On 29 July 2026, the Openscore VPN team downloaded two versioned releases from Proton VPN's official GitHub organization, verified their published hashes and signing, and reviewed public source code, privacy documents, the 2026 Securitum no-logs audit and Proton's current transparency report. VPNTestor independently confirmed the record.
Exact hashes, certificate identity, permissions, findings, scoring and exclusions are preserved in the machine-readable evidence record.
Frozen release artifacts
- Android
5.19.61.0, packagech.protonvpn.android, 55,806,557 bytes, SHA-256568b0f05…517633a. - Windows x64
5.1.5, 128,808,528 bytes, SHA-2561e6600e4…cba1d9c.
Both local hashes matched the SHA-256 digests published with the official GitHub release assets. This establishes exact artifact consistency with that release channel.
Signing and production hardening
The Android APK passed APK Signature Scheme v2 and v3 verification. It targets Android API 35, is not debuggable, disables Android backup and declares a custom network-security configuration. The manifest requests package visibility and camera access in addition to expected VPN lifecycle permissions. Those can support per-app routing and QR import, but their runtime data flows were not exercised.
The Windows installer contains an Authenticode signature with an EV code-signing certificate issued to Proton AG, organization identifier CHE-354.686.492, chained through Sectigo and accompanied by a timestamp chain. macOS and iOS binaries were not frozen in this test run.
Open source and audit transparency
Proton VPN publishes active repositories for Windows, Android, iOS/macOS, Linux and its browser extension. The official GitHub organization is domain-verified and the reviewed repositories were updated during 2026. Open source enables inspection; it does not by itself prove that every store binary is reproducibly built from a particular commit.
Securitum's fifth annual no-logs review examined production server configurations and operating controls. Its published 2026 conclusion reports no evidence of logging browsing activity, DNS queries, destination services, traffic contents or user-identifiable connection metadata in the examined infrastructure. That scope supports a no-logs conclusion; it is not a universal application vulnerability audit.
Proton's transparency report, updated 14 July 2026, reports 47 legally binding Swiss orders through June 2026 and says all 47 were denied because identifying connection logs were unavailable. The count is a provider transparency publication, not independently re-created court data.
Static and public-evidence score: 92/100
- Artifact integrity and provenance: 29/30.
- Platform signing: 28/30.
- Permissions and production hardening: 17/20.
- Public security transparency: 18/20.
Deductions reflect the absence of independently frozen macOS/iOS artifacts in this run, broad Android permissions not runtime-validated, version-specific client audits that do not cover every current release, and reliance on the same GitHub channel for both assets and digests.
What this assessment does not prove
- IPv4, IPv6, DNS, WebRTC and route leakage.
- Kill Switch behavior under interruption, termination and network switching.
- Account, session, dashboard and cross-account authorization.
- Local runtime logging, credential storage and uninstall remnants.
- Streaming availability, sustained speed and latency.
- Infrastructure security outside Securitum's published no-logs scope.