ExpressVPN published its transparency report for the second half of 2025 confirming receipt of approximately 1.38 million data requests during the period — primarily DMCA takedown notices and law enforcement inquiries directed at IP addresses associated with ExpressVPN servers. Of these 1.38 million requests, ExpressVPN disclosed zero user data. The framework architecture — the company structurally cannot disclose user data because it does not maintain logs that link IP addresses to specific user activity — produced the zero-disclosure outcome despite the substantial request volume. ExpressVPN's verification framework also includes the June 2025 KPMG audit (the latest in multi-year audit sequence) and four ISO certifications including ISO 27001 (information security management) earned in early 2026.

This Desk reads the ExpressVPN transparency framework as informative about both the operational reality of zero-logs VPN provider operation and the broader VPN-industry verification architecture. The 1.38 million H2 2025 request volume is substantial in absolute terms, demonstrating that VPN servers attract substantial legal process activity. The zero-disclosure outcome demonstrates that no-logs architecture, when properly implemented, structurally limits provider obligation regardless of legal process volume. The combined verification stack — transparency reporting + independent audit + ISO certification — provides multi-dimensional framework verification.

What the H2 2025 Transparency Report Specifically Established

The transparency report disclosed specific request categories.

DMCA-style takedown notices. Substantial portion of requests related to alleged copyright infringement traced to ExpressVPN IP addresses. The notices typically request logs identifying users connected from specific IP at specific timestamp.

Law enforcement inquiries. Specific inquiries from law enforcement agencies in multiple jurisdictions seeking user identification information.

Civil litigation requests. Specific civil litigation matters where parties sought user information through subpoena or similar process.

Government emergency requests. Specific emergency requests from government authorities citing imminent threat or specific exigent circumstances.

Other categories. Specific other request types including specific national security context requests where relevant.

For each category, the response framework was the same: ExpressVPN does not maintain logs that link user identity to IP address activity. The company cannot disclose user data because the framework does not maintain it.

The 1.38 million figure represents substantial volume. The zero-disclosure outcome confirms framework architectural integrity rather than tactical refusal to comply.

What KPMG June 2025 Audit Specifically Verified

The KPMG audit framework had specific scope.

No-logs framework verification. KPMG verified that ExpressVPN's TrustedServer architecture (RAM-only servers, no persistent storage) operationally implements the no-logs claim.

Server infrastructure verification. Specific server build, deployment, and operation framework evaluated.

Software stack verification. Specific software components evaluated for compliance with no-logs claim.

Audit methodology. KPMG framework operates within specific audit methodology with documented procedures and evidence collection.

Findings. Audit concluded that ExpressVPN's framework operationally implements no-logs claim. Specific operational practices align with claimed architecture.

The audit represents one in multi-year sequence. ExpressVPN has been audited by PwC, KPMG, and other major firms over multiple cycles since 2018.

What ISO 27001 Plus Three Other ISO Certifications Specifically Establish

The ISO certification framework has specific operational requirements.

ISO 27001:2022 (Information Security Management). Comprehensive information security management framework. Requires specific policies, procedures, controls, monitoring, and continuous improvement framework. ISO 27001 certification represents formal third-party verification that organization operates an information security management system meeting the standard.

ISO 22301 (Business Continuity Management). Framework for business continuity management ensuring operational resilience.

ISO 27017 (Cloud Security). Specific framework for cloud-based information security.

ISO 27018 (Privacy in Cloud). Specific framework for personally identifiable information protection in public cloud computing.

The combined four ISO certifications represent comprehensive operational framework verification spanning security management, business continuity, cloud security, and privacy.

ISO certifications operate at organizational rather than product level — they verify management systems and processes rather than specific products. They complement (rather than substitute for) audit framework verification of specific product operational characteristics.

What This Verification Stack Specifically Establishes

The combined ExpressVPN verification framework has multiple dimensions.

Audit framework (KPMG, prior PwC). Verifies specific no-logs claim implementation.

Transparency reporting. Documents request volume and disclosure outcomes, providing ongoing operational read.

ISO certifications. Verify management system framework operation.

Court testing. ExpressVPN has been subject to specific government investigations (notably 2017 Turkish investigation related to assassination of Russian ambassador where authorities seized servers and found no user data — operational verification through legal process).

The combined dimensions produce comprehensive verification framework. Each dimension addresses different aspect; together they support broad operational integrity claim.

Comparison Across Major Provider Verification Stacks

ProviderAudit frameworkTransparency reportingISO certificationsCourt-tested
ExpressVPNKPMG (multiple), PwCAnnual transparency reportsISO 27001 + 3 others (2026)Yes (2017 Turkish case)
NordVPNDeloitte ISAE 3000 (6 sequential)Specific reportingSpecific certificationsLimited tested cases
MullvadSEC Consult, AssureITSpecific frameworkSpecific certificationsYes (2023 Swedish raid)
ProtonVPNCure53Specific reportingSpecific frameworkSpecific cases
SurfsharkSpecific auditsSpecific reportingSpecific frameworkLimited
CyberGhostAudit frameworkQ1 2026 transparency reportSpecific frameworkSpecific

The pattern shows multiple major providers operating multi-dimensional verification frameworks. ExpressVPN's specific combination (audit + transparency + multiple ISO + court testing) provides comprehensive coverage.

What This Means for Users

Three operational considerations.

First, request volume confirms VPN value. The 1.38 million requests demonstrates that VPN users frequently face specific legal process directed at server IPs. Without VPN, the same legal process would directly target user IPs. The framework's value is confirmed by request volume.

Second, zero disclosure validates no-logs framework. Substantial request volume × zero disclosure = framework operational integrity. The arithmetic confirms structural rather than tactical privacy.

Third, multi-dimensional verification matters. Single-dimension verification (audit only, transparency only, ISO only) provides partial signal. Multi-dimensional frameworks reduce likelihood that any single dimension fails to capture important framework gap.

What This Desk Tracks Through 2026

Three datapoints across the rest of 2026.

H1 2026 transparency report when published. Continued zero-disclosure outcome supports framework continuity.

Continued ISO certification renewal. Specific recertification cycles maintain framework verification.

Cross-provider transparency reporting comparison. Specific other providers' frameworks provide cross-reference.

Honest Limits

This Desk reads ExpressVPN transparency framework from publicly available ExpressVPN reports, KPMG audit summaries published by ExpressVPN, ISO certification disclosures, contemporary reporting in Cybernews, Bleeping Computer. Specific verification details remain partially confidential per audit and certification frameworks. The 2026 references reflect data through early May 2026. None of this constitutes specific provider recommendation.

Sources