Audits — Internal, Independent, Scoped

Veyrnox labels every audit honestly. Two audits are complete — both internal. An independent third-party audit is next.

The Strix automated white-box pentest (completed 2026-08-28) was a white-box code review of ~200k LOC across iOS, Android, and web, plus Cloudflare Pages Functions and Supabase Edge Functions. 14 findings confirmed (3 High, 9 Medium, 2 Low, 0 Critical), all remediated; the security score was restored to 100/100.

Internal design reviews cover the Shamir backup and coercion-resistance threat model. No audit is labelled “independent” unless a third party performed it.

Full technical report available under NDA — email security@veyrnox.com.