TrojanAudits
Tested by people
paid to break us.
Every year we hire independent firms to attack our apps, servers and claims, then publish what they found without edits. Here is every report.
Reports
Every finding,
every fix.
- 07Infrastructure and no log verificationPassedSecuritum, June 2026. Random node sampling with root access across 12 cities. Confirmed RAM-only operation and absence of user logs. 2 low findings, both fixed.
- 06Trojan protocol cryptographic reviewPassedCure53, January 2026. Review of the obfuscation layer and handshake. 1 medium finding regarding timing side channel, fixed in v4.1.
- 05Desktop and mobile appsPassedCure53, July 2025. Full source review of macOS, Windows, Linux, iOS and Android clients. 4 low findings, all fixed.
- 04No log policy verificationPassedDeloitte, February 2025. Assurance engagement on the no log claim against ISAE 3000.
- 03Browser extensionsPassedRadically Open Security, September 2024. 1 medium finding in WebRTC handling, fixed.
- 02InfrastructurePassedCure53, March 2024. First fleet-wide review after RAM-only rollout.
- 01Initial application auditPassedCure53, August 2022. 9 findings including 1 high in the kill switch, fixed before public launch.
"A claim you cannot verify is a rumour. We publish so you never have to take our word."
Tomas Brenner, head of security