Secure your semester with up to 80% discount.

Secure your semester with up to 80% discount. Claim offer!

Claim offer!
Back To Campus V2

Secure your semester with up to 80% discount. Ends in

Secure your semester with up to 80% discount. Claim offer!

Claim offer!
Back To Campus V2
  • What authorities asked us for in H1 2026
  • What our no-logs policy means when requests arrive
  • Independent researchers submitted 392 security reports
  • More reports don’t automatically mean weaker security
  • Trust is built through a public record
  • What authorities asked us for in H1 2026
  • What our no-logs policy means when requests arrive
  • Independent researchers submitted 392 security reports
  • More reports don’t automatically mean weaker security
  • Trust is built through a public record

ExpressVPN Transparency Report: January–June 2026

ExpressVPN news 06.08.2026 5 mins
Sonja Raath
Written by Sonja Raath
image2

This transparency report covers legal and copyright requests received between January and June 2026

  • ExpressVPN received 1,361,382 DMCA notices during the first half of 2026
  • Government, law enforcement, and civil requests fell compared with H2 2025
  • Three warrants were received, unchanged from the previous reporting period
  • Our bug bounty programs received 392 submissions, 308 of them unique
  • Forty-two unique reports were classified as valid
  • No requests resulted in the disclosure of VPN activity or connection logs

Privacy shouldn’t depend on a company simply asking to be believed. It should be supported by how its systems are built, how they respond under pressure, and what the company is prepared to publish.

ExpressVPN’s mission is to make digital privacy and security accessible to everyone. That starts with collecting less data, but it also means inviting scrutiny and being open about what happens when authorities and independent security researchers test our systems and policies.

This report records the legal and copyright requests ExpressVPN received between January and June 2026. It also covers activity across our bug bounty and vulnerability disclosure programs during the same period.

What authorities asked us for in H1 2026

ExpressVPN received three main categories of request during the first half of the year:

  • 1,361,382 DMCA notices
  • 137 government, law enforcement, and civil requests
  • 3 warrants
Type of request H2 2025 H1 2026 Change
Government, law enforcement, and civil requests 155 137 Down 18
DMCA requests 1,382,986 1,361,382 Down 21,604
Warrants from any government institution 3 3 No change

The overall picture was relatively stable.

DMCA notices fell by approximately 1.6% compared with the second half of 2025, while requests from government, law enforcement, and civil entities declined by approximately 11.6%. The number of warrants remained unchanged at three.

These categories represent very different types of request. DMCA notices are commonly generated and submitted at scale through automated copyright-enforcement systems. Government, law enforcement, and civil requests are far smaller in number and can involve different legal processes and types of information.

A request being received doesn’t mean an allegation has been verified, that the request is legally enforceable, or that a particular ExpressVPN user was involved. Each request must be assessed according to its individual circumstances and the applicable legal process.

Image1 1

What our no-logs policy means when requests arrive

ExpressVPN’s no-logs policy is a system design choice, not a decision made only after a legal request arrives.

We don’t retain logs of users’ browsing histories, traffic destinations, data content, DNS queries, or the IP addresses assigned to users while connected to the VPN. Our TrustedServer technology also runs our VPN servers on RAM rather than traditional hard drives, with information on the server wiped whenever it is powered off and restarted.

This limits the information available when a request seeks to connect an individual to activity conducted through an ExpressVPN server.

Our legal team reviews requests to determine whether they are valid, properly addressed, and enforceable. The legal process can determine whether ExpressVPN must respond to a request, but it can’t create VPN activity or connection records that our systems weren’t designed to retain.

Number of H1 2026 requests that resulted in the disclosure of VPN activity or connection logs: 0 

Independent researchers submitted 392 security reports

Legal requests test what information our systems retain. Bug bounty programs apply a different kind of pressure by inviting independent researchers to examine eligible ExpressVPN products, applications, websites, servers, and infrastructure for potential security issues.

Between January and June 2026, our bug bounty and vulnerability disclosure programs received:

Image3 1

Eighty-four of the 392 submissions duplicated reports that had already been received, leaving 308 unique submissions.

Forty-two unique reports were classified as valid. Within YesWeHack, this includes reports that have been accepted by the security team as valid issues as well as issues that have progressed to resolution.

A valid classification doesn’t, by itself, describe an issue’s severity, potential impact, or remediation status. The 42 reports may cover different products, systems, and levels of risk, so the total shouldn’t be read as 42 equivalent vulnerabilities.

The relevant security and engineering teams assess each valid report and determine what remediation or further action is required.

The 266 invalid reports didn’t establish a new, valid security issue under the programs’ criteria. Depending on the result of the triage process, this category can include reports that were informational, out of scope, not applicable, not reproducible, or didn’t demonstrate a security impact.

More reports don’t automatically mean weaker security

Submission activity increased considerably from the second half of 2025, when ExpressVPN received 143 reports, including 120 unique submissions and 14 valid issues. That change shouldn’t be treated as a simple security score.

Bug bounty volumes can be influenced by the number of participating researchers, changes in program scope, increased program visibility, duplicate submissions, and changes in researcher tooling and submission practices. A higher number of reports doesn’t automatically show that a product became less secure, just as a lower number wouldn’t prove that all potential issues had been found.

What matters is whether reports are reviewed consistently, valid findings reach the appropriate teams, and the results are presented with enough context to be understood.

ExpressVPN’s bug bounty program is managed through YesWeHack and provides security researchers with defined testing scopes, reporting processes, rewards, and safe-harbor protections. External research sits alongside our internal testing and independent security audits as another way to assess our systems.

Trust is built through a public record

Transparency reporting can’t eliminate legal requests or prevent researchers from finding security issues. Nor should that be the standard.

Its purpose is to make the record visible: how many requests arrived, what information our systems were designed to retain, how often researchers tested our products, and what happened to the reports they submitted.

Our mission is to help people protect their privacy and security online. That mission carries an obligation to minimize the data we hold, subject our systems to external scrutiny, and publish evidence that readers can evaluate over time.

Earlier transparency reports, independent audits, and technical disclosures are available through the ExpressVPN Trust Center.

Our next Transparency Report will cover July through December 2026.

Explore the web with greater privacy

Get ExpressVPN

Sign up today to enjoy our latest offers

ExpressVPN for Teams
Sonja Raath

Sonja Raath

I like hashtags because they look like waffles, my puns intended, and watching videos of unusual animal friendships. Not necessarily in that order.

ExpressVPN is proudly supporting

Get Started