{
  "schemaVersion": "1.0",
  "status": "scope-limited-public-distribution-assessment",
  "provider": "VPN Cat",
  "testedProductIdentity": {
    "appStoreId": "1134784923",
    "trackName": "VPN cat: Fast Secure Unlimited",
    "version": "2.12.5",
    "bundleId": "com.vpn.cat",
    "seller": "SAFDAR NETWORK SMC-PRIVATE LIMITED",
    "minimumIosVersion": "15.0",
    "currentVersionReleaseDate": "2026-03-18T14:39:46Z"
  },
  "testDate": "2026-07-29",
  "reviewTeam": "Openscore VPN",
  "verificationPlatform": "VPNTestor",
  "sources": {
    "website": "https://www.vpncat.net/",
    "privacyPolicy": "https://www.vpncat.net/privacy/com.vpn.cat.html",
    "terms": "https://www.vpncat.net/terms-of-service/com.vpn.cat.html",
    "appStore": "https://apps.apple.com/us/app/vpn-cat-fast-secure-unlimited/id1134784923",
    "appleLookupApi": "https://itunes.apple.com/lookup?id=1134784923&country=us"
  },
  "verified": [
    "The first-party website links to Apple App Store item 1134784923.",
    "The App Store seller and the company named by the website are SAFDAR NETWORK SMC-PRIVATE LIMITED.",
    "Apple's lookup response identifies version 2.12.5, bundle ID com.vpn.cat, iOS 15.0 minimum and a 18 March 2026 release date.",
    "The website, privacy policy and terms were reachable over HTTPS on the assessment date.",
    "The privacy policy discloses Google Mobile Ads SDK collection, and Apple's privacy label lists developer-declared data categories."
  ],
  "findings": [
    {
      "id": "VCAT-2026-001",
      "severity": "high",
      "title": "No independently retrievable application artifact",
      "evidence": "The first-party site links only to the Apple App Store. Apple exposes listing metadata but not an unauthenticated IPA download suitable for reproducible hashing and static inspection.",
      "impact": "VPNTestor could not independently inspect the exact binary, signature chain, entitlements, embedded SDKs, permissions, network-security settings, dependency versions or update behavior.",
      "recommendation": "Publish a versioned, signed assessment copy or reproducible artifact manifest with SHA-256, expected signing identity, entitlements and a software bill of materials."
    },
    {
      "id": "VCAT-2026-002",
      "severity": "medium",
      "title": "Zero-log wording conflicts with disclosed usage and advertising data collection",
      "evidence": "The policy says IP is discarded after a VPN session, but separately defines Usage Data as IP addresses, device information and access times and says Google Mobile Ads may collect IP address, device ID, advertising data and user interactions.",
      "impact": "Readers cannot determine which data flows are limited to the VPN connection, which are handled by advertising SDKs, or the retention periods for usage and advertising data.",
      "recommendation": "Publish a data-flow and retention table separating VPN control-plane data, tunnel traffic, website analytics, advertising SDK data, account data and support records."
    },
    {
      "id": "VCAT-2026-003",
      "severity": "medium",
      "title": "Registration statements are inconsistent",
      "evidence": "The App Store description says no registration is required, while the terms state users must register and submit personally identifiable information and the privacy policy describes registration data.",
      "impact": "Account requirements and the circumstances in which name, email and payment data are collected are unclear.",
      "recommendation": "Align the App Store description, terms and policy by documenting free, paid and account-recovery flows separately."
    },
    {
      "id": "VCAT-2026-004",
      "severity": "medium",
      "title": "No public independent security or no-logs audit",
      "evidence": "No auditor, audit date, tested version, scope, signed report or substantive assessment statement was located on the reviewed first-party pages.",
      "impact": "Backend logging, server configuration, access controls and operational claims cannot receive audit-grade verification.",
      "recommendation": "Commission and publish an independent assessment with scope, versions, exclusions, test dates, findings and remediation status."
    },
    {
      "id": "VCAT-2026-005",
      "severity": "informational",
      "title": "Protocol and security-control documentation is absent",
      "evidence": "The App Store description refers to an advanced proprietary VPN protocol, but the reviewed public pages do not document protocol versions, cryptographic suites, kill-switch behavior, DNS handling, IPv6 behavior or update-chain controls.",
      "impact": "The security-critical connection design cannot be independently evaluated from public documentation.",
      "recommendation": "Publish a technical security model and platform-specific control matrix."
    }
  ],
  "score": {
    "finalOverallVpnScore": null,
    "publicDistributionAssessmentScore": 34,
    "scale": 100,
    "breakdown": [
      {
        "category": "Artifact integrity and provenance",
        "earned": 14,
        "available": 30,
        "rationale": "The official App Store identity, seller, bundle ID and version are reproducible, but the exact IPA, first-party checksum and release manifest are unavailable."
      },
      {
        "category": "Platform signing and binary assurance",
        "earned": 10,
        "available": 30,
        "rationale": "App Store distribution provides a platform gate, but VPNTestor could not retrieve the binary to verify its signature, entitlements, embedded frameworks or hardening."
      },
      {
        "category": "Privacy and security surface",
        "earned": 6,
        "available": 20,
        "rationale": "Developer-declared privacy categories and ad-SDK collection are disclosed, but permissions, runtime traffic, leaks, local storage and control behavior were not testable; policy wording is internally inconsistent."
      },
      {
        "category": "Public security transparency",
        "earned": 4,
        "available": 20,
        "rationale": "Legal and privacy pages are public. No independent audit, source code, protocol specification, permission inventory, SBOM, checksum or remediation record was found."
      }
    ]
  },
  "notTested": [
    "Application binary signature, entitlements, permissions, dependencies and embedded SDK inventory",
    "Installation, account lifecycle and local credential storage",
    "IPv4, IPv6, DNS, WebRTC and route leakage",
    "Kill Switch behavior during server interruption, process termination, sleep/wake and network switching",
    "Update-channel authenticity and rollback resistance",
    "Server ownership, logging, retention and infrastructure access controls",
    "Streaming access, sustained performance, latency and reliability"
  ],
  "limitations": [
    "This is a public-source and App Store metadata assessment, not a source-code audit, penetration test or no-logs infrastructure audit.",
    "Apple states that the App Store privacy information is supplied by the developer and is not verified by Apple.",
    "The result applies to the public record for version 2.12.5 on 29 July 2026.",
    "34/100 is a score for the completed public-distribution assessment scope, not VPN Cat's overall VPN product score."
  ]
}
