VPNs with a no-log audit and RAM-only servers

Providers with independent evidence for both: an audit of the no-log promise and servers running without disks.

5 of 85 providers in the dataset

What this filter checks

This filter demands two pieces of evidence at once. First an independent audit of the no-log promise. Second servers that run fully or partly in memory only. A provider that can show only one of the two does not appear.

Unlike the other filters, only the confidence level confirmed counts here. A provider claim is not enough, and the reason lies in the nature of the statement: that nobody keeps logs is not something a company can credibly establish about itself. It is demonstrated only by an audit report, a court document or a reproducible measurement.

What RAM-only does and does not do: a server without a disk loses its state on restart. It does not prevent logging while it runs, with the log written somewhere else. RAM-only is a building block, not a proof. That is why it stands next to the audit here and not in its place. And an audit too has a scope, a period and a date. The scope is in the profile, the date is on the source.

The rule lives in the source code and is only read out here. It is a condition on catalogue criteria, nothing more.

All of the following conditions must hold.

  • Independent no-logs audit has the value yes

    trust.nolog_audit

    Shows whether an outside firm has examined the provider's no-logs claim. Such an audit is a snapshot taken on a given date, usually based on interviews, configuration review and sampling rather than continuous monitoring of live operations. It records that someone external looked, not that nothing is ever stored.

  • RAM-only servers (diskless) has the value entire network or part of the network

    network.ram_only

    RAM-only means a server boots without any hard disk and keeps its entire operating system in memory, so every reboot wipes whatever was on the machine. It does not mean nothing is recorded while the server runs, because data in memory can be read and shipped elsewhere, and it says nothing about what the data centre or upstream provider captures at the uplink.

Which level of evidence counts

For this filter only the level confirmed counts, meaning independent evidence such as an audit report, a court document, a measurement or source code. A provider claim is not enough. Confidence levels in detail

Not a ranking. The page lists providers for whom a statement is sourced. If someone is missing, it may be missing evidence, not the property.

Providers with evidence for this

Sorted alphabetically, as everywhere on this site. There is no order by quality.