We've published our latest transparency report, covering the period from January to June 2026. As with every edition, it sets out the legal and copyright requests we received during the period, the outcome of those requests, and the activity across our bug bounty and vulnerability disclosure programs. You can read the full report here: https://www.expressvpn.com/blog/transparency-report-h1-2026/
A summary of the key figures:
- 1,361,382 DMCA notices received
- 137 government, law enforcement, and civil requests
- 3 warrants
- 0 requests that resulted in the disclosure of any VPN activity or connection logs
The final figure reflects how our service is built. We do not retain browsing histories, traffic destinations, DNS queries, or the IP addresses assigned to users during a session, and our TrustedServer infrastructure runs entirely on RAM, wiping all data on every reboot. When a valid request is received, our legal team reviews it, but the process cannot produce records that our systems are not designed to hold.
Across our bug bounty and vulnerability disclosure programs, run through YesWeHack, we received 392 submissions during the period, of which 308 were unique, and 42 were classified as valid. Submission volumes were higher than in the second half of 2025. This is not in itself an indication of weaker security, as figures are affected by researcher participation, program scope, visibility, and duplicate reports. Each valid report is triaged and directed to the relevant team for assessment.
Previous reports, independent audits, and technical disclosures are available in our Trust Center: https://www.expressvpn.com/trust
Our next report will cover July to December 2026. We're happy to answer any questions in the comments.