Sources agree
KPMG LLP (UK) issued an ISAE (UK) 3000 Type I reasonable-assurance report dated 8 May 2025 on ExpressVPN's TrustedServer, as at 28 February 2025, with no exceptions on the control objective covering user-activity logging.
3 separate sources: KPMG LLP, Engadget, and ExpressVPN
Sources and caveats (3)
KPMG LLP (hosted by ExpressVPN)
Controls provide reasonable assurance that the ExpressVPN TrustedServer does not collect logs of users’ activity, including no logging of browsing history, traffic destination, data content, DNS queries, or specific connection logs.
Counts toward the two-source rule
Conflict of interest: Commissioned by the auditee (Express Technologies Limited); addressed to it; KPMG disclaims all duty to readers. Hosted behind a click-through of KPMG's terms (no login).
KPMG's assessment was an ISAE 3000 Type I audit. That means it focused on ExpressVPN's control design and implementation at a specific point in time.
Counts toward the two-source rule
Conflict of interest: Engadget lists ExpressVPN among its top VPN picks (page says so) and carries VPN affiliate links; treat as corroboration. Engadget quotes the KPMG paper directly, so it read the report.
KPMG provided reasonable assurance that our systems functioned as designed, with no identified issues regarding our technical safeguards against activity logging
Counts toward the two-source rule
Researcher notes
Three groups: the KPMG report itself (read in full), Engadget (read the report, restates its terms), and ExpressVPN's blog. The report is public behind a click-through, unlike NordVPN's Deloitte/PwC reports, which need a Nord account. Limits stated by KPMG and Engadget: Type I, a point in time (28 Feb 2025), design and implementation not sustained operation; scope is the TrustedServer VPN service and the Privacy Policy claims, not the company's apps, billing or website. Report is addressed to Express Technologies Limited and KPMG accepts no duty to any reader. Control objective 1 rows C1.1.1 to C1.2.1 show 'No exceptions'.