ExpressVPN privacy and server technology gets the OK from two new independent audits

NordVPN Cookies Schild
(Image credit: NordVPN)

ExpressVPN says its privacy policy and core server technology have been validated in two new independent audits from KPMG and Cure53.

The independent auditors from KPMG performed testing on ExpressVPN's controls framework and interviewed its team members in order to check on the processes, systems, and controls to ensure its VPN servers were in compliance with its privacy policy.

The audit, which was conducted under the International Standard on Assurance Engagements (ISAE) (UK) 3000 Type 1, included testing ExpressVPN's policy of not collecting activity logs or connection logs, and that TrustedServer technology operates as it describes.

What else did the auditors find?

Separately, cybersecurity firm Cure53 conducted a source code audit and white-box security assessment of TrustedServer. 

ExpressVPN claims the findings were positive and highlighted TrustedServer’s strong security posture, however, auditors did find some: “mostly general weaknesses and minor flaws were spotted.". 

"Further, most of them can be evaluated as trivial to fix and resolve".

Cure53's auditors elaborated: "It can be positively acknowledged as well that none of the four actually identified vulnerabilities was ranked with a High or Critical severity score, showcasing an already quite robust environment exposed by the ExpressVPN TrustedServer components.”

If you are interested in checking the results of the audit in full, you can check out the report by KPMG here and read the full audit report by Cure53 here.

"Regular third-party audits that validate our controls and the results of our internal team’s work, along with other security efforts like our bug bounty program, give us even more confidence that we are protecting our users well,” says Aaron Engel, Head of Cybersecurity, ExpressVPN. 

The news comes as VPN technology continues to play a key role in conflict zones around the world.

VPN use reportedly skyrocketed in Cuba following authorities disrupting internet access as part of efforts to crack down on political protesters.

If you're interested in testing out ExpressVPN's claims yourself, the company's $100,000 bug bounty for spotting vulnerabilities TrustedServer is still up for grabs.

TOPICS

Will McCurdy has been writing about technology for over five years. He has a wide range of specialities including cybersecurity, fintech, cryptocurrencies, blockchain, cloud computing, payments, artificial intelligence, retail technology, and venture capital investment. He has previously written for AltFi, FStech, Retail Systems, and National Technology News and is an experienced podcast and webinar host, as well as an avid long-form feature writer.

Read more
A repeating pattern of pink magnifying glasses on a light blue background
Why do VPN audits matter?
NordVPN running on a desktop, mobile devices, Apple TV, a router and a game console
NordVPN reacts to results from its latest security audit
Mullvad VPN working on a laptop
Independent auditors confirm Mullvad VPN as secure
A hand holds a smartphone displaying the NordVPN logo
"Privacy isn’t just a buzzword" – independent audit confirms NordVPN doesn't store your data
ExpressVPN Lightway Protocol
ExpressVPN upgrades to post-quantum encryption NIST standards
The logo of ExpressVPN vs NordVPN logo
ExpressVPN vs NordVPN: which VPN should you get?
Latest in VPN Services
ExpressVPN's Lightway Turbo upgrade – promo image
Can fast be faster? ExpressVPN promises it’s possible
AdGuard VPN during TechRadar tests
AdGuard becomes the latest VPN to add post-quantum encryption
ExpressVPN's new Linux app interface
ExpressVPN releases a major upgrade to its Linux app
ExpressVPN apps running on a laptop and mobile during TechRadar's testing
What's new in Lightway 2.0? Here are the 4 biggest changes I'm excited for
A VPN running on a mobile device
A new era for VPN testing? ATMSO publishes the first-ever testing standards in an "important milestone"
Aircove router, smartphone and laptop with ExpressVPN app on screen on a wooden table
ExpressVPN's Aircove becomes the first device equipped with Lightway 2.0 – and the upgrades don't stop there
Latest in News
Garmin Instinct 3 next to the Apple Watch Ultra 2
New figures claim the smartwatch market just shrunk for the first time ever, and the Apple Watch Ultra 3 is to blame
Hitman: World of Assassination on PSVR 2.
Hitman: World of Assassination hits PSVR 2 soon, finally giving you a reason to dust off your headset
A stressed employee looking over some graphs
UK workers are spending more than one day per week tracking down information
Vision Pro Metallica
Apple Vision Pro goes off to never never land with Metallica concert footage
Mufasa is joined by another lion, a monkey and a bird in this promotional image
Mufasa: The Lion King prowls onto Disney+ as it finally gets a streaming release date
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump