VpnHood!

The VpnHood! security audit

VpnHood! was reviewed by Include Security, in an engagement commissioned and paid for by the Open Technology Fund's Red Team Lab. The report was published in full, findings and all.

A shield with lines of code inside it, under a magnifying glass

Open source shows you the code. An audit means somebody read it.

A VPN carries everything you do online, so there is really only one question worth asking about one: who has checked it? Publishing the source answers half of that. The other half is whether anyone qualified has gone looking for the mistakes.

Reading code is not the same as auditing it

Anyone can open our repository, and we would rather they did. But finding a subtle flaw in a VPN protocol takes people who do it for a living, with paid time and a method behind them. That is what an audit buys.

A report, not a badge

Plenty of VPNs announce an audit and never publish it. Ours is a public document on the Open Technology Fund's site, findings and severities included, with our comments on each one beside it. You read the assessment, not a summary of it.

Paid for by someone with no stake in the result

The Open Technology Fund commissioned the engagement and paid for it. The firm doing the reviewing was not being paid by the people being reviewed, which is the part that makes a finding worth something.

Who did it, and who paid for it

Audited by Include Security (opens in new tab)

Auditor
Include Security
Commissioned by
The Open Technology Fund's Red Team Lab
Report
Published in full
Read the results on the Open Technology Fund (opens in new tab)