Last updated: 15 September 2026
Quick Answer
NordVPN is one of the few VPNs whose privacy claims have been checked by outsiders rather than asserted in marketing. Six independent no-logs audits since 2018, the most recent carried out by Deloitte Lithuania, looked at live systems instead of policy documents. There is one real blemish, a breached server in 2018 that took eighteen months to disclose, and there are limits no VPN gets past. Both are below.
Nobody searches this question idly. Either you are about to hand a company your card details and your entire internet connection, or you have read something that worried you. Either way the useful answer is not reassurance. It is evidence, plus an honest account of what the evidence does not cover.
What "no logs" is worth, and how to tell
Every VPN on the market says it keeps no logs. The claim costs nothing to make and, from the outside, nothing to verify. A provider could record every site you visit and publish exactly the same sentence on its home page.
What separates one promise from another is whether anyone independent has gone in and looked. NordVPN has been through six no-logs assurance engagements since 2018, in 2018, 2020, 2022, 2023, 2024 and 2025. The latest ran under ISAE 3000 (Revised), the standard used for assurance work that is not a financial audit, with Deloitte Lithuania inspecting the infrastructure between 10 November and 12 December 2025. The scope covered the standard servers along with the Double VPN, Onion Over VPN and obfuscated ones.
The part that matters is the method. The auditors read configuration files and live system logs, interviewed the engineers who run the machines, and checked whether the setup could retain what the company says it does not retain. Reading a privacy policy and confirming it says the right words is a much easier job, and a much less informative one.
An audit covers a period, and says nothing about the weeks before or after it. What repeating the exercise six times in seven years buys you is a track record, which is as close as this category gets to proof. No competitor has submitted to it as often.
The 2018 breach, in full
In March 2018 an attacker reached one NordVPN server in a rented data centre in Finland. The route in was not NordVPN's software. The hosting company had left an insecure remote management system in place without telling its customers, and the attacker used it.
What was exposed was the TLS key for that single server, which could in principle have allowed a convincing fake NordVPN website or an intercepted connection on that one machine. No usernames, no passwords, no browsing activity. The key expired on its own schedule shortly afterwards.
The failure worth criticising is the timeline. NordVPN learned of the intrusion in 2019 and made it public in October of that year, roughly eighteen months after it happened. The company's explanation was that it wanted to audit its whole estate before saying anything. That is a defensible engineering instinct and a poor disclosure decision, and it is reasonable to hold it against them.
The response was substantive rather than cosmetic. NordVPN moved its fleet to RAM-only servers, which hold nothing once they lose power, ended arrangements with providers that could not meet its requirements, and started the audit cycle described above. Seven years on, that remains the only publicly known compromise, and it happened at a supplier rather than in the product.
Panama, and why the address matters
NordVPN is registered in Panama, which has no law requiring communications providers to retain user activity and no membership of the intelligence-sharing arrangements that oblige companies elsewhere to hand data over quietly.
For a British reader this is the sharper half of the question. The Investigatory Powers Act allows UK authorities to compel a telecommunications operator to retain data and produce it, under a notice the operator is forbidden to mention. That reach applies to providers with a UK presence. A Panamanian company with servers that keep nothing on disk sits outside it.
The limit is worth stating plainly. Jurisdiction is a legal argument rather than a technical safeguard, and legal arguments get tested in ways nobody predicted. It reduces your exposure. Any provider telling you it eliminates exposure is overselling.
The full assessment
Pricing, speed, streaming, the plans where the threat-blocking tool is absent, and where NordVPN is genuinely weaker than its rivals.
Read the NordVPN Review →Is NordVPN legit, or is something off?
The company is real, has been trading since 2012, and belongs to Nord Security, which also makes NordPass and NordLocker. It employs several hundred people and its products are reviewed by every major technology publication. Nothing about it fits the shape of a scam.
The complaints that do surface cluster almost entirely around billing. Subscriptions renew automatically at the standard rate when the discounted term ends, and people who signed up two years earlier are startled by the charge. The thirty-day refund also has to be requested, because cancelling on its own does not produce one.
Neither of those is unique to NordVPN, and neither is dishonest, but both are avoidable. Put a reminder in your calendar a week before the term ends and the entire category of complaint stops applying to you.
What NordVPN cannot protect you from
This is the section most review sites skip, and it is the one that decides whether you end up disappointed.
A VPN hides your traffic from the network you are sitting on and from your internet provider. It does nothing about the accounts you are logged into. Google still knows what you searched while signed in to Google, and Facebook still knows what you looked at while signed in to Facebook. Changing your apparent country does not change who you already told.
It is also not an antivirus. NordVPN's Threat Protection Pro blocks malicious and phishing domains, and the Austrian lab AV-Comparatives certified it at 92% against live phishing addresses in January 2026, which is the only certification of its kind held by a VPN tool. As layers go it earns its place. It is not a substitute for keeping your devices updated, and it is absent from the entry-level plan.
And it cannot save you from a convincing email. If a message persuades you to type your banking password into a page that looks right, the encrypted tunnel carries that mistake as faithfully as it carries anything else.
Compared with a free VPN
The comparison people actually make is not NordVPN against a rival subscription. It is NordVPN against the free app at the top of the store listing.
Running a VPN costs money: servers, bandwidth, staff. A provider that charges nothing still has those costs and must recover them somewhere. The usual method is selling the browsing data you installed the app to conceal, which inverts the entire point of the exercise. Free tiers offered by paid providers are a different thing, since they exist to sell you the paid tier, but a standalone free VPN with no visible business model has one you are not being shown.
Paying does not make a provider trustworthy on its own. It removes the incentive that makes the free ones dangerous, and it buys you someone to hold accountable.
So: safe enough for you?
If you want a VPN for public Wi-Fi at the airport, for the streaming service you already pay for and cannot reach abroad, or to keep your browsing away from your internet provider, the evidence supports NordVPN and there is a refund window if it turns out you never open the app.
If you need protection from a state adversary, from a former partner with access to your devices, or in a country where VPN use itself is prosecuted, this article is the wrong reference and a consumer VPN is the wrong tool. Those situations need advice built around your specific risk, not a product recommendation.
For everyone in between, the honest summary is that NordVPN has been checked more often, by more outside parties, than almost anything else in the category, and that it once handled a supplier's mistake badly and then fixed the underlying architecture. You can decide what weight to give each of those. What you should not do is take any provider's word for it, including through us.
Frequently Asked Questions
On the evidence that can be checked by outsiders, yes. Six independent no-logs assurance engagements since 2018, the most recent by Deloitte Lithuania under ISAE 3000, examined live systems rather than policy documents. No audit can prove a negative for ever, but no rival has submitted to that many.
It is a real company, part of Nord Security, operating since 2012 and registered in Panama. The complaints that surface are about billing and renewals rather than the product being fake. Set a calendar reminder before the term renews and most of that disappears.
One server in a rented Finnish data centre was accessed in March 2018 through a management tool the hosting provider had left exposed. No user credentials or browsing activity were taken. NordVPN was criticised for waiting until October 2019 to disclose it, which is a fair criticism.
Technically any VPN provider could, which is why the audits matter more than the promise. NordVPN runs its servers from RAM rather than disks, so a machine that is seized or powered down retains nothing to examine.
A free VPN has to earn money somewhere, and the usual method is selling the traffic data you installed it to protect. Paying for a VPN does not guarantee good behaviour, but it removes the incentive that makes free ones dangerous.
Yes. Buying and using a VPN is legal in the United Kingdom, and in July 2026 the government told Parliament it will not age-gate or ban them. What you do while connected is still subject to the same law as anything else.
Sources
- NordVPN — sixth independent no-logs assurance engagement (Deloitte Lithuania, ISAE 3000)
- AV-Comparatives — Anti-Phishing Comparative Test
- Ofcom — age assurance reporting under the Online Safety Act
- Federal Trade Commission — Are Public Wi-Fi Networks Safe?
How we assess VPNs
We did not buy this subscription and we do not publish speed figures we did not measure. What this page compiles is the material that already exists and can be checked by someone other than us: published audits and the standard each ran under, laboratory results, the provider's own documentation and refund terms, the jurisdiction it operates from, and the problems users report repeatedly. Where a claim comes from the company, we say so. Where it comes from an outside body, we name that body and the date. More on how this site works.
This site earns a commission if you subscribe through our links. It does not change what is written above. Full disclosure.