As a security engineer that specializes in applied cryptography, I’m generally not interested in the “Tor vs VPN” debate. Audits are a type of engagement between a vendor and a team of security consultants with specific expertise in the technologies involved. It isn’t important that the company providing the audit be one of the more recognizable names (e.g., for cryptography: Cure53, Kudelski Security, Least Authority, NCC Group, Trail of Bits, and myriad blockchain / smart contract security firms that sometimes demonstrate real cryptography chops).