Security / Audit status

No independent audit has been completed yet

This is the page most security software would leave unwritten. An independent third-party audit of KalderaShield has not been performed. No audit badge on this site corresponds to a completed external review, and none will appear until one exists.

Where the claim stands

What is verified automatically, and by whom

What exists today is automated, reproducible verification: 2204 unit tests across 248 files, a property-based fuzz gate over import parsing, backup envelopes and attachment metadata, mutation testing with Stryker, CodeQL analysis and OpenSSF Scorecard in CI, gitleaks secret scanning, and a dependency policy that fails on any high or critical npm advisory.

What does not exist is an external, independent expert review of the cryptographic design and implementation. Internal review reports document hundreds of findings and fixes, but they were written by the project itself. That is a different class of assurance and it is not presented as one.

The plan is an external audit: a draft scope document already exists, listing the components in scope — cryptography, vault persistence, the extension bridge, the Tauri IPC surface — so the work can start as soon as an auditor is engaged. No date is promised before a contract exists.

The verification you can do without us

Read the source

The entire application is Apache-2.0 open source. The security-critical paths are documented in the threat model, and the code that implements them is on GitHub.

Run the gates yourself

The test suite, fuzz gate and release-hardening scans run locally with npm and cargo commands that are documented in the repository. Nothing about the pipeline is hidden.

Verify the artifact you install

Every release publishes SHA-256 checksums, and the updater bundles carry minisign signatures. The verification page gives the exact commands.

Security Architecture

Why we say this on a public page

Honesty is part of the design

An unfinished audit marketed as an achievement is how trust products lose trust. The absence of an external audit is a real limitation: it means no independent expert has hunted for the flaw the automation misses. Stating it plainly lets you weigh the risk yourself, and gives the project a public commitment to be held to.

2204 test

Unit suite

248 test files with coverage thresholds enforced at 90% lines and 80% branches; the measured baseline runs above them.

fast-check

Fuzz gate

Property-based tests throw malformed JSON, CSV, KDF parameters and backup envelopes at the importer and crypto paths on every release run.

CodeQL + Scorecard

CI analysis

GitHub CodeQL analyzes the code weekly, OpenSSF Scorecard grades the supply chain, and gitleaks blocks committed secrets.

Frequently Asked Questions

About the audit status

Does "no audit" mean the app is insecure?

No. It means independent experts have not validated the design. The source is open, the automated gates are strict and public, and the threat model states its limits — you can evaluate all three yourself.

When will an external audit happen?

When an auditor is engaged. The scope document is published so the engagement can start immediately; promising a date without a contract would be another claim this site refuses to make.

Will you show the audit results?

Yes. The full report, or the auditor's own publication of it, will be linked from this page, including findings that are not yet fixed.

Related pages

Download Installer