TRANSPARENCY / VEILORA

No-logs audit.
Scope, evidence, context.

Understand the reported findings and how the operator identifies Veilora within the reviewed service.

Reported assessment

VPNTestor Platform / Openscore VPN

James Robert Smith

Review date & version

2026-07-29 · v1.0

Publication: 30 July 2026

Reported result

Pass — within the stated scope

Restricted read-only production review

A point-in-time review

The published report describes a restricted, read-only review of the production environment on 29 July 2026: the central backend, data structures and reporting interfaces, node configuration, DNS handling, cloud and CDN settings, backups, support, diagnostics and administrator permissions. Its reported result was a pass within that scope.

Activity data and service data

The report says the inspected systems did not persist browsing destinations, domains, full URLs, DNS queries, browsing or communication content, original IP histories, per-user node histories, or individual connection start/end times and durations. This is a finding about the reviewed systems, not a claim that a VPN processes no data at all.

Temporary connection state

Active tunnels need temporary session, routing, handshake and buffering state. The report describes memory-based processing and release after disconnection, with short-lived caches for online device limits. Those transient states should be distinguished from durable connection histories.

Usage totals are not destination histories

The reviewed service processes aggregate upload/download totals and daily usage for quotas, subscriptions and support. The report states that these totals do not contain destinations or communication content. A usage total alone does not identify which websites were visited.

Access, infrastructure and backups

The review also covered administrator queries and exports, cloud/CDN logging settings, and backup data. The report describes no discovered facility to retrieve user browsing histories in the inspected management system. System health metrics, account records and service operations remain separate data categories.

What signatures establish

The source provides SHA-256 manifests and Ed25519 signatures for reports and evidence packages. These can establish file integrity and signing-key use; they do not by themselves establish that every statement is true. We have not independently reproduced the production audit or verified those signatures.

Read the result within its limits

This review is not an ISO certification, SOC 2 report, legal opinion, or guarantee for every future version. Material changes to apps, nodes, suppliers or data handling require further review. A VPN and a no-logs assessment do not guarantee wallet, asset or transaction security.

Retention periods described in the source

These are the source report’s descriptions of the reviewed service. They are not a newly issued Veilora privacy policy or a guarantee for later deployments.

Daily aggregate traffic

Approximately two months

Historical registration and order records

Approximately three months

Voluntarily submitted diagnostics

Up to 14 days

Completed support conversations

Deleted from the active system after completion

Online device and session state

Temporary session processing and short-lived caches

Back to technology & privacy →