So I was pulling together audit docs for a client project, the usual privacy policy deep vetting. And man, going through these 'independent' security audit reports from the big VPN names just left me frustrated. Half of them feel like they checked a box, you know? They audit one server in one location from 18 months ago and call it a day. Where's the ongoing commitment? I wanna see them audit the no-log claim under real pressure, not just a staged test. It all comes down to trust, and right now the whole audit landscape feels performative. For most users looking for real privacy, digging into who did the audit and their scope matters more than the brand's marketing. A smaller player with a solid, recent audit from a firm like Cure53 often means more than a giant's vague annual summary. Just my two cents from being in the data trenches. Anyone else feel like the audit transparency is more smoke than fire lately?