Is Proton VPN Open Source and Independently Audited?

Is Proton VPN Open Source and Independently Audited?
Yes. Proton VPN open source clients ship on every platform, published on GitHub under the GPLv3 since January 2020, and independent auditors have examined both the apps and the no-logs server infrastructure. Securitum has audited the no-logs policy every year since 2022, and the applications have been through separate security audits with the reports published rather than summarised. Open source means you can read the client, not that you can read the servers, and that distinction is where most VPN transparency claims quietly stop. Reproducible builds are the missing piece for anyone who wants to confirm that the binary in the app store matches the published source. Even with that gap, this sits a long way ahead of the industry norm of a closed binary and a confident press release.
This page is part of the Proton VPN FAQ Hub.
Which apps are open source?
Proton VPN open source coverage runs across the consumer platforms: Windows, macOS, Linux, Android, iOS and the browser extension, all published on GitHub. The client repositories carry the GNU General Public Licence v3, with some bundled WireGuard components under MIT and Apache licences. Proton released the lot in January 2020, and Proton’s open source announcement and audit links have been kept current since.
Worth checking for yourself, because this is the sort of claim that rots quietly. A repository last touched four years ago is technically open source and practically useless. Proton’s are active, with commits landing in the same weeks the apps update.
Who has audited Proton VPN, and when?
Two separate strands. Whether the servers keep any logs has been audited annually by Securitum, a European security firm, since 2022, with the fifth consecutive report published in June 2026. The applications have had their own security audits, including earlier work by SEC Consult and more recent reviews by the independent researcher Ruben Santamarta, refreshed in December 2025.
The part that matters is publication. Proton puts the reports out rather than a summary of the reports, which lets anyone with the patience read the findings and the caveats. A press release announcing that a company passed an audit is not an audit.
What did the no-logs audit actually test?
The 2026 Securitum engagement went after the claims that would matter in a courtroom rather than the ones on the homepage. Auditors reviewed server configuration files, logging directives and the automated systems meant to catch unauthorised changes.
The conclusion, in the auditors’ careful phrasing, was that the technical evidence reviewed did not indicate that the examined infrastructure logs browsing activity, DNS queries, destination services, traffic contents or user-identifiable connection metadata. Careful wording, and appropriately so, because nobody can prove a negative across every machine forever.
- Whether user activity or connection metadata such as DNS queries and timestamps are recorded anywhere
- Whether network traffic contents are inspected or stored in the path
- Whether the services a user connects to are monitored
- Whether the no-logs configuration is uniform across regions, not just on the servers shown to auditors
- Whether automated detection would catch a logging directive being switched back on
What does Proton VPN open source code not prove?
You can read the client. You cannot read the servers, and no VPN on the market can offer that, because a machine you do not control can be reconfigured the moment the auditors pack up. This is the permanent structural limit of the whole category, and Proton is subject to it exactly like everyone else.
Reproducible builds close part of the gap by letting anyone confirm that a shipped binary was compiled from the published source. Proton offers this on some platforms and not on all of them. Until that is universal, reading the source tells you what the source says, not what installed itself on your laptop.
Why does any of this matter to a normal user?
Security that depends on nobody reading the code is not security, a point cryptographers settled in the nineteenth century and now file under Kerckhoffs’s principle. Published code invites awkward questions, and awkward questions are what find bugs. A closed VPN client asks you to take the vendor’s word for it, indefinitely, on the one piece of software with a view of everything you do online.
For most people the benefit of Proton VPN open source code is indirect. You will not be auditing the Android client this weekend. Somebody will, eventually, and that standing possibility is what keeps Proton VPN honest, and much of why the service counts as safe, in a market where several competitors have shipped clients caught reporting back to their own analytics.
Read the code first if you like. The price will still be here.
BAIZAAR has Proton VPN Plus at £2.39 / $2.99 / €2.99 per month on the two year plan, 70% off the usual £7.99 / $9.99 / €9.99 and billed £57.36 / $71.76 / €71.76 for the first 24 months. Ten devices, 20,000+ servers across 140+ countries, and a 30-day money-back guarantee so you can test the claims yourself.
Get Proton VPN Plus for £2.39 / $2.99 / €2.99 per month on the two year plan, a saving of 70%. Prefer a shorter commitment? The one year plan runs £3.19 / $3.99 / €3.99 per month.
Pricing shown in GBP / USD / EUR, taken from Proton’s partner offer page on 23 August 2026. The two year plan is billed £57.36 / $71.76 / €71.76 up front and renews at the standard rate. Affiliate link: BAIZAAR may earn a commission at no extra cost to you.
