Security Audit Reports — CipherVPN
Security Audit Reports

Third-Party Security Audits

CipherVPN undergoes independent penetration testing and security reviews on a scheduled basis. Executive summaries of completed audits are published here. Full reports are available to enterprise customers under NDA.

12
Audits completed
4
Independent firms
0
Critical findings open
100%
Findings remediated

Transparency commitment: We publish executive summaries in the calendar year following each test. Findings marked Critical or High are remediated before the next product release and noted with their resolution date in the summary.

2025 Audit Cycle

VPN Infrastructure Penetration Test — Q3 2025 Published
Conducted: Aug–Sep 2025 · Published: Nov 2025 · Auditor: Nettitude Group

Full infrastructure penetration test of the WireGuard® server fleet, control plane APIs, key management systems and client update delivery pipeline across all production regions. Scope included network segmentation, authentication bypass attempts and WireGuard handshake verification.

Critical: 0 High: 1 (resolved 2025-09-18) Medium: 3 (all resolved) Low/Info: 8
CipherMail Cryptographic Review — Q2 2025 Published
Conducted: May 2025 · Published: Jul 2025 · Auditor: Cure53

Deep-dive cryptographic audit of the CipherMail end-to-end encryption implementation including key generation, storage, exchange protocols, and the JavaScript/WebAssembly OpenPGP layer used in the web client. Scope included PGP key management, session encryption and metadata minimisation.

Critical: 0 High: 0 Medium: 2 (all resolved) Low/Info: 5
Web Application & API Security Audit — Q1 2025 Published
Conducted: Jan–Feb 2025 · Published: Apr 2025 · Auditor: Bishop Fox

Full web application penetration test covering the CipherVPN dashboard, REST API surface, authentication flows (including MFA), session management, CORS policy, Content Security Policy, and all user-facing endpoints. Mobile API endpoints were included in scope.

Critical: 0 High: 2 (resolved 2025-02-28) Medium: 4 (all resolved) Low/Info: 11

2024 Audit Cycle

No-Log Policy Independent Verification — 2024 Published
Conducted: Oct 2024 · Published: Dec 2024 · Auditor: Deloitte Cyber

Independent verification engagement to confirm no user-identifiable connection logs, metadata logs or traffic data are retained on the CipherVPN infrastructure. Auditors were provided unannounced access to production servers and infrastructure logs.

No logging violations: Confirmed Verdict: Pass
Network Infrastructure Security Review — Q2 2024 Published
Conducted: Jun 2024 · Published: Aug 2024 · Auditor: NCC Group

Assessment of the server network topology, firewall rule sets, DDoS mitigation configuration, BGP routing security, DNS infrastructure and IP leak prevention mechanisms across all 47 server locations.

Critical: 0 High: 0 Medium: 5 (all resolved) Low/Info: 9
Client Applications Security Audit — Q1 2024 Published
Conducted: Feb 2024 · Published: Apr 2024 · Auditor: Cure53

Security review of the CipherVPN native client applications for Windows, macOS, iOS and Android. Scope included local privilege escalation, IPC security, certificate pinning, auto-update security, and WireGuard configuration file handling.

Critical: 0 High: 1 (resolved 2024-03-04) Medium: 3 (all resolved) Low/Info: 14

Scheduled Audits

The following audits are planned or currently in progress. Executive summaries will be published within 90 days of completion.

Zero-Knowledge Architecture Review — Q1 2026 In Progress
Scheduled: Jan–Mar 2026 · Auditor: Cure53 · Expected publish: Jun 2026

Comprehensive review of all zero-knowledge cryptographic claims across VPN key handling, mail encryption, account recovery flows and the password manager module. This audit will assess whether data held by Velocity is computationally inaccessible under real-world adversarial conditions.

Report pending — results published upon completion
Pending

Auditing Firms

We select auditors independently without financial incentives tied to outcomes. All firms engaged are internationally recognised security research organisations with no prior or ongoing commercial relationship with Velocity beyond the audit engagement.

Firm Specialisation Engagements Website
Cure53 Cryptography, web application security, open-source audits 3 cure53.de
NCC Group Infrastructure security, network penetration testing 2 nccgroup.com
Bishop Fox Red team operations, web application & API security 2 bishopfox.com
Nettitude Group Infrastructure penetration testing, CREST-certified 2 nettitude.com
Deloitte Cyber Compliance verification, no-log policy attestation 1 deloitte.com
Rotating pool Remaining engagements to be announced 2

Requesting Full Reports

Full penetration test reports contain sensitive technical detail about our infrastructure and remediated vulnerabilities. To prevent this information from being used maliciously, full reports are provided only to enterprise customers under a mutual NDA.

Enterprise customers: Contact your account manager or email enterprise@ciphervpn.eu to request a full report package for any listed audit. We typically respond within 2 business days.

What is included in full reports

  • Complete finding descriptions with reproduction steps
  • Proof-of-concept exploit code (where applicable)
  • Detailed remediation notes with commit references
  • Auditor methodology and testing scope documentation
  • Risk scoring using CVSS v3.1
  • Post-remediation retest results

Researchers & press: Academic researchers and journalists may request redacted versions for reporting purposes. Contact press@ciphervpn.eu with your organisation and intended use.

Our Audit Commitment

We commit to the following minimum audit schedule:

  • Annual — Full infrastructure and web application penetration test
  • Annual — Independent no-log policy verification
  • Every 18 months — Cryptographic protocol review
  • Per major release — Security review of new client applications or protocols
  • On demand — Targeted review following significant architectural changes

We also operate a continuous vulnerability disclosure programme. If you discover a security issue, please report it following the process described on our Security Policy page.