NordVPN had the clients audited by VerSprite last year, and their No-log policy audited by PwC in 2018 and 2020. And a bug bounty program on HackerOne. [1]
ExpressVPN - Windows Client was just audited by F-Secure in March, and server side audits by Cure54, and PwC in 2021 and 2019 respectively. And a bug bounty program on Bug Crowd. [2]
---
For comparison
Mullvad has been audited (Client security and Infrastructure (for privacy)) by Cure53 through 2020, and first was in 2018. Has no bug bounty, but they do still have a vulnerability disclosure program. [3]
ProtonVPN, audits of the no-log policy in April, and clients in 2020. And they run their own bug bounty program.[4]
---
I actually find it kinda interesting that while they've all had audits regarding privacy on the server side, only ExpressVPN has had a security audit of server side components. (Granted I've not look that deeply at this)
[1] Annoying, you can only download the audit reports if you Login then click Reports in the menu
[2] https://www.expressvpn.com/blog/?s=audit
The actual use of VPN technology is to create virtual networks that are private (hence the name). It's a system level technology. There are several types of network topologies you can set up, when I was learning about this I found this article which is quite nice: https://www.procustodibus.com/blog/2020/10/wireguard-topolog.... You can proxy traffic through a VPN, but the only scenario I can think of in which it makes sense is if you are an OSINT researcher and you need a safe system on which to conduct your research.
If you need to proxy traffic and "hide" your IP, just use a flipping proxy. It's an application level technology (e.g. for torrenting, every torrent client under the sun supports a SOCKS5 proxy). If you don't have the patience to set up a VPS yourself, you can even use something like Outline (https://getoutline.org) which automates that (and it has a mobile client app as well).
If you need privacy (and to actually hide your IP), then use Tor.
I think the reason why the method you mention isn't commonly used is that it is complicated to understand/set up and hard to verify.
I've seen more advanced users encapsulate everything in a VM so that non-VPN traffic can be blocked globally by the OS.
Ironically (I hope?), Mullvad is by far the one I see pushed the most.