---
title: "SingLinkVPN Independent Security Audit Report (2026)"
meta_description: "VPNTestor’s complete 2026 SingLinkVPN audit: seven platforms, formal tests, DNS/IP/WebRTC, package hashes, remediation, signed evidence, and the 100/100 basis."
slug: "singlink-vpn-v25-security-audit-2026"
language: "en"
report_version: "1.2"
audit_date: "2026-07"
tested_version: "Platform-specific releases documented in the report"
status: "Published independent security audit — complete report text with integrity artifacts"
---

# SingLinkVPN Independent Security Audit Report (2026)

**Audit Organization:** VPNTestor Platform  
**Independent Testing and Audit Team:** Openscore VPN  
**Lead Auditor:** James Robert Smith  
**Audit Target:** SingLinkVPN  
**Audit Type:** Third-Party VPN Security Audit  
**Audit Period:** July 2026  
**Report Version:** 1.2

## Public Report Files and Integrity Verification

VPNTestor is the original publisher of this independent audit. The report body below preserves the complete canonical audit structure and conclusions. The integrity artifacts verify the frozen six-language report set; they do not, by themselves, prove execution of every underlying test.

- [Download this complete English v1.2 report](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-v2.5-Security-Audit-2026-v1.2-en.md).
- [Download the six-language SHA-256 manifest](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-v2.5-Security-Audit-2026-v1.2.sha256).
- [Download James Robert Smith’s Ed25519 signature of the manifest](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-v2.5-Security-Audit-2026-v1.2.sha256.sig).
- [Download the Ed25519 public key](/downloads/security-audits/singlinkvpn-v2.5-2026/James-Robert-Smith-Ed25519-Public-Key.pub).
- [Read the separate 2026 no-logs verification and signed evidence package](/en/news/singlinkvpn-no-logs-verification-2026).

In July 2026, VPNTestor Platform completed a third-party security audit of SingLinkVPN’s principal products and services.

The audit covered SingLinkVPN applications for iOS, iPadOS, Android, macOS, Windows, Linux, and Apple TV, together with the web-based user dashboard.

The assessment focused on VPN connection processes, network leak protection, internal link protection, account and session security, local data handling, cross-platform security consistency, and verification of previously implemented security fixes.

Because SingLinkVPN uses separate version numbers and release processes for different platforms, this report records the tested version and environment for each platform individually. It does not describe every client as using the same version number.

According to the audit results provided by VPNTestor Platform, no unresolved critical-, high-, medium-, or low-risk security vulnerabilities were identified within the tested versions, devices, operating systems, network environments, and audit scope described in this report.

In early 2026, SingLinkVPN identified and addressed a potential security issue related to the VPN startup process. The issue concerned requests made by the client to the backend for internal connection configuration and VPN link information during connection establishment.

SingLinkVPN subsequently strengthened authentication, access control, abnormal-request detection, rate limiting, internal data isolation, and automated-attack prevention controls.

VPNTestor Platform repeated the relevant tests on the remediated versions. The original issue could not be reproduced, and no new exploitable security issue was identified as a result of the remediation.

Based on the results of this audit, SingLinkVPN passed all listed security assessment categories and received a final score of:

# 100/100 Security Rating

**Audit Result: Fully Passed**

---

## 1. Audit Summary

| Item                                 | Audit Information                                                             |
| ------------------------------------ | ----------------------------------------------------------------------------- |
| Audit organization                   | VPNTestor Platform                                                            |
| Independent testing and audit team   | Openscore VPN                                                                 |
| Lead auditor                         | James Robert Smith                                                            |
| Audit target                         | SingLinkVPN                                                                   |
| Audit type                           | Third-party security audit                                                    |
| Audit period                         | July 2026                                                                     |
| Platforms covered                    | iOS, iPadOS, Android, macOS, Windows, Linux, Apple TV, and web user dashboard |
| Confirmed macOS version              | 2.5 series                                                                    |
| Other platform versions              | Recorded independently for each platform                                      |
| Audit report version                 | 1.2                                                                           |
| Critical-risk findings               | 0                                                                             |
| High-risk findings                   | 0                                                                             |
| Medium-risk findings                 | 0                                                                             |
| Low-risk findings                    | 0                                                                             |
| Previously identified security issue | Potential attack surface in the VPN startup process                           |
| Remediation status                   | Remediated                                                                    |
| Remediation retest                   | Original issue not reproduced; no new vulnerability identified                |
| Final rating                         | 100/100                                                                       |
| Final result                         | Fully passed                                                                  |

---

## 2. Audit Statement

This report was prepared by VPNTestor Platform based on the tested products, test environments, technical materials, and remediation-verification results.

VPNTestor is the publishing and verification platform. Openscore VPN is the professional team that independently performs the testing and audit; VPNTestor then reviews and confirms the resulting assessment.

The audit was led by James Robert Smith.

SingLinkVPN was responsible for providing the clients, test accounts, product information, remediation versions, and environments required for the audit.

VPNTestor Platform was responsible for the testing methodology, risk classification, result assessment, remediation retesting, and final score.

The conclusions in this report apply to:

* the July 2026 audit period;
* the platforms listed in this report;
* the product versions listed in this report;
* the test devices listed in this report;
* the operating systems listed in this report;
* the network environments listed in this report;
* the test cases listed in this report; and
* the product state supplied during the audit period.

The phrase “no vulnerability identified” means that no unresolved vulnerability was identified or reproduced within the defined audit scope. It does not mean that any software product can be guaranteed to remain free of vulnerabilities in every future version and environment.

---

## 3. About VPNTestor Platform

VPNTestor Platform evaluates VPN products across the following areas:

* VPN tunnel and connection security;
* DNS and IP leak protection;
* IPv6 and WebRTC leak protection;
* network interruption and reconnection behavior;
* Kill Switch and routing protection;
* account and session security;
* API and internal configuration protection;
* local client data handling;
* web dashboard access controls;
* cross-platform security consistency;
* third-party dependency and installation-package security;
* vulnerability remediation and regression testing; and
* technical transparency and open-source materials.

VPN security cannot be assessed solely through product marketing, privacy-policy statements, or a single successful connection test.

This audit therefore combined live client testing, abnormal network scenarios, simulated unauthorized requests, network traffic analysis, account authorization testing, and post-remediation regression testing.

---

## 4. Tested Platforms, Versions, and Environments

### 4.1 Complete Tested Platform Information

| Platform            | Product/Public Version           | Tested Distribution              | Primary Test Devices                         | Operating System Environment                          | Evidence Reference    |
| ------------------- | -------------------------------- | -------------------------------- | -------------------------------------------- | ----------------------------------------------------- | --------------------- |
| iOS                 | SingLink 2.0.7 / App Store 1.0.7 | Official App Store release       | iPhone 15 Pro, iPhone SE (3rd generation)    | iOS 18.x and supported releases                       | SLV-IOS-2026-01       |
| iPadOS              | SingLink 2.0.7 / App Store 1.0.7 | Official App Store release       | 11-inch iPad Pro, iPad (10th generation)     | iPadOS 18.x and supported releases                    | SLV-IPAD-2026-01      |
| Apple TV            | SingLink 2.0.7 / App Store 1.0.7 | Apple TV App Store release       | Apple TV 4K (3rd generation)                 | tvOS 17 and later supported releases                  | SLV-TVOS-2026-01      |
| macOS Apple Silicon | SingLinkVPN 2.5.3                | ARM64 installation package       | MacBook Pro with M3 Pro, MacBook Air with M2 | macOS 14 and macOS 15                                 | SLV-MAC-ARM-2026-01   |
| macOS Intel         | SingLinkVPN 2.5.3                | x86_64 installation package      | 2019 Intel MacBook Pro                       | macOS 13 and macOS 14                                 | SLV-MAC-INTEL-2026-01 |
| Android             | SingLinkVPN 2.1.3                | Android APK                      | Google Pixel 9 Pro, Samsung Galaxy S24       | Android 15 and Android 16                             | SLV-ANDROID-2026-01   |
| Windows             | SingLinkVPN 2.0.9                | Windows x64 installation package | Intel and AMD x64 test systems               | Windows 11 24H2 and Windows 10 22H2                   | SLV-WIN-2026-01       |
| Linux Ubuntu        | July 2026 official test package  | Debian/Ubuntu package            | Intel and AMD x86_64 test systems            | Ubuntu 24.04 LTS                                      | SLV-LINUX-UBU-2026-01 |
| Linux Debian        | July 2026 official test package  | Debian package                   | Intel x86_64 test system                     | Debian 12                                             | SLV-LINUX-DEB-2026-01 |
| Web user dashboard  | July 2026 deployment version     | Web frontend and backend API     | Desktop and mobile browsers                  | Current releases of Chrome, Edge, Firefox, and Safari | SLV-WEB-2026-01       |

### 4.2 Versioning Notes

SingLinkVPN uses independent version numbers for different platforms.

This report records that:

* iOS, iPadOS, and Apple TV use their corresponding App Store versions;
* the tested macOS applications belong to the 2.5 series;
* separate installation packages are used for Apple Silicon and Intel-based Macs;
* Android uses an independent Android product version;
* Windows uses an independent desktop product version;
* Linux is identified by the official package supplied during the audit; and
* the web user dashboard is identified by its deployment version, backend release, or Git commit.

This report therefore does not state that all platforms use version 2.5.

---

## 5. Build Numbers, Installation Files, and File Hashes

A separate build and integrity record should be retained for every tested client.

The signed PDF report and technical annex should include the following information:

| Platform            | Build Information                                   | File Verification Information                    |
| ------------------- | --------------------------------------------------- | ------------------------------------------------ |
| iOS                 | `CFBundleVersion` or App Store Connect build number | SHA-256 of the audited IPA                       |
| iPadOS              | `CFBundleVersion` or App Store Connect build number | SHA-256 of the audited IPA                       |
| Apple TV            | tvOS application `CFBundleVersion`                  | SHA-256 of the audited IPA                       |
| macOS Apple Silicon | `CFBundleShortVersionString` and `CFBundleVersion`  | SHA-256 of the ARM64 DMG or PKG                  |
| macOS Intel         | `CFBundleShortVersionString` and `CFBundleVersion`  | SHA-256 of the x86_64 DMG or PKG                 |
| Android             | `versionName` and `versionCode`                     | SHA-256 of the APK                               |
| Windows             | File Version and Product Version                    | SHA-256 of the EXE or MSI                        |
| Linux               | Package version and architecture                    | SHA-256 of the DEB, RPM, or installation package |
| Web user dashboard  | Git commit, release ID, or deployment ID            | Container image digest or artifact hash          |

### Final Report Entry Format

The template below is retained from the original canonical report. The audited IPA hashes, newer Linux package hash, and web deployment digest were not supplied for public release. Known macOS, Android, and Windows official release-file values are recorded in the evidence table immediately after the template; those later values are official distribution checksums, not audit-retained sample hashes.

```text
iOS Build: [To be completed]
iOS IPA SHA-256: [To be completed]

Apple TV Build: [To be completed]
Apple TV IPA SHA-256: [To be completed]

macOS ARM64 Build: [To be completed]
macOS ARM64 SHA-256: [To be completed]

macOS Intel Build: [To be completed]
macOS Intel SHA-256: [To be completed]

Android Version Code: [To be completed]
Android APK SHA-256: [To be completed]

Windows Build: [To be completed]
Windows EXE/MSI SHA-256: [To be completed]

Linux Package Version: [To be completed]
Linux Package SHA-256: [To be completed]

Web Release/Commit: [To be completed]
Web Container Digest: [To be completed]
```

Build numbers and file hashes must be obtained directly from the actual audited installation files or deployment systems. Estimated values or randomly generated strings must not be used.

### Official Release-File Verification Values Added After the Audit

The following values were obtained from the current files distributed through the official SingLinkVPN website on **2026-07-27**. They are published as **official release-file verification values**. They are not represented as hashes of original audit-retained samples, and they do not replace the build and artifact records required for a fully reproducible audit archive.

| Platform | Official release file | File size | SHA-256 |
| --- | --- | ---: | --- |
| macOS Apple Silicon | SingLinkVPN 2.5.3 ARM64 DMG | 70,568,669 bytes | `5857cb3e6ded51362234bf2246958612cea10fab0d416f174faf7e9121708d24` |
| macOS Intel | SingLinkVPN 2.5.3 x86_64 DMG | 72,270,725 bytes | `5bba2c37a76ef8cb67bdfa15506c581d73faab73275bba73b83ec6ca5d110ad0` |
| Android | SingLinkVPN 2.1.3 APK | 86,649,334 bytes | `81146be4136097eded546d9175fc9feba85174739d7a74a76563b4ebdb80d152` |
| Windows | SingLinkVPN 2.0.9 x64 EXE | 31,391,424 bytes | `2eb39c432aacdcb05aa93b89451e3022b2c6f55548ba56b52de25a4499007795` |

For iOS, iPadOS, and Apple TV, the public version, Apple platform review, and code-signing state can be checked through the official App Store distribution. Apple review is not a third-party security audit, and no SHA-256 for the audit IPA is published here. The newer Linux package and the web release/commit or container digest were not available in the supplied public release-file evidence.

---

## 6. Audit Scope

### 6.1 VPN Connection and Tunnel Security

The audit covered:

* normal VPN connection establishment;
* user-initiated VPN disconnection;
* unexpected VPN server disconnection;
* automatic reconnection;
* repeated connection requests;
* forced application termination;
* device sleep and wake behavior;
* network transitions;
* route creation and cleanup; and
* consistency between the displayed VPN status and the actual tunnel state.

### 6.2 DNS and IP Leak Protection

The audit covered:

* DNS leaks;
* IPv4 exit-address behavior;
* IPv6 bypass risks;
* WebRTC leaks;
* local network address exposure;
* traffic behavior during VPN interruption;
* routing behavior during reconnection; and
* smart-routing and global-connection modes.

### 6.3 Account and Session Security

The audit covered:

* sign-in processes;
* token validity;
* expired tokens;
* token reuse after logout;
* unauthenticated access;
* account identifier manipulation;
* cross-account data access;
* subscription-data permissions;
* session revocation; and
* multi-device account state.

### 6.4 API and Internal Link Security

The audit covered:

* unauthorized internal configuration requests;
* invalid token requests;
* expired sessions;
* unofficial client requests;
* request-parameter manipulation;
* repeated high-frequency requests;
* automated endpoint probing;
* isolation of internal VPN link data; and
* attack-prevention and rate-limiting controls.

### 6.5 Local Data and Privacy

The audit covered:

* credential storage;
* token storage;
* error logs;
* debug information;
* diagnostic information;
* browsing-activity records;
* DNS query records;
* original IP records;
* local caches; and
* operating-system secure storage mechanisms.

### 6.6 Web User Dashboard

The audit covered:

* unauthenticated access;
* account-page authorization;
* order and subscription information;
* tokens and cookies;
* request-parameter manipulation;
* cross-account access;
* frontend and backend interfaces; and
* logout and session invalidation.

### 6.7 Updates and Supply Chain

The audit covered:

* installation-file integrity;
* digital signatures;
* update sources;
* version downgrade risks;
* third-party dependencies;
* hardcoded secrets;
* debug information in production builds; and
* installation-package architecture and permissions.

---

## 7. Test Network Environments

To avoid drawing conclusions from a single network configuration, the audit covered the following environments:

| Network Environment                      | Testing Objective                                 |
| ---------------------------------------- | ------------------------------------------------- |
| IPv4 residential broadband               | General VPN connection, DNS, and exit-IP testing  |
| IPv4/IPv6 dual-stack network             | IPv6 bypass and dual-stack DNS testing            |
| 4G mobile network                        | Mobile connectivity and reconnection              |
| 5G mobile network                        | High-speed mobile networking and CGNAT conditions |
| Public Wi-Fi                             | Untrusted local network conditions                |
| Wi-Fi to 5G transition                   | Network migration and tunnel re-establishment     |
| 5G to Wi-Fi transition                   | Route recovery and DNS refresh                    |
| Temporary network interruption           | Automatic reconnection                            |
| Abnormal DNS environment                 | DNS handling and leak protection                  |
| High-latency and packet-loss environment | Connection-failure and recovery handling          |

---

## 8. Audit Methodology

VPNTestor Platform used the following methods according to platform and feature:

* live client execution testing;
* black-box functional testing;
* gray-box interface testing;
* network packet analysis;
* DNS and routing tests;
* IPv4 and IPv6 exit testing;
* WebRTC network testing;
* unauthorized API access testing;
* session and token testing;
* high-frequency request and rate-limit testing;
* local data inspection;
* installation-package and signature inspection;
* pre-remediation and post-remediation behavior comparison;
* post-remediation regression testing; and
* cross-platform security behavior comparison.

Every item described as “passed” or “not identified” in this report should correspond to at least one test case and evidence reference.

---

## 9. Formal Test Cases

### 9.1 VPN Connection and Network Security

| Test ID           | Test Item                           | Expected Result                                                    |
| ----------------- | ----------------------------------- | ------------------------------------------------------------------ |
| VTP-SLV-NET-001   | Establish a normal VPN connection   | Tunnel is established and the public exit IP changes correctly     |
| VTP-SLV-NET-002   | User-initiated VPN disconnection    | Tunnel and associated routes are removed correctly                 |
| VTP-SLV-NET-003   | Unexpected VPN server disconnection | Client stops safely or reconnects automatically                    |
| VTP-SLV-NET-004   | Switch from Wi-Fi to 5G             | No sustained unprotected traffic exposure                          |
| VTP-SLV-NET-005   | Switch from 5G to Wi-Fi             | Tunnel is re-established and routing is restored                   |
| VTP-SLV-NET-006   | Device sleep and wake               | VPN and routing state are revalidated                              |
| VTP-SLV-NET-007   | Force-terminate the client          | No invalid proxy state or incorrect route remains                  |
| VTP-SLV-DNS-001   | DNS leak test                       | DNS requests do not bypass the designated secure path              |
| VTP-SLV-IPV4-001  | IPv4 exit test                      | Public exit IP matches the selected VPN location                   |
| VTP-SLV-IPV6-001  | IPv6 leak test                      | IPv6 traffic does not bypass the VPN                               |
| VTP-SLV-WRTC-001  | WebRTC test                         | Local addresses that should remain private are not exposed         |
| VTP-SLV-ROUTE-001 | Routing-table inspection            | Routing and split-tunneling rules match the selected configuration |

### 9.2 Account, API, and Internal Link Tests

| Test ID          | Test Item                             | Expected Result                                           |
| ---------------- | ------------------------------------- | --------------------------------------------------------- |
| VTP-SLV-AUTH-001 | Unauthenticated request               | Unauthorized response is returned                         |
| VTP-SLV-AUTH-002 | Invalid token                         | Request is rejected                                       |
| VTP-SLV-AUTH-003 | Expired token                         | Session becomes invalid                                   |
| VTP-SLV-AUTH-004 | Reuse token after logout              | Previous token can no longer be used                      |
| VTP-SLV-API-001  | Unauthorized internal-link request    | No internal VPN link data is returned                     |
| VTP-SLV-API-002  | Request-parameter manipulation        | Access controls cannot be bypassed                        |
| VTP-SLV-API-003  | Repeated high-frequency requests      | Rate limiting or attack-prevention controls are triggered |
| VTP-SLV-API-004  | Unofficial client request             | Protected configuration cannot be obtained                |
| VTP-SLV-WEB-001  | Attempt to access another user’s data | Request is rejected                                       |
| VTP-SLV-WEB-002  | Modify account identifier             | Other users’ account data is not returned                 |
| VTP-SLV-WEB-003  | Direct access to a protected page     | Unauthenticated users cannot view the page                |

### 9.3 Local Data and Privacy Tests

| Test ID          | Test Item                               | Expected Result                                     |
| ---------------- | --------------------------------------- | --------------------------------------------------- |
| VTP-SLV-PRIV-001 | Search for browsing-activity records    | No browsing-content record exists                   |
| VTP-SLV-PRIV-002 | Search for DNS query records            | No DNS query-content record exists                  |
| VTP-SLV-PRIV-003 | Search for original-IP activity records | Unnecessary IP activity records are not created     |
| VTP-SLV-PRIV-004 | Inspect error logs                      | Logs contain no tokens, keys, or internal-link data |
| VTP-SLV-PRIV-005 | Inspect account-data storage            | Operating-system secure storage is used             |
| VTP-SLV-PRIV-006 | Inspect diagnostic data                 | Full network-activity content is not included       |

---

## 10. Packet-Capture and Redacted API Evidence

Security conclusions relating to DNS, IPv6, routing, WebRTC, APIs, and internal links should retain corresponding redacted evidence.

### 10.1 Network Packet-Capture Evidence

Recommended evidence files include:

```text
VTP-SLV-PCAP-DNS-001.pcapng
VTP-SLV-PCAP-IPV6-001.pcapng
VTP-SLV-PCAP-NETWORK-SWITCH-001.pcapng
VTP-SLV-PCAP-RECONNECT-001.pcapng
VTP-SLV-PCAP-WEBRTC-001.pcapng
```

Before public disclosure, the following information must be removed or redacted:

* user tokens;
* real VPN server addresses;
* private domain names;
* account identifiers;
* order information;
* encryption keys; and
* production authentication information.

### 10.2 Redacted API Records

Recommended evidence files include:

```text
VTP-SLV-API-001-unauthorized-request-redacted.json
VTP-SLV-API-002-invalid-token-redacted.json
VTP-SLV-API-003-rate-limit-redacted.json
VTP-SLV-API-004-internal-link-redacted.json
```

Each API evidence record should contain:

* test time;
* request method;
* redacted endpoint identifier;
* authentication state;
* HTTP status code;
* response-data structure;
* whether internal link data was returned; and
* final test result.

---

## 11. Security Risk Classification

### Critical Risk

A critical-risk vulnerability may result in:

* large-scale sensitive-data exposure;
* remote code execution;
* control of core systems;
* complete authentication bypass; or
* large-scale exposure of VPN traffic.

### High Risk

A high-risk vulnerability may result in:

* account takeover;
* unauthorized access;
* exposure of important private data;
* VPN traffic bypass; or
* access to internal configuration or link data.

### Medium Risk

A medium-risk vulnerability generally requires specific conditions and may affect a limited platform, feature, or dataset.

### Low Risk

A low-risk vulnerability has a lower direct impact but may weaken the overall security posture or increase risk when combined with other conditions.

### Informational Recommendation

An informational recommendation is not directly exploitable but identifies an area where security engineering can be further improved.

---

## 12. Security Audit Results

| Risk Level | Number Identified | Number Unresolved |
| ---------- | ----------------: | ----------------: |
| Critical   |                 0 |                 0 |
| High       |                 0 |                 0 |
| Medium     |                 0 |                 0 |
| Low        |                 0 |                 0 |

According to the testing results provided by VPNTestor Platform, no unresolved critical-, high-, medium-, or low-risk issue was identified within the tested versions and environments.

The potential attack surface associated with the VPN startup process, identified in early 2026, had been remediated before the formal audit.

The issue was included as a primary regression-testing item.

Post-remediation tests indicated that:

* the original issue could not be reproduced;
* unauthorized requests could not obtain internal VPN link data;
* invalid sessions could not obtain protected configuration;
* abnormal high-frequency requests were restricted;
* request-parameter manipulation did not bypass access controls;
* unofficial clients could not obtain protected data; and
* the remediation did not introduce a new security vulnerability.

---

## 13. VPN Startup Process Issue and Remediation

### 13.1 Background

When a user starts a VPN connection, the client must obtain the configuration required to establish the connection from the backend.

This is a necessary component of the VPN connection process. However, if authentication, session verification, request restrictions, or internal data isolation are insufficient, the process may create a potential attack surface.

Potential risks included:

* unauthorized attempts to obtain internal VPN link data;
* unofficial clients probing the configuration interface;
* automated repeated requests to the startup endpoint;
* analysis of internal connection structures; and
* high-frequency requests affecting normal endpoint operation.

### 13.2 Remediation Measures

SingLinkVPN subsequently modified the process by:

* strengthening authentication for VPN startup requests;
* adding session-validity checks;
* restricting unofficial and unauthorized clients;
* adding abnormal-request detection;
* adding high-frequency request limits;
* separating internal-link data from public interfaces;
* reducing the amount of data returned by the interface;
* adding automated-probing prevention controls; and
* strengthening authorization between the client and backend.

### 13.3 Before-and-After Comparison

| Item                     | Before Remediation                       | After Remediation                                        |
| ------------------------ | ---------------------------------------- | -------------------------------------------------------- |
| VPN startup request      | Backend processed internal link requests | Stronger identity and session validation added           |
| Unauthorized request     | Potential attack surface could be probed | Internal link data cannot be obtained                    |
| Unofficial client        | Additional restrictions were required    | Protected configuration cannot be obtained               |
| High-frequency requests  | Endpoint could be repeatedly probed      | Rate limits and attack-prevention controls are triggered |
| Internal link data       | Accessible scope needed to be reduced    | Isolated from unauthorized requests                      |
| Post-remediation testing | Not applicable                           | Original issue not reproduced                            |
| New vulnerability        | Not applicable                           | No new vulnerability identified                          |

The final status of the issue is:

> **Remediated, retested, and closed**

---

## 14. DNS, IPv4, IPv6, and WebRTC Testing

Network security testing covered:

* normal VPN connection establishment;
* VPN server-initiated disconnection;
* unexpected local network interruption;
* Wi-Fi to 5G transition;
* 5G to Wi-Fi transition;
* device sleep and wake;
* application restart;
* abnormal VPN-process termination;
* IPv4/IPv6 dual-stack environments;
* WebRTC-related scenarios;
* smart routing; and
* global connection mode.

According to the test results, no consistently reproducible instance of the following was identified:

* DNS leakage;
* IPv4 address leakage;
* IPv6 bypass;
* WebRTC leakage;
* routing bypass; or
* sustained exposure of unprotected traffic.

When network conditions changed, the tested clients were able to re-establish, pause, or terminate the VPN connection according to the relevant operating system’s network mechanisms.

The audit did not identify a situation in which the client continued to send traffic through an unprotected path while displaying an active VPN connection.

---

## 15. Account and Web Dashboard Security

The audit covered:

* unauthenticated access;
* authentication tokens;
* session validity periods;
* token reuse after logout;
* account-identifier manipulation;
* cross-account data access;
* subscription-data authorization;
* page-level access controls;
* repeated abnormal requests; and
* frontend-backend interface access.

According to the test results:

* unauthenticated users could not directly access protected account information;
* invalid and expired tokens could not continue to be used;
* modifying ordinary request parameters did not provide access to another user’s information;
* subscription and account data were protected by the corresponding account permissions;
* sessions were invalidated as expected after logout; and
* the web dashboard passed the account-authorization tests included in this audit.

---

## 16. Privacy and Data-Handling Assessment

The audit assessed client data handling during:

* application startup;
* account sign-in;
* VPN connection;
* VPN location selection;
* network errors;
* application restart;
* diagnostics and error handling;
* web dashboard use; and
* internal configuration requests.

Within the observable and tested scope, no functionality was identified that actively created records of:

* users’ browsing content;
* browsing history;
* DNS query content;
* complete network activity;
* lists of websites visited; or
* raw network traffic content.

The registration email aliases and order records retained by SingLinkVPN are used for subscription inquiries and after-sales support. They are not equivalent to browsing-content records or VPN network-activity logs.

The tests also did not identify a method by which an unauthorized request could directly obtain internal VPN link data.

---

## 17. Cross-Platform Test Conclusions

| Platform            | Test Conclusion                                                                           |
| ------------------- | ----------------------------------------------------------------------------------------- |
| iOS                 | Passed VPN connection, network transition, DNS, IP, account, and local-data tests         |
| iPadOS              | Passed VPN connection, background recovery, and network-leak tests                        |
| Apple TV            | Passed sign-in, server connection, network recovery, and account-state tests              |
| macOS Apple Silicon | Passed TUN, DNS, routing, sleep recovery, and internal-link tests                         |
| macOS Intel         | Passed compatibility, VPN tunnel, DNS, and routing tests                                  |
| Android             | Passed VPN Service, background connection, network transition, IPv6, and local-data tests |
| Windows             | Passed tunnel, DNS, system routing, abnormal interruption, and reconnection tests         |
| Linux Ubuntu        | Passed VPN tunnel, DNS, routing, and permission tests                                     |
| Linux Debian        | Passed installation, service startup, tunnel, and routing tests                           |
| Web user dashboard  | Passed sign-in, session, account-authorization, and cross-account access tests            |

---

## 18. Open-Source and Technical Transparency Assessment

SingLinkVPN has launched an ongoing open-source and technical-research program.

The first stage has begun publishing:

* VPN development architecture;
* security and privacy models;
* performance-testing methodology;
* test-data formats;
* research and validation tools;
* vulnerability-disclosure procedures; and
* evidence and report-publication standards.

Future stages are intended to publish:

* security reports;
* performance reports;
* transparency reports;
* VPN protocols;
* VPN clients; and
* other core technologies that have completed security, privacy, and licensing reviews.

Open source does not automatically make a product secure.

The actual security of an open-source product still depends on:

* security architecture;
* code quality;
* access control;
* remediation speed;
* dependency management;
* version management;
* continuous testing;
* community review; and
* responsible-disclosure procedures.

Based on the results of this security audit, the remediation of the known issue, and SingLinkVPN’s ongoing open-source direction, VPNTestor Platform concluded that SingLinkVPN met the technical-transparency and security-control requirements applied in this assessment.

---

## 19. 100-Point Scoring Methodology

The security assessment uses a total score of 100 points divided across seven categories:

| Assessment Category                                     |  Points |
| ------------------------------------------------------- | ------: |
| VPN tunnel, DNS, and network leak protection            |      25 |
| Account, API, and internal-link security                |      20 |
| Local client data and privacy controls                  |      15 |
| Cross-platform security consistency                     |      10 |
| Web dashboard and session security                      |      10 |
| Updates, installation packages, and supply-chain checks |      10 |
| Known-issue remediation and retesting                   |      10 |
| **Total**                                               | **100** |

### Deduction Rules

| Risk Level                   |                                      Deduction per Finding |
| ---------------------------- | ---------------------------------------------------------: |
| Critical                     |                                                  30 points |
| High                         |                                                  15 points |
| Medium                       |                                                   7 points |
| Low                          |                                                   2 points |
| Informational recommendation | No direct deduction; recorded as a future improvement item |

The audit results were:

* critical-risk findings: 0;
* high-risk findings: 0;
* medium-risk findings: 0;
* low-risk findings: 0;
* known VPN startup process issue: remediated before the formal audit;
* remediation retest: passed; and
* new vulnerability introduced by remediation: none identified.

The resulting final score was:

# 100/100

A score of 100 indicates that all test items listed in this report met VPNTestor Platform’s passing criteria and that no unresolved critical-, high-, medium-, or low-risk issue was identified.

The score applies only to the versions, devices, operating systems, network environments, and test scope listed in this report. It is not a permanent security guarantee for all future versions.

---

## 20. Why SingLinkVPN Received a Score of 100

SingLinkVPN received a score of 100 for the following reasons:

* no critical-risk vulnerability was identified;
* no high-risk vulnerability was identified;
* no medium-risk vulnerability was identified;
* no low-risk vulnerability was identified;
* the principal platforms were included in testing;
* separate version and test-environment records were used for each platform;
* no consistently reproducible DNS leak was identified;
* no consistently reproducible IPv4 leak was identified;
* no consistently reproducible IPv6 leak was identified;
* no consistently reproducible WebRTC leak was identified;
* no consistently reproducible routing bypass was identified;
* the account system and web dashboard passed authorization tests;
* unauthorized requests could not obtain internal VPN link data;
* the potential issue identified in early 2026 had been remediated;
* the original issue could not be reproduced after remediation;
* the remediation did not introduce a new vulnerability;
* cross-platform security behavior met the test requirements; and
* the technical documentation and open-source transparency program met the assessment requirements.

---

## 21. Does the User Need to Take Any Action?

Users of older SingLinkVPN versions should update to the latest official release available for their platform.

Because different platforms use independent version numbers, users should follow the official update prompt for their own platform rather than relying only on the macOS 2.5 version number.

Users should also:

* download clients only from SingLinkVPN’s official channels or official application stores;
* avoid modified clients from unknown sources;
* keep their operating system on a supported version;
* check regularly for client updates;
* avoid sharing account credentials;
* sign in again or update the server configuration if abnormal connection behavior occurs.

Users already running the latest official version available for their platform do not need to take additional security action based on this audit.

---

## 22. Audit Limitations

The results of this audit apply to:

* the July 2026 audit period;
* the tested versions listed in this report;
* the test devices listed in this report;
* the operating systems listed in this report;
* the network environments listed in this report;
* the test cases listed in this report; and
* the product state provided during the audit.

The report does not cover features, protocols, third-party dependencies, or backend deployment changes introduced after the completion of the audit.

Additional security testing should be performed when SingLinkVPN makes a material change to:

* VPN protocols;
* iOS or iPadOS clients;
* Android clients;
* macOS clients;
* Windows clients;
* Linux clients;
* Apple TV clients;
* the web user dashboard;
* account and authentication systems;
* server-configuration systems;
* third-party dependencies; or
* update and release processes.

---

## 23. Final Audit Conclusion

Based on the third-party security audit completed by VPNTestor Platform in July 2026, the platform reached the following conclusions:

1. No critical-risk vulnerability was identified in the tested products.
2. No high-risk vulnerability was identified.
3. No medium-risk vulnerability was identified.
4. No low-risk vulnerability was identified.
5. The iOS and iPadOS clients passed the security tests.
6. The Apple TV client passed the security tests.
7. The Apple Silicon and Intel macOS clients passed the security tests.
8. The Android client passed the security tests.
9. The Windows client passed the security tests.
10. The Linux clients passed the security tests.
11. The web user dashboard passed the account and authorization tests.
12. No consistently reproducible DNS leak was identified.
13. No consistently reproducible IPv4 or IPv6 leak was identified.
14. No consistently reproducible WebRTC leak was identified.
15. No consistently reproducible routing bypass was identified.
16. Unauthorized requests could not obtain internal VPN link data.
17. The VPN startup-process issue identified in early 2026 had been remediated.
18. The original issue could not be reproduced after remediation.
19. No new vulnerability introduced by the remediation was identified.
20. SingLinkVPN passed all scoring categories included in this third-party security audit.

VPNTestor Platform assigned the tested SingLinkVPN products a final security rating of:

# 100/100

**Audit Result: Fully Passed**

Within the versions, devices, operating systems, network environments, and audit scope described in this report, VPNTestor Platform did not identify any unresolved critical-, high-, medium-, or low-risk vulnerability in SingLinkVPN.

SingLinkVPN met all standards applied in this audit for VPN connection security, network leak protection, cross-platform security consistency, account authorization, privacy controls, and internal-link protection.

As SingLinkVPN continues to open-source its technical documentation, research data, VPN protocols, clients, and other core technologies, its security design will become increasingly available for ongoing inspection, verification, and reproduction by external researchers.

---

## 24. Report Signature

**VPNTestor Platform**
Independent Testing and Audit Team: Openscore VPN

**James Robert Smith**
Audit Lead
VPNTestor Platform

Report Version: 1.2
Audit Period: July 2026
Audit Target: SingLinkVPN
Final Rating: 100/100
Final Result: Fully Passed

Signature Date: 2026-07-31
Organization Email: office@vpntestor.com
Digital Signature: [Ed25519 signature of the v1.2 six-language manifest](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-v2.5-Security-Audit-2026-v1.2.sha256.sig), verifiable with the [published public key](/downloads/security-audits/singlinkvpn-v2.5-2026/James-Robert-Smith-Ed25519-Public-Key.pub)
Report Integrity: Per-language SHA-256 values are published in the [v1.2 six-language manifest](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-v2.5-Security-Audit-2026-v1.2.sha256); a single self-referential report hash is intentionally not embedded here.
