CipherVPN undergoes independent penetration testing and security reviews on a scheduled basis. Executive summaries of completed audits are published here. Full reports are available to enterprise customers under NDA.
Transparency commitment: We publish executive summaries in the calendar year following each test. Findings marked Critical or High are remediated before the next product release and noted with their resolution date in the summary.
Full infrastructure penetration test of the WireGuard® server fleet, control plane APIs, key management systems and client update delivery pipeline across all production regions. Scope included network segmentation, authentication bypass attempts and WireGuard handshake verification.
Deep-dive cryptographic audit of the CipherMail end-to-end encryption implementation including key generation, storage, exchange protocols, and the JavaScript/WebAssembly OpenPGP layer used in the web client. Scope included PGP key management, session encryption and metadata minimisation.
Full web application penetration test covering the CipherVPN dashboard, REST API surface, authentication flows (including MFA), session management, CORS policy, Content Security Policy, and all user-facing endpoints. Mobile API endpoints were included in scope.
Independent verification engagement to confirm no user-identifiable connection logs, metadata logs or traffic data are retained on the CipherVPN infrastructure. Auditors were provided unannounced access to production servers and infrastructure logs.
Assessment of the server network topology, firewall rule sets, DDoS mitigation configuration, BGP routing security, DNS infrastructure and IP leak prevention mechanisms across all 47 server locations.
Security review of the CipherVPN native client applications for Windows, macOS, iOS and Android. Scope included local privilege escalation, IPC security, certificate pinning, auto-update security, and WireGuard configuration file handling.
The following audits are planned or currently in progress. Executive summaries will be published within 90 days of completion.
Comprehensive review of all zero-knowledge cryptographic claims across VPN key handling, mail encryption, account recovery flows and the password manager module. This audit will assess whether data held by Velocity is computationally inaccessible under real-world adversarial conditions.
We select auditors independently without financial incentives tied to outcomes. All firms engaged are internationally recognised security research organisations with no prior or ongoing commercial relationship with Velocity beyond the audit engagement.
| Firm | Specialisation | Engagements | Website |
|---|---|---|---|
| Cure53 | Cryptography, web application security, open-source audits | 3 | cure53.de |
| NCC Group | Infrastructure security, network penetration testing | 2 | nccgroup.com |
| Bishop Fox | Red team operations, web application & API security | 2 | bishopfox.com |
| Nettitude Group | Infrastructure penetration testing, CREST-certified | 2 | nettitude.com |
| Deloitte Cyber | Compliance verification, no-log policy attestation | 1 | deloitte.com |
| Rotating pool | Remaining engagements to be announced | 2 | — |
Full penetration test reports contain sensitive technical detail about our infrastructure and remediated vulnerabilities. To prevent this information from being used maliciously, full reports are provided only to enterprise customers under a mutual NDA.
Enterprise customers: Contact your account manager or email enterprise@ciphervpn.eu to request a full report package for any listed audit. We typically respond within 2 business days.
Researchers & press: Academic researchers and journalists may request redacted versions for reporting purposes. Contact press@ciphervpn.eu with your organisation and intended use.
We commit to the following minimum audit schedule:
We also operate a continuous vulnerability disclosure programme. If you discover a security issue, please report it following the process described on our Security Policy page.