Short version: ask directly, and treat evasions as answers

Ask these questions before you sign up to any VPN. A clear, short answer from the vendor’s documentation or legal pages is what you want; vague or shifting responses are a red flag.

What to ask (and why)

  1. Do you keep traffic logs, connection logs, or timestamps?

    Why: “No‑logs” is a common marketing claim, but it covers different things. Ask for the vendor’s privacy policy page and the exact wording that defines what is, and is not, logged. If they point to a generic marketing line instead of the legal policy, that’s a weak sign.

  2. What is your legal jurisdiction and company ownership?

    Why: the country where a company is incorporated determines the powers a government has to compel data. Many vendors publish a country and a legal entity in their support or legal pages; insist on the exact company name and the country of incorporation.

  3. Have you had independent audits or forensic reviews of your no‑logs claim? Which firms, and when?

    Why: recent third‑party audits, plus the auditor’s report or statement, let you check what was actually examined (code, systems, policies). Ask for a link to the audit report hosted on the auditor’s or vendor’s site.

  4. Where do you run your servers (own hardware, colocated, cloud)? Are they RAM‑only / diskless?

    Why: RAM‑only servers cannot retain data after a reboot; that materially reduces the risk of stored logs. If the vendor says “we own the servers” ask for detail — ownership and operational model differ hugely.

  5. Do you publish transparency reports, and do you use a warrant canary?

    Why: transparency reports show how many legal requests a vendor received and how they handled them; a warrant canary is another signal. Some vendors replaced canaries with regular transparency reports — ask which they publish and where.

  6. Which encryption and protocols do you support? How is Perfect Forward Secrecy (PFS) implemented?

    Why: the protocol (WireGuard, OpenVPN, IKEv2, proprietary variants) and PFS matter for practical security. Ask for a support or security page link that lists ciphers and key‑exchange details.

  7. What is your kill‑switch behaviour (per app and per OS)? Any exceptions?

    Why: a kill switch prevents leaks if the VPN drops. Get the exact behavioural description — does it block network access system‑wide, or only the app’s traffic? Is it enabled by default?

  8. How many simultaneous connections are allowed, and how are seat/ device rules enforced?

    Why: some plans are seat‑based while others are flat‑rate. If the vendor enforces by device fingerprint, ask what data is used to identify devices and whether that data is stored.

  9. Which third‑party services do you use (payment processors, crash analytics, customer support CRM)?

    Why: these services often receive personal data. Ask the vendor to list categories of third parties and point to their privacy policy section describing data sharing.

  10. What is your refund policy and how do you handle billing disputes?

    Why: pricing pages can hide non‑pro rata rules and automatic renewals. Ask for the exact refund window and any exceptions (cryptocurrency purchases, gift subscriptions).

What a good answer looks like

  • Direct links to a privacy policy and a transparency report, with dates and clear, constrained language (for example: “we do not log traffic, DNS queries or connection timestamps — Privacy Policy, published 2026‑01‑01”).
  • An auditor name and a link to the auditor’s report that lists scope and findings.
  • An explicit statement of jurisdiction with the registered company name and country, on a legal or support page.
  • Technical pages describing server setup (RAM‑only, diskless or how keys are managed) and exact protocol/cipher choices.

What a bad answer sounds like

Below are actual‑sounding examples. If a vendor answers this way, you should follow up until you get a primary source (policy page, audit report, legal page).

  • “We don’t log anything.” — Without a link to the current privacy policy and a dated audit, this is marketing, not a legal guarantee. Ask for the policy page and the specific language that covers connection and session data. If they refuse or give only marketing copy, that’s a red flag.
  • “We’re based in a privacy‑friendly country” (but won’t name the legal entity). — Jurisdiction is a legal fact. Push for the registered company name and country. A refusal to supply that is avoidance.
  • “Our servers are secure” (no details on RAM‑only vs disk storage). — “Secure” is meaningless unless you get the architecture. If they can’t state whether servers are RAM‑only or whether disk is encrypted and how keys are held, assume the worst.
  • “We don’t have any transparency reports because we haven’t received requests.” — Transparency reports are a best practice; lack of them gives you no visibility. Vendors that publish regular reports are easier to evaluate. If they say they won’t publish them, ask why.
  • “We use analytics to improve the app” — no list of third parties. — Acceptable only if their privacy policy lists the analytics providers and the data shared. If they won’t name them, insist on the policy linkage.

Examples from the market (what vendors publish)

Some major vendors publish the exact pages you should read. For example, ExpressVPN publishes a privacy policy and transparency reports that explicitly state what they say they don’t collect; NordVPN publishes a no‑logs statement and support pages describing stored data. Proton VPN publishes legal and transparency material explaining how Swiss law affects requests. Always read the vendor’s own policy or report rather than a press article. (Examples: ExpressVPN privacy and trust pages; NordVPN no‑logs pages; Proton’s transparency statements.)

Sources: ExpressVPN’s privacy policy and trust pages; NordVPN’s no‑log feature and support pages; Proton’s public transparency discussion. expressvpn.com

Practical checklist you can use in a support chat

  1. “Please send the URL to your current privacy policy (with last‑updated date).”
  2. “Please send the URL to your latest transparency report and any prior independent audit report (with dates).”
  3. “What is your incorporating legal entity and country?”
  4. “Are your VPN servers diskless/RAM‑only? If not, how is disk encryption and key management handled?”
  5. “List the protocols and cipher suites you support and whether PFS is enabled by default.”
  6. “Provide your kill‑switch behaviour page and whether it’s on by default on each OS.”
  7. “List third‑party vendors that receive customer data and the categories they receive.”
  8. “State your refund window and any exceptions.”

When to walk away

Walk away if the vendor repeatedly refuses to put answers in writing, refuses to link to primary documents, or uses only marketing language where you asked for legal or technical detail. If a vendor’s only response to requests for audits and transparency is “we’re working on it” with no date, that’s a practical failure for anyone who needs immediate assurance.

Pricing note

We hold current entry prices and plan types in our catalogue — for instance ExpressVPN, NordVPN, Surfshark VPN and others. Use those pages to compare the list price, but treat any privacy or legal claims as separate: pricing doesn’t prove privacy. (See our catalogue for entry monthly figures.)

Ask for primary documents. If the vendor can’t or won’t show them, consider that an answer.