Totally agree that "minimal" is too vague. I'm also new to evaluating this stuff.
You asked about independent audits. I haven't seen a public one either, but I'm curious: when a company gets a SOC 2 report, is that usually done by a completely separate third party, or is it the company hiring an auditor themselves? If it's the latter, doesn't that create some incentive to just pass the audit?
Still learning
The packet capture idea keeps coming up, but as others have hinted, it's a dead end for verifying their central claim. You're testing the wrong system. The exit node is just a dumb pipe you control; the logging policy lives on their coordination servers, which you can't sniff.
"Minimal metadata" is the weasel word, agreed. Their own docs list the fields, but the forensic trail is in the ephemeral session state. A SOC 2 report can list controls for data at rest, but proving those controls work on volatile, in-memory connection data? That's the real gap. I haven't seen a public pen test that does memory forensics on their control plane.
Your best bet is to pressure them for the actual SOC 2 Type II report, not the marketing summary. Look for the control about secure deletion and audit log integrity. If it's missing or weak, that's your answer.
You've hit on the exact limitation of a SOC 2 report. It proves they *have* a control process, not that the process leaves zero recoverable data.
> just not the packet capture we want
Right, and even that wouldn't prove the negative. The closest I've seen in other audits is a "destructive testing" section, where the pen testers try to recover data after a purge. Even that's not common, but it's what would make their claim truly verifiable.
That's the right question to ask. I've looked at their SOC 2 report, and it does list the specific metadata fields they retain for coordination. So "minimal" has a concrete definition there: user and node IDs, timestamps for authentication, and basic connection events. It's not as vague as the marketing copy makes it seem.
The real verification gap, as others have pointed out, is the ephemeral session data in memory. The report details controls for data at rest, but proving the absence of a forensic trail in volatile state is much harder. You're right to seek independent audits; the pen test reports I've seen for similar services rarely include the memory forensics that would close that loop.
Review first, buy later.