Audits
Audits — labelled, dated, scoped.
Every security review Veyrnox has run is listed here, labelled INTERNAL, PENTEST, or INDEPENDENT. Internal reviews are not independent audits; an automated pentest is not a manual audit — both are documented for transparency, not presented as proof. A manual independent audit is next.
Two internal reviews and one automated third-party pentest complete — 14 findings, all remediated. No manual independent audit has been engaged yet. Every entry here is labelled INTERNAL, PENTEST, or INDEPENDENT — the word "audited" is never used without that label.
Threat model of seedless recovery
INTERNAL- Auditor
- Veyrnox Engineering (internal)
- Date
- 2026 — ongoing
- Scope
- Threat model for Shamir-sharded seedless recovery: shard storage in the device secure enclave and the user's personal cloud account, the reconstruction flow, and the guarantee that Veyrnox holds no shard.
- Methodology
- Internal design review against the documented threat model.
- Findings
- Documented in the public security model. No shard is held by Veyrnox; the seed is never presented as text the user must re-enter.
- Remediation
- Ongoing — feeds into the independent audit scope.
- Evidence
- Security model ↗
Key binding and secure storage review
INTERNAL- Auditor
- Veyrnox Engineering (internal)
- Date
- 2026 — ongoing
- Scope
- Hardware-bound key operations (Secure Enclave on iOS, StrongBox on Android), shard encryption at rest, and biometric gating of signing.
- Methodology
- Internal code review of the key management and storage layer.
- Findings
- Keys are generated and sealed on-device; the backend is untrusted by design and never receives key material.
- Remediation
- Ongoing — findings tracked for the independent audit.
- Evidence
- Secure Enclave glossary ↗
Strix automated white-box pentest
PENTEST- Auditor
- Strix (app.strix.ai) — automated third party
- Date
- 2026-08-28
- Scope
- White-box code review of ~200k LOC across iOS, Android, and web, plus Cloudflare Pages Functions and Supabase Edge Functions — covering authentication, key management, signing gates, the deniability boundary, and WalletConnect paths.
- Methodology
- Automated static + dynamic pentest with proof-of-concept reproduction per finding.
- Findings
- 14 confirmed vulnerabilities — 0 Critical, 3 High, 9 Medium, 2 Low. All 14 remediated in the working tree; security score restored to 100.0/100.
- Remediation
- Complete — all 14 findings fixed and verified by re-scan.
- Evidence
- Full report under NDA — email security@veyrnox.com ↗
Audits in progress
Independent third-party security audit
INDEPENDENT- Auditor
- Not engaged yet
- Date
- Scoping — not started
- Scope
- Full wallet security audit covering cryptography, key management, the network layer (including the decoy session boundary), and coercion resistance.
- Methodology
- To be defined with the selected firm.
- Status
- Scoping in progress. No firm contracted yet.
When the independent audit is engaged, its auditor, scope, and timeline will appear here. See feature status →