No-Logs Audit
A privacy promise is worth nothing without proof. Independent auditors inspected our servers, source code, and internal processes to verify that NexVeil keeps no record of what you do.
Audit completed: 30 August 2026 · Next audit: annuallyVerdict: auditors found no mechanism by which NexVeil could reconstruct a user's browsing activity, originating IP address, or session history. The no-logs claim was assessed as accurately represented.
1. Audit verdict
An independent security assurance firm was given unrestricted read access to our production configuration, VPN server images, DNS resolvers, and account systems. Their conclusion: the infrastructure is designed so that activity data is never written anywhere it could persist.
| Claim tested | Result |
|---|---|
| No browsing or DNS query logs | Verified |
| No originating IP address stored | Verified |
| No connection timestamps or session records | Verified |
| Servers operate from volatile memory only | Verified |
| Account data limited to email, hashed password, billing state | Verified |
| Any third-party analytics on VPN traffic | None found |
2. Scope
- All 5,400+ production VPN servers across 90+ countries, sampled at random plus full review of the base image
- NexVeil DNS resolvers and the ad/tracker blocking service
- Account, authentication, and subscription databases
- Server provisioning and configuration-management pipelines
- Internal access controls, logging policy, and staff procedures
- Client applications for iOS, Android, macOS, Windows, and Linux
3. Methodology
Configuration review
Auditors reviewed the server image and configuration management code line by line to confirm that logging directives are disabled at the daemon level and that no syslog forwarding, packet capture, or flow export is configured.
Live server inspection
Randomly selected production servers were inspected while carrying real traffic. Filesystems, memory, and running processes were examined for any artefact tying a user to a destination.
Staff interviews
Engineers with production access were interviewed separately about what they could retrieve if instructed to. In each case the answer matched the technical finding: account and billing data only.
Simulated legal request
The team was asked to produce activity data for a known test account. They were unable to, because no such data exists.
4. Findings and remediation
No critical or high-severity privacy findings were raised. Two low-severity observations were made and both have been resolved:
- Low — a diagnostic verbosity flag on a small number of staging nodes could have produced connection metadata if promoted to production. The flag was removed from the image and a pipeline check now blocks it.
- Low — support ticket attachments were retained longer than the stated policy. Retention is now enforced automatically at 90 days.
5. How RAM-only servers work
Our VPN servers have no writable disk in normal operation. Each machine network-boots a signed, read-only image directly into memory, so:
- There is no persistent storage for logs to accumulate in
- A reboot or power loss wipes every trace of session state instantly
- Physical seizure of hardware yields no user data
- Any tampering with the image breaks signature verification and the server refuses to boot
Configuration is applied at boot from our management plane, which means a server can never silently drift into a logging state.
6. Warrant canary
As of the date above, NexVeil has not received any national security letter, gag order, or warrant requiring us to compromise the integrity of our service or install surveillance capability. This statement is reviewed and re-published each quarter. If it disappears or stops being updated, treat that as meaningful.
7. Data request transparency
| Period | Requests received | User data produced |
|---|---|---|
| H1 2026 | 14 | 0 |
| H2 2025 | 11 | 0 |
| H1 2025 | 7 | 0 |
Every request was answered truthfully: we hold no activity data to produce. Where an order was legally valid and sought only billing records, we complied within the narrowest possible scope.
8. Verify it yourself
- Run a DNS and WebRTC leak test while connected — your real IP should never appear
- Disable your network mid-session to confirm the kill switch cuts traffic immediately
- Read our Privacy Policy against this report and tell us if anything conflicts
- Request the full audit report by email if you need it for a security review
9. Contact
To request the complete report or raise a privacy concern: security@nexveilvpn.com. We also welcome responsible vulnerability disclosure.
This page is illustrative content for the NexVeil showcase site. Replace the verdict, dates, and figures with your real independent audit before publishing.