Private Internet Access Transparency Report Q2 2026

Posted on Aug 6, 2026 by Sonja Raath

Transparency reporting is most useful when it’s consistent. Every quarter, we publish the legal requests PIA receives, explain how they are categorized, and share the latest figures from our Bug Bounty and Vulnerability Disclosure programs.

Between April and June 2026, PIA received 19 legal requests. Our security programs also received 59 submissions, including two valid issues.

Here’s what the numbers show.

PIA’s Q2 2026 Legal Request Numbers

PIA categorizes the legal requests it receives under four headings: subpoenas, warrants, other government, law enforcement and civil requests, and foreign and informal requests.

Request typeQ2 2026
Subpoenas4
Warrants2
Other government, law enforcement, and civil requests7
Foreign and informal requests6
Total19

Logs produced: 0

PIA received 19 requests during Q2, the same overall number recorded during the first three months of 2026.

These figures represent requests received. They don’t indicate that an allegation was substantiated, that a particular user was involved, or that every request sought the same type of information.

PIA does not record VPN activity logs or connection information that could be used to reconstruct what someone did while connected to the service. Its VPN infrastructure uses RAM-only servers, which don’t write VPN session data to a hard drive.

Each request is assessed according to the applicable legal process and PIA’s policies. However, the absence of VPN activity and connection logs limits the information available in response to requests seeking those records.

No VPN activity or connection logs were produced in response to the 19 requests received during Q2.

Breaking Down the Requests

Subpoenas

4

PIA received four subpoenas between April and June.

A subpoena may seek records or other information relevant to a legal matter. Receiving one doesn’t establish that wrongdoing occurred, and the information requested can vary from case to case.

PIA reviews each subpoena to determine whether it is valid, properly addressed, and legally enforceable. Its no-logs policy means it doesn’t retain browsing histories or VPN connection records that could link a person to activity conducted through the VPN.

Warrants

2

PIA received two warrants during Q2.

Warrants are reviewed individually by the legal team. The existence of a warrant doesn’t change what information PIA holds: the company’s systems are designed not to record VPN activity or connection logs.

Other Government, Law Enforcement, and Civil Requests

7

This was the largest category during the quarter, with seven requests.

The category covers requests that don’t fall under subpoenas or warrants, including other government, law enforcement, and civil legal processes. The scope and legal standing of these requests can differ, so each one is assessed on its own circumstances.

Foreign and Informal Requests

6

PIA received six foreign and informal requests during Q2.

These can include approaches from authorities outside the United States or requests that aren’t made through a formal, enforceable US legal process. PIA reviews the origin, scope, and legal basis of each request before responding.

Q2 Bug Bounty and Vulnerability Disclosure Activity

PIA works with independent security researchers through its programs on YesWeHack. Researchers can submit suspected vulnerabilities affecting eligible PIA products and systems for review by the security team.

A higher number of submissions doesn’t necessarily mean that more vulnerabilities were found. Reports can include duplicates, informational observations, out-of-scope findings, or behavior that doesn’t present a security risk.

Here are the Q2 figures:

After duplicate submissions were excluded, 51 unique reports remained.

Two unique submissions were classified as valid and passed to the relevant teams for assessment and remediation where required.

Forty-nine unique submissions were classified as invalid. Depending on the outcome of the triage process, this category can include reports that are informational, out of scope, not reproducible, or don’t demonstrate a security impact.

Each submission still requires review. The process helps the security team separate valid vulnerabilities from duplicate reports, expected product behavior, and findings that fall outside the programs’ defined scope.

Continuing to Publish the Numbers

Transparency reports aren’t a claim that risks or legal requests disappear. They provide a recurring record of what PIA receives, what information it retains, and how external researchers interact with its security programs.

The numbers will change from quarter to quarter. Our commitment is to continue publishing them and provide enough context for readers to understand what they represent.

Our next report will cover July, August, and September 2026.