Audits

Audits — labelled, dated, scoped.

Every security review Veyrnox has run is listed here, labelled INTERNAL, PENTEST, or INDEPENDENT. Internal reviews are not independent audits; an automated pentest is not a manual audit — both are documented for transparency, not presented as proof. A manual independent audit is next.

Two internal reviews and one automated third-party pentest complete — 14 findings, all remediated. No manual independent audit has been engaged yet. Every entry here is labelled INTERNAL, PENTEST, or INDEPENDENT — the word "audited" is never used without that label.

Threat model of seedless recovery

INTERNAL
Auditor
Veyrnox Engineering (internal)
Date
2026 — ongoing
Scope
Threat model for Shamir-sharded seedless recovery: shard storage in the device secure enclave and the user's personal cloud account, the reconstruction flow, and the guarantee that Veyrnox holds no shard.
Methodology
Internal design review against the documented threat model.
Findings
Documented in the public security model. No shard is held by Veyrnox; the seed is never presented as text the user must re-enter.
Remediation
Ongoing — feeds into the independent audit scope.
Evidence
Security model ↗

Key binding and secure storage review

INTERNAL
Auditor
Veyrnox Engineering (internal)
Date
2026 — ongoing
Scope
Hardware-bound key operations (Secure Enclave on iOS, StrongBox on Android), shard encryption at rest, and biometric gating of signing.
Methodology
Internal code review of the key management and storage layer.
Findings
Keys are generated and sealed on-device; the backend is untrusted by design and never receives key material.
Remediation
Ongoing — findings tracked for the independent audit.
Evidence
Secure Enclave glossary ↗

Strix automated white-box pentest

PENTEST
Auditor
Strix (app.strix.ai) — automated third party
Date
2026-08-28
Scope
White-box code review of ~200k LOC across iOS, Android, and web, plus Cloudflare Pages Functions and Supabase Edge Functions — covering authentication, key management, signing gates, the deniability boundary, and WalletConnect paths.
Methodology
Automated static + dynamic pentest with proof-of-concept reproduction per finding.
Findings
14 confirmed vulnerabilities — 0 Critical, 3 High, 9 Medium, 2 Low. All 14 remediated in the working tree; security score restored to 100.0/100.
Remediation
Complete — all 14 findings fixed and verified by re-scan.
Evidence
Full report under NDA — email security@veyrnox.com ↗

Audits in progress

Independent third-party security audit

INDEPENDENT
Auditor
Not engaged yet
Date
Scoping — not started
Scope
Full wallet security audit covering cryptography, key management, the network layer (including the decoy session boundary), and coercion resistance.
Methodology
To be defined with the selected firm.
Status
Scoping in progress. No firm contracted yet.

When the independent audit is engaged, its auditor, scope, and timeline will appear here. See feature status →