ExpressVPN published its transparency report for the second half of 2025 confirming receipt of approximately 1.38 million data requests during the period — primarily DMCA takedown notices and law enforcement inquiries directed at IP addresses associated with ExpressVPN servers. Of these 1.38 million requests, ExpressVPN disclosed zero user data. The framework architecture — the company structurally cannot disclose user data because it does not maintain logs that link IP addresses to specific user activity — produced the zero-disclosure outcome despite the substantial request volume. ExpressVPN's verification framework also includes the June 2025 KPMG audit (the latest in multi-year audit sequence) and four ISO certifications including ISO 27001 (information security management) earned in early 2026.
This Desk reads the ExpressVPN transparency framework as informative about both the operational reality of zero-logs VPN provider operation and the broader VPN-industry verification architecture. The 1.38 million H2 2025 request volume is substantial in absolute terms, demonstrating that VPN servers attract substantial legal process activity. The zero-disclosure outcome demonstrates that no-logs architecture, when properly implemented, structurally limits provider obligation regardless of legal process volume. The combined verification stack — transparency reporting + independent audit + ISO certification — provides multi-dimensional framework verification.
What the H2 2025 Transparency Report Specifically Established
The transparency report disclosed specific request categories.
DMCA-style takedown notices. Substantial portion of requests related to alleged copyright infringement traced to ExpressVPN IP addresses. The notices typically request logs identifying users connected from specific IP at specific timestamp.
Law enforcement inquiries. Specific inquiries from law enforcement agencies in multiple jurisdictions seeking user identification information.
Civil litigation requests. Specific civil litigation matters where parties sought user information through subpoena or similar process.
Government emergency requests. Specific emergency requests from government authorities citing imminent threat or specific exigent circumstances.
Other categories. Specific other request types including specific national security context requests where relevant.
For each category, the response framework was the same: ExpressVPN does not maintain logs that link user identity to IP address activity. The company cannot disclose user data because the framework does not maintain it.
The 1.38 million figure represents substantial volume. The zero-disclosure outcome confirms framework architectural integrity rather than tactical refusal to comply.
What KPMG June 2025 Audit Specifically Verified
The KPMG audit framework had specific scope.
No-logs framework verification. KPMG verified that ExpressVPN's TrustedServer architecture (RAM-only servers, no persistent storage) operationally implements the no-logs claim.
Server infrastructure verification. Specific server build, deployment, and operation framework evaluated.
Software stack verification. Specific software components evaluated for compliance with no-logs claim.
Audit methodology. KPMG framework operates within specific audit methodology with documented procedures and evidence collection.
Findings. Audit concluded that ExpressVPN's framework operationally implements no-logs claim. Specific operational practices align with claimed architecture.
The audit represents one in multi-year sequence. ExpressVPN has been audited by PwC, KPMG, and other major firms over multiple cycles since 2018.
What ISO 27001 Plus Three Other ISO Certifications Specifically Establish
The ISO certification framework has specific operational requirements.
ISO 27001:2022 (Information Security Management). Comprehensive information security management framework. Requires specific policies, procedures, controls, monitoring, and continuous improvement framework. ISO 27001 certification represents formal third-party verification that organization operates an information security management system meeting the standard.
ISO 22301 (Business Continuity Management). Framework for business continuity management ensuring operational resilience.
ISO 27017 (Cloud Security). Specific framework for cloud-based information security.
ISO 27018 (Privacy in Cloud). Specific framework for personally identifiable information protection in public cloud computing.
The combined four ISO certifications represent comprehensive operational framework verification spanning security management, business continuity, cloud security, and privacy.
ISO certifications operate at organizational rather than product level — they verify management systems and processes rather than specific products. They complement (rather than substitute for) audit framework verification of specific product operational characteristics.
What This Verification Stack Specifically Establishes
The combined ExpressVPN verification framework has multiple dimensions.
Audit framework (KPMG, prior PwC). Verifies specific no-logs claim implementation.
Transparency reporting. Documents request volume and disclosure outcomes, providing ongoing operational read.
ISO certifications. Verify management system framework operation.
Court testing. ExpressVPN has been subject to specific government investigations (notably 2017 Turkish investigation related to assassination of Russian ambassador where authorities seized servers and found no user data — operational verification through legal process).
The combined dimensions produce comprehensive verification framework. Each dimension addresses different aspect; together they support broad operational integrity claim.
Comparison Across Major Provider Verification Stacks
| Provider | Audit framework | Transparency reporting | ISO certifications | Court-tested |
|---|---|---|---|---|
| ExpressVPN | KPMG (multiple), PwC | Annual transparency reports | ISO 27001 + 3 others (2026) | Yes (2017 Turkish case) |
| NordVPN | Deloitte ISAE 3000 (6 sequential) | Specific reporting | Specific certifications | Limited tested cases |
| Mullvad | SEC Consult, AssureIT | Specific framework | Specific certifications | Yes (2023 Swedish raid) |
| ProtonVPN | Cure53 | Specific reporting | Specific framework | Specific cases |
| Surfshark | Specific audits | Specific reporting | Specific framework | Limited |
| CyberGhost | Audit framework | Q1 2026 transparency report | Specific framework | Specific |
The pattern shows multiple major providers operating multi-dimensional verification frameworks. ExpressVPN's specific combination (audit + transparency + multiple ISO + court testing) provides comprehensive coverage.
What This Means for Users
Three operational considerations.
First, request volume confirms VPN value. The 1.38 million requests demonstrates that VPN users frequently face specific legal process directed at server IPs. Without VPN, the same legal process would directly target user IPs. The framework's value is confirmed by request volume.
Second, zero disclosure validates no-logs framework. Substantial request volume × zero disclosure = framework operational integrity. The arithmetic confirms structural rather than tactical privacy.
Third, multi-dimensional verification matters. Single-dimension verification (audit only, transparency only, ISO only) provides partial signal. Multi-dimensional frameworks reduce likelihood that any single dimension fails to capture important framework gap.
What This Desk Tracks Through 2026
Three datapoints across the rest of 2026.
H1 2026 transparency report when published. Continued zero-disclosure outcome supports framework continuity.
Continued ISO certification renewal. Specific recertification cycles maintain framework verification.
Cross-provider transparency reporting comparison. Specific other providers' frameworks provide cross-reference.
Honest Limits
This Desk reads ExpressVPN transparency framework from publicly available ExpressVPN reports, KPMG audit summaries published by ExpressVPN, ISO certification disclosures, contemporary reporting in Cybernews, Bleeping Computer. Specific verification details remain partially confidential per audit and certification frameworks. The 2026 references reflect data through early May 2026. None of this constitutes specific provider recommendation.
Sources
- ExpressVPN Transparency Report — ExpressVPN
- ExpressVPN Independent Audits — ExpressVPN
- Best VPN 2026 Tested Audited — Axis Intelligence
- Major VPN Providers Independent Audit Results 2026 — Compass Reviews
- Best No-Log VPNs 2026 — Cybernews
- 149M Logins Exposed Online — ExpressVPN Blog
- Top 10 VPNs of 2026 — Gupta Deepak