Providers That Got Caught

Several VPN providers that advertised "no logs" policies have been proven wrong when law enforcement came knocking:

PureVPN handed detailed connection logs to the FBI in 2017 despite claiming a no-logs policy. IPVanish provided logs to Homeland Security that directly led to a criminal conviction. HideMyAss gave logs to police that helped identify a hacker — again, while marketing themselves as a privacy-first service.

In each case, the logs existed. The privacy policy was marketing copy, not technical reality.

What a Real Zero-Log Policy Looks Like

A genuine no-log VPN doesn't store connection timestamps, originating IPs, traffic content, DNS queries, or bandwidth usage tied to individual accounts. The architecture itself makes logging impossible — or at least makes any stored data meaningless without a decryption key that only you hold.

The gold standard is a provider that has been independently audited by a third-party security firm, with the full audit report published publicly. Court cases where a provider genuinely couldn't hand over data also serve as real-world proof.

How to verify a VPN's no-log claim

  • Look for published third-party audit reports from reputable security firms
  • Check if they've been subpoenaed and what they were able to hand over
  • Read the privacy policy carefully — look for phrases like 'aggregate data' or 'diagnostic data'
  • Avoid providers headquartered in Five Eyes countries without additional verification

A VPN that actually keeps no logs

SoloFlight's strict no-logs policy means your activity is never stored, tracked, or sold. Cancel anytime, no questions.