A public transaction, a server access log and a customer-support record are different datasets. Evidence about one does not establish deletion of the others.
Ask which data the claim covers
Scroll horizontally to read all columns.
| Data type | Question to ask |
|---|---|
| Access and security logs | Are IP addresses, request timestamps or device information retained? By the operator or a hosting provider? |
| Order and transaction records | Are quotes, destinations, amounts and status changes retained? For how long? |
| Support messages | What happens to tickets, attachments and correspondence? |
| Analytics | Which third-party tools receive events or identifiers? |
| Backups and legal holds | Does deletion include backups, and what retention exceptions apply? |
What an audit needs to specify
Look for an identifiable reviewer, review date, period covered, systems in scope, testing method and exclusions. The report should support the exact claim being made. A code audit of a contract is not an inspection of an operator’s server logging, support platform or backups.
A report is also a snapshot. A later deployment, analytics integration or policy change can alter the data flows. “Audited once” does not establish the current behavior of an unrelated domain or a new application version.
A vanished order page proves very little
An interface can stop displaying a record while the backend, a processor or a backup retains it. A deletion timer is therefore a statement about interface behavior unless there is evidence of the wider deletion process.
Ask whether deletion is automatic, what exceptions exist and how the provider handles legally required retention. Do not interpret a legal exception as a secret guarantee that nothing will ever be disclosed.
No server logs does not mean no transaction trail
Even if an operator could demonstrate that it retains no relevant server records, public blockchain activity is a separate source of information. Ethereum explorers expose transaction identifiers, amounts, participants, token events and timing.
The correct question is what the evidence supports, not whether a badge says “anonymous.” We do not claim that every transfer can be attributed to a person, but absence of a known attribution is not proof that attribution is impossible.
Choose an evidence-based conclusion
“Unverified” is not the same as “false.” It means the evidence is insufficient to rely on the promise. StableScope has not audited the internal systems of a mixing or exchange provider and does not certify a no-logs service.
- Documented: the report explicitly covers the claim and the current system.
- Partly documented: some data or processors are covered, others are excluded.
- Unverified: the claim is only marketing copy, a timer or an unsupported badge.
- Contradictory: another policy describes retaining the same data without explaining the difference.
Direct answers about “no logs”
Scroll horizontally to read all columns.
| Question | Answer |
|---|---|
| Does deleting an order page delete logs? | No conclusion follows. The interface, backend, support system, processor and backups may be different records. |
| Does an audit prove no logs forever? | No. It covers a defined system, time period and exclusions. A deployment or analytics change can alter later behaviour. |
| Does no logs remove the blockchain trail? | No. Public transaction data, timestamps, amounts and token events remain a separate record. |
| What should count as verified? | An identifiable, dated review that names systems, data types, retention, processors, exclusions and the current deployment. A badge or slogan is not enough. |
Sources & review
Editorial review: Sep 21, 2026. Source-specific dates and retrieval limits are stated where relevant. Issuer and service statements are attributed, not independently audited; a citation is not an endorsement.
- Ethereum · Block explorers (opens in a new tab)
Public transaction, token and account fields.