ExpressVPN's external auditors confirm no-logs policy as of February<p>"ExpressVPN never keeps data that could tie you to any online activity," the <a data-i13n="cpos:1;pos:1" href="
https://www.engadget.com/cybersecurity/vpn/expressvpn-review-2025-fast-speeds-and-a-low-learning-curve-160052884.html">VPN provider[/url] claims on its website. An independent audit from late February supports those claims. Accounting firm KPMG found "reasonable assurance" that the VPN provider's system prevents the logging of user activity. The product is one of <a data-i13n="cpos:2;pos:1" href="
https://www.engadget.com/cybersecurity/vpn/best-vpn-130004396.html">Engadget's top VPN picks[/url].</p>
<h2 id="jump-link-ram-based-vpn-servers">RAM-based VPN servers</h2>
<p>The firm's audit put ExpressVPN's TrustedServer system under a microscope. That's the company's RAM-based system. In theory, this approach means user data is wiped with every server reboot. (Doing so would prevent even the possibility of long-term storage.) Some competitors, including NordVPN, also <a data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:3;pos:1" class="no-affiliate-link" href="
https://nordvpn.com/blog/ram-based-servers/">use[/url] RAM-based servers. Meanwhile, ProtonVPN <a data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:4;pos:1" class="no-affiliate-link" href="
https://protonvpn.com/blog/ram-only-servers">counters[/url] that properly encrypted hard drives are just as secure.</p>
<span id="end-legacy-contents"></span><p>Another counter-argument to RAM-based servers is that they're only effective if they're rebooted. In theory, a company could run RAM servers for marketing purposes, but then never restart them. That's where audits can help.</p>
<h2 id="jump-link-kpmgs-findings">KPMG's findings</h2>
<p>KPMG has a high level of confidence that the no-logging system functioned as advertised in late February. "Controls provide reasonable assurance that the ExpressVPN TrustedServer does not collect logs of users' activity," KPMG's paper reads. That included "no logging of browsing history, traffic destination, data content, DNS queries or specific connection logs."</p>
<p>KPMG's assessment was an ISAE 3000 Type I audit. That means it focused on ExpressVPN's control design and implementation at a specific point in time. (Meanwhile, a Type II audit would have gone farther, testing the effectiveness of those controls over an extended period.) If you aren't familiar, KPMG is one of the Big Four accounting firms. It's a trusted name that corporations shell out big bucks to for audits like this.</p>
<p>The assessment looked at several factors. These included documentation reviews, observing the system at work and interviewing ExpressVPN personnel. The audit's conclusion applies "as of February 28, 2025." So, it represents KPMG's conclusions for a specific point in time rather than a blanket statement of permanent trust. The assessment also didn't include stress-testing the entire system or a full-fledged security analysis of the company.</p>
<p>You can read KPMG's <a data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:5;pos:1" class="no-affiliate-link" href="
https://www.expressvpn.com/security-audit-reports/kpmg-privacy-policy-2025">full paper[/url] for a more detailed breakdown.</p>This article originally appeared on Engadget at 
https://www.engadget.com/cybersecurity/vpn/expressvpns-external-auditors-confirm-no-logs-policy-as-of-february-171957335.html?src=rssSource: 
ExpressVPN's external auditors confirm no-logs policy as of February