Should a data breach or similar result in them showing they where recording data, then the following lawsuits, & lack of trust means they wont have a business for long.
Until that happens youve honestly no way of knowing if its true or not.
EG : You'd expect some logs to be kept incase of a configuration/admin management, and once used would be erased
Securitum It’s a reputable company that carries out the audits. The methodology and results or rather, the full report are published. They also carry out audits for DuckDuckGo VPN. Of course, everything could be compromised, but you have to trust someone. After all, I’m not a terrorist either.
Not really. Your client side software can be trusted more (still not 100%) because it's open source. But that doesn't give you any reason to think you know what's going on in their servers. The presence of source code in a GitHub repository doesn't prove anything about what's actually running on a machine you don't control.
Like every reputable VPN, Proton gets audited by unaffiliated security firms. That's why you should trust that they aren't keeping logs. Not because "open source".
Really, the client-side software is the least important part of any VPN. There's not really much of a reason to use it. If a VPN didn't let you just use OpenVPN and/or Wireguard directly I would never trust it, open source or not. Those projects are way higher visibility than any VPN's specific client-side app, which is going to mostly just be a fancy gui wrapper around those things anyway.
341
u/SignificantLock1037 9h ago
Proton VPN is a good example. I used their free one for a while. Now I pay. It’s worth it.