Every VPN says the same four things about itself: that it keeps no logs, that the encryption is strong, that nothing is stored on its servers, and that it has been independently audited.
Those four sentences sit on the front page of services that have earned them and services that have not. Read on their own, none of them is evidence.
Which leaves most people stuck in the same place in the App Store. There are hundreds of these apps, roughly half are free, and the front pages are close to identical. The useful question is not which one is best. It is which of those four claims can be checked, and where the checking happens.
One of the four is quick. With afree VPN you can settle two questions in about a minute: whether it wants an account before it will run, and whether it caps how much data you move. The other three cannot be settled by reading a website, which is the reason this page exists.
What a VPN Can Claim, and What It Can Evidence
The difference between these four claims is not truth. It is where the evidence lives.
| The Claim on the Page | What Would Count as Evidence | Where That Evidence Sits |
| It keeps no logs | An assurance report naming the standard it was carried out under, what it covered, and when | The provider’s audit page, not the front page |
| The encryption is strong | A named algorithm and key exchange, rather than an adjective | The technical specification, or the app’s own connection details |
| Nothing is written to disk | A statement that the servers run in memory only | Technical documentation |
| It is free to use | Whether it asks you to register, and whether it caps the data you move | The download and setup flow, which takes a minute |
The bottom row is the one you can settle today. The top three are not. Row two is the easiest to judge at a glance, because encryption has names. AES-256-GCM is a name — a specific cipher you can go and read about. A page that hands you the name has given you something to look up. A page that reaches for a comforting phrase has given you a feeling.
Work down the table in reverse. Start with the bottom row, because it costs you a minute. Then take the top row, which matters most and is the hardest to confirm. Rows two and three tend to be published in the same place as row one, so they come along with it. The next two sections are about row one.
What “No Logs” Means Before Anyone Checks It
“No logs” is a sentence a company has written about itself, describing something that happens on hardware you cannot see.
Your device knows where its own traffic went. It has no way of knowing what the company receiving that traffic wrote down. A no-logs policy is a statement about that company’s internal practice, not a setting on your phone. That is what separates it from the other three claims — the others can be matched against technical documentation, and this one cannot.
The reason it outweighs the rest is what a VPN does. Using one does not make the record of which sites you connected to disappear. It moves that record, from the network you are sitting on to the company running the VPN. That is the trade you are making. The logging question is the question of who you have handed the record to.
So the claim can only be answered by someone outside the company. The industry’s answer is to bring in an external firm, have it examine the practice, and publish the result. That creates a second problem, because “independently audited” is also a line printed on a website. Reading it properly takes three details.
How to Read an Audit Without Reading the Report
An audit is worth something when three details come with it: the standard it was carried out under, what it covered, and when it happened. With those three, you have evidence. With the word on its own, you have a badge.
Start with the standard. An audit is not one defined action — it is an examination carried out against a published set of professional rules, and those rules decide how demanding the work has to be. A provider that names its standard has handed you something you can go and read for yourself. A provider that says only “audited” has told you that somebody looked.
The second detail is scope. An engagement can examine a written policy on its own, or the policy together with the systems and day-to-day practice meant to deliver it. Those are different pieces of work, and the difference appears in the summary of the report rather than in the headline. A company that publishes its scope is showing you the shape of the check it paid for.
The third detail is the date. An assurance engagement describes a point in time. An audit from three years ago tells you the company agreed to be examined then. It does not describe the service you would download this afternoon.
One example you can hold against those three: X-VPN’s no-logs policy was assessed under ISAE 3000 (Revised) — an international assurance standard for this kind of engagement — with the result published in 2026. Standard, scope and date are stated, which is the shape the answer should take. The report itself sits behind an account login, which is common across the industry and worth knowing before you go looking for it.
What a Free Tier Is Asking You For
On a free tier there are two things you can establish yourself, and both take about a minute: whether it wants you to register, and whether it limits how much data you move.
Both are worth settling because both are structural. A company holding no account details has no account details to keep. A service setting no limit on your data is not relying on that limit to move you onto a paid plan. Neither fact asks you to trust anybody — they are visible in the download and setup flow, before you have committed to anything.
X-VPN’s free tier answers both. It asks for no account before it will run, and it sets no cap on the data you move. Leak protection for DNS, IP and WebRTC is included in the free version as well as the paid one, which is worth knowing because that line is where free tiers are commonly cut.
If the phone in your pocket is an iPhone, the free VPN for iOS build is the one to start from — it comes from the App Store and needs no registration to run. On iPhone and Android the free version also lets you pick a location by hand, and Sydney and Melbourne are both on that list; the free desktop version connects on its own instead. Set it up at home on your own network rather than in a café, so the setup happens somewhere you already recognise.
Price is not the test. The four claims are the test, and they apply to the free tier and the paid tier of the same company in the same way. How a provider behaves towards the people paying it nothing is itself a piece of information.
What Australian Readers Can Cross-Check
Two Australian sources discuss this subject with nothing to sell, which makes them useful as a second opinion.
CHOICE, the consumer organisation, publishes a buying guide on what to look for in a VPN provider. Its value is not the conclusion it reaches. It is that CHOICE earns nothing when you sign up — unlike most of the “best VPN” rankings filling the search results, which carry a commission on every click through to a provider.
eSafety’s Be Connected material covers similar ground in plainer language, written for readers who are not steeped in this. Put the two beside each other and one thing stands out: neither of them reaches for the adjectives the product pages lean on.
One thing none of this settles. A VPN moves the record of which sites you connected to from the network you are on to the company running the VPN. An audit is how that company shows what it does with that record — which is why the three details in the previous section carry more weight than anything printed on a front page, and why ten minutes of checking is time well spent before you hand the record over.
Questions People Ask
How Do I Know If a VPN Is Legit?
Check whether it names the standard, the scope and the date of its audit. With those three, the company has agreed to be examined on the record. The word “audited” on its own is a statement, not a result.
Does a No-Logs Policy Mean Nobody Can See What I Do?
No. It describes what one company keeps, not what everyone else can see. The network you are connected to still knows a device came online and how much data it moved.
Is a Paid VPN More Trustworthy Than a Free One?
Price is not the measure. Within one company, the free and paid tiers run the same logging policy and the same encryption.
How Often Does an Audit Need Repeating?
An assurance engagement describes a point in time, so the date carries more weight than the badge. A provider examined once and not since is describing its history.
What Should I Check Before I Set One Up?
Run the four claims past the provider. Settle the free-tier questions in a minute, then look for the standard, the scope and the date sitting behind the audit line.
The Short Version
Of the four things a VPN says about itself, one can be settled in a minute and three cannot. The one that matters most — what the company records — is answered by an outside examination, and that examination is only worth reading when it states its standard, its scope and its date. A VPN moves the record of where you have been from one party to another. Choosing one is choosing who you would rather hold it.

