VPN Warrant Canaries Explained: Do Any Providers Still Use Them?
A warrant canary is one of the more clever, if legally untested, tools a privacy-focused company can use to work around laws that prohibit it from directly disclosing a secret government data request. Here's how the concept works, which VPN providers actually use one, and why most of the industry has largely moved on from the practice.
The Legal Problem a Warrant Canary Tries to Solve
In some jurisdictions, a company that receives a secret government surveillance order — like a US National Security Letter, which can come with a gag order attached — is legally barred from telling anyone, including its own customers, that the request happened. A warrant canary is a workaround built on a legal technicality: a company can't be compelled to lie, only to stay silent. So the company regularly publishes a statement along the lines of "we have not received any secret government data requests as of this date." As long as that statement keeps appearing on schedule, customers can infer no such request has been received. If the statement quietly disappears, or stops being updated, that absence itself is the signal — without the company ever having to explicitly say what happened.
Who Actually Publishes One
IVPN is the most prominent VPN provider still maintaining this practice, publishing a warrant canary monthly, confirming it has received no searches, seizures, or data requests as of each publication date. This sits alongside the company's other transparency measures, including annual independent Cure53 audits and published ethics guidelines.
Most other major providers have moved toward a different, arguably more robust transparency model instead: regular transparency reports that disclose the actual number of legal requests received and how each was handled, rather than a binary canary statement. CyberGhost pioneered this approach back in 2011, publishing quarterly transparency reports years before "no-logs VPN" was even a common marketing phrase. PIA now publishes similar quarterly reports (its Q1 2026 report disclosed 19 government and law enforcement requests, none resulting in data disclosure, since none was held). ExpressVPN publishes biannual transparency reports through its Trust Center.
Why the Warrant Canary Approach Has Fallen Out of Favor
The legal theory behind warrant canaries has never been definitively tested in court, and several legal experts have raised doubts about whether a canary's disappearance would actually hold up as a workaround if directly challenged — a company could arguably still be compelled to keep publishing a false "all clear" canary under a sufficiently aggressive gag order, undermining the whole premise. Transparency reports, by contrast, disclose actual figures on a fixed schedule and don't rely on the same untested legal loophole, which is likely why more of the industry has gravitated toward that model instead of maintaining a canary.
What This Means for Evaluating a VPN
Neither approach is inherently superior on its own — both are transparency signals layered on top of a provider's actual no-logs architecture, not a substitute for it. A warrant canary from a provider with weak underlying data retention practices doesn't protect you any more than a quarterly transparency report from one. What matters most is the combination: does the provider have a genuinely audited, minimal-logging architecture, and does it also make a good-faith effort to disclose what legal pressure it faces, whether through a canary, a transparency report, or both? IVPN and Mullvad both combine minimal-data architecture with active transparency practices; CyberGhost and PIA combine it with regular transparency reporting instead of a canary specifically.
The Original Warrant Canary Concept Beyond VPNs
Warrant canaries didn't originate with VPN providers specifically — the concept dates back to early 2000s discussions among librarians and civil liberties advocates responding to US Patriot Act provisions, and was later popularized more broadly by services like the now-defunct secure email provider Lavabit, whose 2013 shutdown (rather than complying with a government order to hand over its encryption keys) remains one of the most frequently cited cautionary tales in VPN privacy discussions generally. That history is part of why some privacy-focused VPN providers adopted the practice in the first place: it was an established, if legally untested, transparency tool already circulating in the broader privacy and digital-rights community before VPN companies began using it themselves.
How to Actually Check a Provider's Canary Yourself
If you want to verify a warrant canary yourself rather than relying on a provider's own claim that they publish one, look for a dedicated page on the company's website (often under a "transparency" or "canary" section), check the publication date against the promised schedule, and ideally check an independent archive service to confirm the page's history hasn't been quietly altered or had older versions removed. A canary that's consistently late, or whose historical versions have disappeared from public archives, is a weaker signal than one with a clean, consistently timestamped publication record.
Should a Missing Canary Alone Make You Switch Providers?
Privacy advocates generally caution against treating a single missed or discontinued canary update as definitive proof of a secret government order, since companies sometimes simply discontinue the practice for unrelated reasons — a change in legal counsel's advice, a shift toward transparency reporting instead, or an oversight during a company restructuring. The more reliable approach is watching for a pattern: a canary that disappears suddenly and permanently, with no public explanation and no replacement transparency mechanism introduced, is a meaningfully stronger signal than one instance of a missed monthly update.
Whichever transparency practice a provider uses, treat it as one signal among several rather than the sole basis for trust.
Check a provider's current transparency page directly for the most up to date practice, since these policies evolve over time.
Frequently Asked Questions
What is a VPN warrant canary?
A regularly published statement confirming a company hasn't received a secret government data request as of that date. If the statement stops appearing or updating, that absence itself signals something may have changed, without the company having to explicitly disclose what.
Which VPN providers currently publish a warrant canary?
IVPN is the most prominent example, publishing one monthly. Most other major providers have shifted toward regular transparency reports disclosing actual request figures instead.
Is a warrant canary legally guaranteed to work?
No. The legal theory has never been definitively tested in court, and some legal experts question whether a company could still be compelled to keep publishing a false canary under a sufficiently aggressive gag order.
Is a transparency report better than a warrant canary?
Neither is inherently superior; both are transparency signals layered on top of a provider's actual data-retention practices. Transparency reports disclose concrete figures on a fixed schedule rather than relying on an untested legal workaround.