If you use a VPN, you are trusting them to have their act together. Some of them really miss the mark.
//
Hacked Data for 69K LimeVPN Users Up for Sale on Dark Web | Threatpost
https://threatpost.com/hacked-data-limevpn-dark-web/167492/
@BlueStateBabe
I would start with companies that pay for third-party audits of their systems, and publish those results, warts and all. The audit will only evaluate what the VPN company asks the auditor to look into, but it's way better than no audit at all.
TunnelBear was actually the first to do this. Mullvad (also mentioned in the article) is fairly well respected, and I believe a few CoSo members who know their infosec are customers.