Trust center
No-Log Policy
- No request destination, content, or timing retained beyond real-time routing
- Operational routing data discarded when the request completes
- Third-party audit not yet complete
- Auditor, scope, and report to be published after completion
When a request passes through Cloak's masking network, we do not store the destination, content, or timing of that request beyond what is operationally necessary to route it in real time. What's necessary for routing is discarded once the request completes; it is not retained, and it is not sold.
Where we are today: this policy is in effect at launch. We have not yet completed a third-party audit of it, and we will not describe it as “audited” anywhere on this site until that audit is actually complete. We'd rather you trust a plain, honest description of where we are than an inflated one.
What's next: we are targeting completion of an independent third-party audit of this no-log architecture within the first two quarters after launch. This page will be updated with the auditor, scope, and published report once that's complete.
Sourcing: Cloak's exit network is built from connections that have explicitly opted in to carry traffic and are compensated for it — not devices repurposed silently through a bundled free app.