Read the source
The entire application is Apache-2.0 open source. The security-critical paths are documented in the threat model, and the code that implements them is on GitHub.
Security / Audit status
This is the page most security software would leave unwritten. An independent third-party audit of KalderaShield has not been performed. No audit badge on this site corresponds to a completed external review, and none will appear until one exists.
What exists today is automated, reproducible verification: 2204 unit tests across 248 files, a property-based fuzz gate over import parsing, backup envelopes and attachment metadata, mutation testing with Stryker, CodeQL analysis and OpenSSF Scorecard in CI, gitleaks secret scanning, and a dependency policy that fails on any high or critical npm advisory.
What does not exist is an external, independent expert review of the cryptographic design and implementation. Internal review reports document hundreds of findings and fixes, but they were written by the project itself. That is a different class of assurance and it is not presented as one.
The plan is an external audit: a draft scope document already exists, listing the components in scope — cryptography, vault persistence, the extension bridge, the Tauri IPC surface — so the work can start as soon as an auditor is engaged. No date is promised before a contract exists.
The entire application is Apache-2.0 open source. The security-critical paths are documented in the threat model, and the code that implements them is on GitHub.
The test suite, fuzz gate and release-hardening scans run locally with npm and cargo commands that are documented in the repository. Nothing about the pipeline is hidden.
Every release publishes SHA-256 checksums, and the updater bundles carry minisign signatures. The verification page gives the exact commands.
An unfinished audit marketed as an achievement is how trust products lose trust. The absence of an external audit is a real limitation: it means no independent expert has hunted for the flaw the automation misses. Stating it plainly lets you weigh the risk yourself, and gives the project a public commitment to be held to.
248 test files with coverage thresholds enforced at 90% lines and 80% branches; the measured baseline runs above them.
Property-based tests throw malformed JSON, CSV, KDF parameters and backup envelopes at the importer and crypto paths on every release run.
GitHub CodeQL analyzes the code weekly, OpenSSF Scorecard grades the supply chain, and gitleaks blocks committed secrets.
No. It means independent experts have not validated the design. The source is open, the automated gates are strict and public, and the threat model states its limits — you can evaluate all three yourself.
When an auditor is engaged. The scope document is published so the engagement can start immediately; promising a date without a contract would be another claim this site refuses to make.
Yes. The full report, or the auditor's own publication of it, will be linked from this page, including findings that are not yet fixed.