Skip to main content

Has Standard Notes completed a third-party security audit?

We have completed three (3) security audits to date by industry-leading security firms, which cover the entirety of our ecosystem. You can review the results below.

Client-side Protocol and Encryption Security Assessment#

This audit covers the entirety of our shared client-side framework for encrypting and syncing data, and covers our usage of industry-leading algorithms like Argon2 and XChaCha20-Poly1305.

Conducted by Trail of Bits, New York, in 2020.

View Report

Full Ecosystem Penetration Test#

This extensive audit covered the entirety of our ecosystem, both client-side and server-side, with the aim of penetrating the code and executables to achieve unintended effects and discover latent vulnerabilities. We're happy to report that 100% of the issues found were promptly resolved.

Conducted by Cure53, Berlin, in 2020.

View Report

Cryptography Design Review#

This early audit helped ensure our initial client-side encryption and server-side communication systems were built correctly and strongly.

Conducted by Shackle Labs, United States, in 2017.

View Report

Last updated on