Contact

Guide

SingLinkVPN Independent Security Audit Report (2026)

Published ·Last updated ·VPNTestor Platform / Openscore VPN

SingLink VPN · security audit · Windows 2.5.8 · macOS 2.5.7 · signed audit · 2026

Latest audit navigation · Append-only, with history preserved

Latest-Version Security Audits and Evidence Downloads

Browse security audits and evidence by platform. Version checks, runtime materials and recovery tests for each series are grouped together; original report URLs, publication dates, historical conclusions, downloads and digital signatures remain unchanged.

2026-09-11iOS 2.5 series security auditExisting security and no-logs audit conclusions, current mobile tests and signed evidence in one place.View audit and evidence

Version information is verified. This batch contains 3 reviewed screenshots; the local-address check returned an anonymized hostname. The VPNTestor test team recorded normal recovery in all 3 scenarios: screen lock, network switching and interruption. See the results report for itemized outcomes and methodology.

2026-09-11Android 2.5 series security auditExisting security and no-logs audit conclusions, current mobile tests and signed evidence in one place.View audit and evidence

Sample information is verified. This batch contains 6 reviewed screenshots: two connected-node interfaces and IP-check records with different exit values. The local-address check returned a local-scope address. The VPNTestor test team recorded normal recovery in all 3 scenarios. See the results report for outcomes and methodology.

Latest signed report translation2026 v2.0 · 100/100Faithful translation covering macOS 2.5.7, Windows 2.5.8, and new-protocol verification · Integrity-signedView or download evidenceLatest Windows new-protocol verificationWindows 2.5.8 / build 30777/7 items passed · Public security verification and integrity evidenceView or download evidenceWindows version security verificationWindows 2.5.8 / build 3077All listed items passed · Public verification summaryView or download evidenceLatest macOS sample evidencemacOS 2.5.7 / build 30656/6 items passed · Release security verification and integrity evidenceView or download evidencemacOS new-protocol verificationmacOS 2.5.6 / build 30647/7 items passed · Public security verification and integrity evidenceView or download evidence

Audit and Evidence Update History

  1. This article was first published; the original publication date remains preserved, and the v1.2 report is not rewritten by subsequent updates.

  2. Recorded the formal installation sample, signature, and notarization verification status for macOS 2.5.6 / build 3056.

  3. Added new-protocol security verification and evidence verification values for macOS 2.5.6 / build 3064.

  4. Recorded release security verification and integrity evidence for macOS 2.5.7 / build 3065.

  5. Added the installation sample and version security verification record for Windows 2.5.8 / build 3077.

  6. Added the Windows 2.5.8 / build 3077 new-protocol security verification, with 7/7 items passing.

  7. Applied consistent redaction to the webpage and downloadable summaries; detailed evidence remains in the restricted archive.

  8. Published the current-version v2.0 complete security audit report with a final rating of 100/100 and completed its digital signature.

  9. Updated iOS / Android 2.5 series version and sample verification, runtime materials, screenshot review, VPNTestor device recovery tests and signed evidence. Each conclusion retains the scope of its source record.

This timeline is a quick summary; Section 25 of the report retains the dates, results, and integrity records for each version.

SingLinkVPN Independent Security Audit Report (2026)

Audit Organization: VPNTestor Platform Independent Testing and Audit Team: Openscore VPN Lead Auditor: James Robert Smith Audit Target: SingLinkVPN Audit Type: Third-Party VPN Security Audit Audit Period: July 2026 Report Version: 1.2

Public Report Files and Integrity Verification

VPNTestor is the original publisher of this independent audit. The report body below preserves the complete canonical audit structure and conclusions. The integrity artifacts verify the frozen six-language report set; they do not, by themselves, prove execution of every underlying test.

In July 2026, VPNTestor Platform completed a third-party security audit of SingLinkVPN’s principal products and services.

The audit covered SingLinkVPN applications for iOS, iPadOS, Android, macOS, Windows, Linux, and Apple TV, together with the web-based user dashboard.

The assessment focused on VPN connection processes, network leak protection, internal link protection, account and session security, local data handling, cross-platform security consistency, and verification of previously implemented security fixes.

Because SingLinkVPN uses separate version numbers and release processes for different platforms, this report records the tested version and environment for each platform individually. It does not describe every client as using the same version number.

According to the audit results provided by VPNTestor Platform, no unresolved critical-, high-, medium-, or low-risk security vulnerabilities were identified within the tested versions, devices, operating systems, network environments, and audit scope described in this report.

In early 2026, SingLinkVPN identified and addressed a potential security issue related to the VPN startup process. The issue concerned requests made by the client to the backend for internal connection configuration and VPN link information during connection establishment.

SingLinkVPN subsequently strengthened authentication, access control, abnormal-request detection, rate limiting, internal data isolation, and automated-attack prevention controls.

VPNTestor Platform repeated the relevant tests on the remediated versions. The original issue could not be reproduced, and no new exploitable security issue was identified as a result of the remediation.

Based on the results of this audit, SingLinkVPN passed all listed security assessment categories and received a final score of:

100/100 Security Rating

Audit Result: Fully Passed

1. Audit Summary

ItemAudit Information
Audit organizationVPNTestor Platform
Independent testing and audit teamOpenscore VPN
Lead auditorJames Robert Smith
Audit targetSingLinkVPN
Audit typeThird-party security audit
Audit periodJuly 2026
Platforms coverediOS, iPadOS, Android, macOS, Windows, Linux, Apple TV, and web user dashboard
Confirmed macOS version2.5 series
Other platform versionsRecorded independently for each platform
Audit report version1.2
Critical-risk findings0
High-risk findings0
Medium-risk findings0
Low-risk findings0
Previously identified security issuePotential attack surface in the VPN startup process
Remediation statusRemediated
Remediation retestOriginal issue not reproduced; no new vulnerability identified
Final rating100/100
Final resultFully passed

2. Audit Statement

This report was prepared by VPNTestor Platform based on the tested products, test environments, technical materials, and remediation-verification results.

VPNTestor is the publishing and verification platform. Openscore VPN is the professional team that independently performs the testing and audit; VPNTestor then reviews and confirms the resulting assessment.

The audit was led by James Robert Smith.

SingLinkVPN was responsible for providing the clients, test accounts, product information, remediation versions, and environments required for the audit.

VPNTestor Platform was responsible for the testing methodology, risk classification, result assessment, remediation retesting, and final score.

The conclusions in this report apply to:

  • the July 2026 audit period;

  • the platforms listed in this report;

  • the product versions listed in this report;

  • the test devices listed in this report;

  • the operating systems listed in this report;

  • the network environments listed in this report;

  • the test cases listed in this report; and

  • the product state supplied during the audit period.

The phrase “no vulnerability identified” means that no unresolved vulnerability was identified or reproduced within the defined audit scope. It does not mean that any software product can be guaranteed to remain free of vulnerabilities in every future version and environment.

3. About VPNTestor Platform

VPNTestor Platform evaluates VPN products across the following areas:

  • VPN tunnel and connection security;

  • DNS and IP leak protection;

  • IPv6 and WebRTC leak protection;

  • network interruption and reconnection behavior;

  • Kill Switch and routing protection;

  • account and session security;

  • API and internal configuration protection;

  • local client data handling;

  • web dashboard access controls;

  • cross-platform security consistency;

  • third-party dependency and installation-package security;

  • vulnerability remediation and regression testing; and

  • technical transparency and open-source materials.

VPN security cannot be assessed solely through product marketing, privacy-policy statements, or a single successful connection test.

This audit therefore combined live client testing, abnormal network scenarios, simulated unauthorized requests, network traffic analysis, account authorization testing, and post-remediation regression testing.

4. Tested Platforms, Versions, and Environments

4.1 Complete Tested Platform Information

PlatformProduct/Public VersionTested DistributionPrimary Test DevicesOperating System EnvironmentEvidence Reference
iOSSingLink 2.0.7 / App Store 1.0.7Official App Store releaseiPhone 15 Pro, iPhone SE (3rd generation)iOS 18.x and supported releasesSLV-IOS-2026-01
iPadOSSingLink 2.0.7 / App Store 1.0.7Official App Store release11-inch iPad Pro, iPad (10th generation)iPadOS 18.x and supported releasesSLV-IPAD-2026-01
Apple TVSingLink 2.0.7 / App Store 1.0.7Apple TV App Store releaseApple TV 4K (3rd generation)tvOS 17 and later supported releasesSLV-TVOS-2026-01
macOS Apple SiliconSingLinkVPN 2.5.3ARM64 installation packageMacBook Pro with M3 Pro, MacBook Air with M2macOS 14 and macOS 15SLV-MAC-ARM-2026-01
macOS IntelSingLinkVPN 2.5.3x86_64 installation package2019 Intel MacBook PromacOS 13 and macOS 14SLV-MAC-INTEL-2026-01
AndroidSingLinkVPN 2.1.3Android APKGoogle Pixel 9 Pro, Samsung Galaxy S24Android 15 and Android 16SLV-ANDROID-2026-01
WindowsSingLinkVPN 2.0.9Windows x64 installation packageIntel and AMD x64 test systemsWindows 11 24H2 and Windows 10 22H2SLV-WIN-2026-01
Linux UbuntuJuly 2026 official test packageDebian/Ubuntu packageIntel and AMD x86_64 test systemsUbuntu 24.04 LTSSLV-LINUX-UBU-2026-01
Linux DebianJuly 2026 official test packageDebian packageIntel x86_64 test systemDebian 12SLV-LINUX-DEB-2026-01
Web user dashboardJuly 2026 deployment versionWeb frontend and backend APIDesktop and mobile browsersCurrent releases of Chrome, Edge, Firefox, and SafariSLV-WEB-2026-01

4.2 Versioning Notes

SingLinkVPN uses independent version numbers for different platforms.

This report records that:

  • iOS, iPadOS, and Apple TV use their corresponding App Store versions;

  • the tested macOS applications belong to the 2.5 series;

  • separate installation packages are used for Apple Silicon and Intel-based Macs;

  • Android uses an independent Android product version;

  • Windows uses an independent desktop product version;

  • Linux is identified by the official package supplied during the audit; and

  • the web user dashboard is identified by its deployment version, backend release, or Git commit.

This report therefore does not state that all platforms use version 2.5.

5. Build Numbers, Installation Files, and File Hashes

A separate build and integrity record should be retained for every tested client.

The signed PDF report and technical annex should include the following information:

PlatformBuild InformationFile Verification Information
iOS`CFBundleVersion` or App Store Connect build numberSHA-256 of the audited IPA
iPadOS`CFBundleVersion` or App Store Connect build numberSHA-256 of the audited IPA
Apple TVtvOS application `CFBundleVersion`SHA-256 of the audited IPA
macOS Apple Silicon`CFBundleShortVersionString` and `CFBundleVersion`SHA-256 of the ARM64 DMG or PKG
macOS Intel`CFBundleShortVersionString` and `CFBundleVersion`SHA-256 of the x86_64 DMG or PKG
Android`versionName` and `versionCode`SHA-256 of the APK
WindowsFile Version and Product VersionSHA-256 of the EXE or MSI
LinuxPackage version and architectureSHA-256 of the DEB, RPM, or installation package
Web user dashboardGit commit, release ID, or deployment IDContainer image digest or artifact hash
Historical Original Input Template (Preserved Record, Not a Current Audit Task)The original v1.2 content remains unchanged; see the v2.0 complete signed report at the top of the page for current conclusions and evidence.Expand historical source text

Final Report Entry Format

The template below is retained from the original canonical report. The audited IPA hashes, newer Linux package hash, and web deployment digest were not supplied for public release. Known macOS, Android, and Windows official release-file values are recorded in the evidence table immediately after the template; those later values are official distribution checksums, not audit-retained sample hashes.

iOS Build: [To be completed]
iOS IPA SHA-256: [To be completed]

Apple TV Build: [To be completed]
Apple TV IPA SHA-256: [To be completed]

macOS ARM64 Build: [To be completed]
macOS ARM64 SHA-256: [To be completed]

macOS Intel Build: [To be completed]
macOS Intel SHA-256: [To be completed]

Android Version Code: [To be completed]
Android APK SHA-256: [To be completed]

Windows Build: [To be completed]
Windows EXE/MSI SHA-256: [To be completed]

Linux Package Version: [To be completed]
Linux Package SHA-256: [To be completed]

Web Release/Commit: [To be completed]
Web Container Digest: [To be completed]

Build numbers and file hashes must be obtained directly from the actual audited installation files or deployment systems. Estimated values or randomly generated strings must not be used.

Official Release-File Verification Values Added After the Audit

The following values were obtained from the current files distributed through the official SingLinkVPN website on 2026-07-27. They are published as official release-file verification values. They are not represented as hashes of original audit-retained samples, and they do not replace the build and artifact records required for a fully reproducible audit archive.

PlatformOfficial release fileFile sizeSHA-256
macOS Apple SiliconSingLinkVPN 2.5.3 ARM64 DMG70,568,669 bytes`5857cb3e6ded51362234bf2246958612cea10fab0d416f174faf7e9121708d24`
macOS IntelSingLinkVPN 2.5.3 x86_64 DMG72,270,725 bytes`5bba2c37a76ef8cb67bdfa15506c581d73faab73275bba73b83ec6ca5d110ad0`
AndroidSingLinkVPN 2.1.3 APK86,649,334 bytes`81146be4136097eded546d9175fc9feba85174739d7a74a76563b4ebdb80d152`
WindowsSingLinkVPN 2.0.9 x64 EXE31,391,424 bytes`2eb39c432aacdcb05aa93b89451e3022b2c6f55548ba56b52de25a4499007795`

For iOS, iPadOS, and Apple TV, the public version, Apple platform review, and code-signing state can be checked through the official App Store distribution. Apple review is not a third-party security audit, and no SHA-256 for the audit IPA is published here. The newer Linux package and the web release/commit or container digest were not available in the supplied public release-file evidence.

6. Audit Scope

6.1 VPN Connection and Tunnel Security

The audit covered:

  • normal VPN connection establishment;

  • user-initiated VPN disconnection;

  • unexpected VPN server disconnection;

  • automatic reconnection;

  • repeated connection requests;

  • forced application termination;

  • device sleep and wake behavior;

  • network transitions;

  • route creation and cleanup; and

  • consistency between the displayed VPN status and the actual tunnel state.

6.2 DNS and IP Leak Protection

The audit covered:

  • DNS leaks;

  • IPv4 exit-address behavior;

  • IPv6 bypass risks;

  • WebRTC leaks;

  • local network address exposure;

  • traffic behavior during VPN interruption;

  • routing behavior during reconnection; and

  • smart-routing and global-connection modes.

6.3 Account and Session Security

The audit covered:

  • sign-in processes;

  • token validity;

  • expired tokens;

  • token reuse after logout;

  • unauthenticated access;

  • account identifier manipulation;

  • cross-account data access;

  • subscription-data permissions;

  • session revocation; and

  • multi-device account state.

6.4 API and Internal Link Security

The audit covered:

  • unauthorized internal configuration requests;

  • invalid token requests;

  • expired sessions;

  • unofficial client requests;

  • request-parameter manipulation;

  • repeated high-frequency requests;

  • automated endpoint probing;

  • isolation of internal VPN link data; and

  • attack-prevention and rate-limiting controls.

6.5 Local Data and Privacy

The audit covered:

  • credential storage;

  • token storage;

  • error logs;

  • debug information;

  • diagnostic information;

  • browsing-activity records;

  • DNS query records;

  • original IP records;

  • local caches; and

  • operating-system secure storage mechanisms.

6.6 Web User Dashboard

The audit covered:

  • unauthenticated access;

  • account-page authorization;

  • order and subscription information;

  • tokens and cookies;

  • request-parameter manipulation;

  • cross-account access;

  • frontend and backend interfaces; and

  • logout and session invalidation.

6.7 Updates and Supply Chain

The audit covered:

  • installation-file integrity;

  • digital signatures;

  • update sources;

  • version downgrade risks;

  • third-party dependencies;

  • hardcoded secrets;

  • debug information in production builds; and

  • installation-package architecture and permissions.

7. Test Network Environments

To avoid drawing conclusions from a single network configuration, the audit covered the following environments:

Network EnvironmentTesting Objective
IPv4 residential broadbandGeneral VPN connection, DNS, and exit-IP testing
IPv4/IPv6 dual-stack networkIPv6 bypass and dual-stack DNS testing
4G mobile networkMobile connectivity and reconnection
5G mobile networkHigh-speed mobile networking and CGNAT conditions
Public Wi-FiUntrusted local network conditions
Wi-Fi to 5G transitionNetwork migration and tunnel re-establishment
5G to Wi-Fi transitionRoute recovery and DNS refresh
Temporary network interruptionAutomatic reconnection
Abnormal DNS environmentDNS handling and leak protection
High-latency and packet-loss environmentConnection-failure and recovery handling

8. Audit Methodology

VPNTestor Platform used the following methods according to platform and feature:

  • live client execution testing;

  • black-box functional testing;

  • gray-box interface testing;

  • network packet analysis;

  • DNS and routing tests;

  • IPv4 and IPv6 exit testing;

  • WebRTC network testing;

  • unauthorized API access testing;

  • session and token testing;

  • high-frequency request and rate-limit testing;

  • local data inspection;

  • installation-package and signature inspection;

  • pre-remediation and post-remediation behavior comparison;

  • post-remediation regression testing; and

  • cross-platform security behavior comparison.

Every item described as “passed” or “not identified” in this report should correspond to at least one test case and evidence reference.

9. Formal Test Cases

9.1 VPN Connection and Network Security

Test IDTest ItemExpected Result
VTP-SLV-NET-001Establish a normal VPN connectionTunnel is established and the public exit IP changes correctly
VTP-SLV-NET-002User-initiated VPN disconnectionTunnel and associated routes are removed correctly
VTP-SLV-NET-003Unexpected VPN server disconnectionClient stops safely or reconnects automatically
VTP-SLV-NET-004Switch from Wi-Fi to 5GNo sustained unprotected traffic exposure
VTP-SLV-NET-005Switch from 5G to Wi-FiTunnel is re-established and routing is restored
VTP-SLV-NET-006Device sleep and wakeVPN and routing state are revalidated
VTP-SLV-NET-007Force-terminate the clientNo invalid proxy state or incorrect route remains
VTP-SLV-DNS-001DNS leak testDNS requests do not bypass the designated secure path
VTP-SLV-IPV4-001IPv4 exit testPublic exit IP matches the selected VPN location
VTP-SLV-IPV6-001IPv6 leak testIPv6 traffic does not bypass the VPN
VTP-SLV-WRTC-001WebRTC testLocal addresses that should remain private are not exposed
VTP-SLV-ROUTE-001Routing-table inspectionRouting and split-tunneling rules match the selected configuration

9.2 Account, API, and Internal Link Tests

Test IDTest ItemExpected Result
VTP-SLV-AUTH-001Unauthenticated requestUnauthorized response is returned
VTP-SLV-AUTH-002Invalid tokenRequest is rejected
VTP-SLV-AUTH-003Expired tokenSession becomes invalid
VTP-SLV-AUTH-004Reuse token after logoutPrevious token can no longer be used
VTP-SLV-API-001Unauthorized internal-link requestNo internal VPN link data is returned
VTP-SLV-API-002Request-parameter manipulationAccess controls cannot be bypassed
VTP-SLV-API-003Repeated high-frequency requestsRate limiting or attack-prevention controls are triggered
VTP-SLV-API-004Unofficial client requestProtected configuration cannot be obtained
VTP-SLV-WEB-001Attempt to access another user’s dataRequest is rejected
VTP-SLV-WEB-002Modify account identifierOther users’ account data is not returned
VTP-SLV-WEB-003Direct access to a protected pageUnauthenticated users cannot view the page

9.3 Local Data and Privacy Tests

Test IDTest ItemExpected Result
VTP-SLV-PRIV-001Search for browsing-activity recordsNo browsing-content record exists
VTP-SLV-PRIV-002Search for DNS query recordsNo DNS query-content record exists
VTP-SLV-PRIV-003Search for original-IP activity recordsUnnecessary IP activity records are not created
VTP-SLV-PRIV-004Inspect error logsLogs contain no tokens, keys, or internal-link data
VTP-SLV-PRIV-005Inspect account-data storageOperating-system secure storage is used
VTP-SLV-PRIV-006Inspect diagnostic dataFull network-activity content is not included

10. Packet-Capture and Redacted API Evidence

Security conclusions relating to DNS, IPv6, routing, WebRTC, APIs, and internal links should retain corresponding redacted evidence.

10.1 Network Packet-Capture Evidence

Recommended evidence files include:

VTP-SLV-PCAP-DNS-001.pcapng
VTP-SLV-PCAP-IPV6-001.pcapng
VTP-SLV-PCAP-NETWORK-SWITCH-001.pcapng
VTP-SLV-PCAP-RECONNECT-001.pcapng
VTP-SLV-PCAP-WEBRTC-001.pcapng

Before public disclosure, the following information must be removed or redacted:

  • user tokens;

  • real VPN server addresses;

  • private domain names;

  • account identifiers;

  • order information;

  • encryption keys; and

  • production authentication information.

10.2 Redacted API Records

Recommended evidence files include:

VTP-SLV-API-001-unauthorized-request-redacted.json
VTP-SLV-API-002-invalid-token-redacted.json
VTP-SLV-API-003-rate-limit-redacted.json
VTP-SLV-API-004-internal-link-redacted.json

Each API evidence record should contain:

  • test time;

  • request method;

  • redacted endpoint identifier;

  • authentication state;

  • HTTP status code;

  • response-data structure;

  • whether internal link data was returned; and

  • final test result.

11. Security Risk Classification

Critical Risk

A critical-risk vulnerability may result in:

  • large-scale sensitive-data exposure;

  • remote code execution;

  • control of core systems;

  • complete authentication bypass; or

  • large-scale exposure of VPN traffic.

High Risk

A high-risk vulnerability may result in:

  • account takeover;

  • unauthorized access;

  • exposure of important private data;

  • VPN traffic bypass; or

  • access to internal configuration or link data.

Medium Risk

A medium-risk vulnerability generally requires specific conditions and may affect a limited platform, feature, or dataset.

Low Risk

A low-risk vulnerability has a lower direct impact but may weaken the overall security posture or increase risk when combined with other conditions.

Informational Recommendation

An informational recommendation is not directly exploitable but identifies an area where security engineering can be further improved.

12. Security Audit Results

Risk LevelNumber IdentifiedNumber Unresolved
Critical00
High00
Medium00
Low00

According to the testing results provided by VPNTestor Platform, no unresolved critical-, high-, medium-, or low-risk issue was identified within the tested versions and environments.

The potential attack surface associated with the VPN startup process, identified in early 2026, had been remediated before the formal audit.

The issue was included as a primary regression-testing item.

Post-remediation tests indicated that:

  • the original issue could not be reproduced;

  • unauthorized requests could not obtain internal VPN link data;

  • invalid sessions could not obtain protected configuration;

  • abnormal high-frequency requests were restricted;

  • request-parameter manipulation did not bypass access controls;

  • unofficial clients could not obtain protected data; and

  • the remediation did not introduce a new security vulnerability.

13. VPN Startup Process Issue and Remediation

13.1 Background

When a user starts a VPN connection, the client must obtain the configuration required to establish the connection from the backend.

This is a necessary component of the VPN connection process. However, if authentication, session verification, request restrictions, or internal data isolation are insufficient, the process may create a potential attack surface.

Potential risks included:

  • unauthorized attempts to obtain internal VPN link data;

  • unofficial clients probing the configuration interface;

  • automated repeated requests to the startup endpoint;

  • analysis of internal connection structures; and

  • high-frequency requests affecting normal endpoint operation.

13.2 Remediation Measures

SingLinkVPN subsequently modified the process by:

  • strengthening authentication for VPN startup requests;

  • adding session-validity checks;

  • restricting unofficial and unauthorized clients;

  • adding abnormal-request detection;

  • adding high-frequency request limits;

  • separating internal-link data from public interfaces;

  • reducing the amount of data returned by the interface;

  • adding automated-probing prevention controls; and

  • strengthening authorization between the client and backend.

13.3 Before-and-After Comparison

ItemBefore RemediationAfter Remediation
VPN startup requestBackend processed internal link requestsStronger identity and session validation added
Unauthorized requestPotential attack surface could be probedInternal link data cannot be obtained
Unofficial clientAdditional restrictions were requiredProtected configuration cannot be obtained
High-frequency requestsEndpoint could be repeatedly probedRate limits and attack-prevention controls are triggered
Internal link dataAccessible scope needed to be reducedIsolated from unauthorized requests
Post-remediation testingNot applicableOriginal issue not reproduced
New vulnerabilityNot applicableNo new vulnerability identified

The final status of the issue is:

Remediated, retested, and closed

14. DNS, IPv4, IPv6, and WebRTC Testing

Network security testing covered:

  • normal VPN connection establishment;

  • VPN server-initiated disconnection;

  • unexpected local network interruption;

  • Wi-Fi to 5G transition;

  • 5G to Wi-Fi transition;

  • device sleep and wake;

  • application restart;

  • abnormal VPN-process termination;

  • IPv4/IPv6 dual-stack environments;

  • WebRTC-related scenarios;

  • smart routing; and

  • global connection mode.

According to the test results, no consistently reproducible instance of the following was identified:

  • DNS leakage;

  • IPv4 address leakage;

  • IPv6 bypass;

  • WebRTC leakage;

  • routing bypass; or

  • sustained exposure of unprotected traffic.

When network conditions changed, the tested clients were able to re-establish, pause, or terminate the VPN connection according to the relevant operating system’s network mechanisms.

The audit did not identify a situation in which the client continued to send traffic through an unprotected path while displaying an active VPN connection.

15. Account and Web Dashboard Security

The audit covered:

  • unauthenticated access;

  • authentication tokens;

  • session validity periods;

  • token reuse after logout;

  • account-identifier manipulation;

  • cross-account data access;

  • subscription-data authorization;

  • page-level access controls;

  • repeated abnormal requests; and

  • frontend-backend interface access.

According to the test results:

  • unauthenticated users could not directly access protected account information;

  • invalid and expired tokens could not continue to be used;

  • modifying ordinary request parameters did not provide access to another user’s information;

  • subscription and account data were protected by the corresponding account permissions;

  • sessions were invalidated as expected after logout; and

  • the web dashboard passed the account-authorization tests included in this audit.

16. Privacy and Data-Handling Assessment

The audit assessed client data handling during:

  • application startup;

  • account sign-in;

  • VPN connection;

  • VPN location selection;

  • network errors;

  • application restart;

  • diagnostics and error handling;

  • web dashboard use; and

  • internal configuration requests.

Within the observable and tested scope, no functionality was identified that actively created records of:

  • users’ browsing content;

  • browsing history;

  • DNS query content;

  • complete network activity;

  • lists of websites visited; or

  • raw network traffic content.

The registration email aliases and order records retained by SingLinkVPN are used for subscription inquiries and after-sales support. They are not equivalent to browsing-content records or VPN network-activity logs.

The tests also did not identify a method by which an unauthorized request could directly obtain internal VPN link data.

17. Cross-Platform Test Conclusions

PlatformTest Conclusion
iOSPassed VPN connection, network transition, DNS, IP, account, and local-data tests
iPadOSPassed VPN connection, background recovery, and network-leak tests
Apple TVPassed sign-in, server connection, network recovery, and account-state tests
macOS Apple SiliconPassed TUN, DNS, routing, sleep recovery, and internal-link tests
macOS IntelPassed compatibility, VPN tunnel, DNS, and routing tests
AndroidPassed VPN Service, background connection, network transition, IPv6, and local-data tests
WindowsPassed tunnel, DNS, system routing, abnormal interruption, and reconnection tests
Linux UbuntuPassed VPN tunnel, DNS, routing, and permission tests
Linux DebianPassed installation, service startup, tunnel, and routing tests
Web user dashboardPassed sign-in, session, account-authorization, and cross-account access tests

18. Open-Source and Technical Transparency Assessment

SingLinkVPN has launched an ongoing open-source and technical-research program.

The first stage has begun publishing:

  • VPN development architecture;

  • security and privacy models;

  • performance-testing methodology;

  • test-data formats;

  • research and validation tools;

  • vulnerability-disclosure procedures; and

  • evidence and report-publication standards.

Future stages are intended to publish:

  • security reports;

  • performance reports;

  • transparency reports;

  • VPN protocols;

  • VPN clients; and

  • other core technologies that have completed security, privacy, and licensing reviews.

Open source does not automatically make a product secure.

The actual security of an open-source product still depends on:

  • security architecture;

  • code quality;

  • access control;

  • remediation speed;

  • dependency management;

  • version management;

  • continuous testing;

  • community review; and

  • responsible-disclosure procedures.

Based on the results of this security audit, the remediation of the known issue, and SingLinkVPN’s ongoing open-source direction, VPNTestor Platform concluded that SingLinkVPN met the technical-transparency and security-control requirements applied in this assessment.

19. 100-Point Scoring Methodology

The security assessment uses a total score of 100 points divided across seven categories:

Assessment CategoryPoints
VPN tunnel, DNS, and network leak protection25
Account, API, and internal-link security20
Local client data and privacy controls15
Cross-platform security consistency10
Web dashboard and session security10
Updates, installation packages, and supply-chain checks10
Known-issue remediation and retesting10
**Total****100**

Deduction Rules

Risk LevelDeduction per Finding
Critical30 points
High15 points
Medium7 points
Low2 points
Informational recommendationNo direct deduction; recorded as a future improvement item

The audit results were:

  • critical-risk findings: 0;

  • high-risk findings: 0;

  • medium-risk findings: 0;

  • low-risk findings: 0;

  • known VPN startup process issue: remediated before the formal audit;

  • remediation retest: passed; and

  • new vulnerability introduced by remediation: none identified.

The resulting final score was:

100/100

A score of 100 indicates that all test items listed in this report met VPNTestor Platform’s passing criteria and that no unresolved critical-, high-, medium-, or low-risk issue was identified.

The score applies only to the versions, devices, operating systems, network environments, and test scope listed in this report. It is not a permanent security guarantee for all future versions.

20. Why SingLinkVPN Received a Score of 100

SingLinkVPN received a score of 100 for the following reasons:

  • no critical-risk vulnerability was identified;

  • no high-risk vulnerability was identified;

  • no medium-risk vulnerability was identified;

  • no low-risk vulnerability was identified;

  • the principal platforms were included in testing;

  • separate version and test-environment records were used for each platform;

  • no consistently reproducible DNS leak was identified;

  • no consistently reproducible IPv4 leak was identified;

  • no consistently reproducible IPv6 leak was identified;

  • no consistently reproducible WebRTC leak was identified;

  • no consistently reproducible routing bypass was identified;

  • the account system and web dashboard passed authorization tests;

  • unauthorized requests could not obtain internal VPN link data;

  • the potential issue identified in early 2026 had been remediated;

  • the original issue could not be reproduced after remediation;

  • the remediation did not introduce a new vulnerability;

  • cross-platform security behavior met the test requirements; and

  • the technical documentation and open-source transparency program met the assessment requirements.

21. Does the User Need to Take Any Action?

Users of older SingLinkVPN versions should update to the latest official release available for their platform.

Because different platforms use independent version numbers, users should follow the official update prompt for their own platform rather than relying only on the macOS 2.5 version number.

Users should also:

  • download clients only from SingLinkVPN’s official channels or official application stores;

  • avoid modified clients from unknown sources;

  • keep their operating system on a supported version;

  • check regularly for client updates;

  • avoid sharing account credentials;

  • sign in again or update the server configuration if abnormal connection behavior occurs.

Users already running the latest official version available for their platform do not need to take additional security action based on this audit.

22. Audit Limitations

The results of this audit apply to:

  • the July 2026 audit period;

  • the tested versions listed in this report;

  • the test devices listed in this report;

  • the operating systems listed in this report;

  • the network environments listed in this report;

  • the test cases listed in this report; and

  • the product state provided during the audit.

The report does not cover features, protocols, third-party dependencies, or backend deployment changes introduced after the completion of the audit.

Additional security testing should be performed when SingLinkVPN makes a material change to:

  • VPN protocols;

  • iOS or iPadOS clients;

  • Android clients;

  • macOS clients;

  • Windows clients;

  • Linux clients;

  • Apple TV clients;

  • the web user dashboard;

  • account and authentication systems;

  • server-configuration systems;

  • third-party dependencies; or

  • update and release processes.

23. Final Audit Conclusion

Based on the third-party security audit completed by VPNTestor Platform in July 2026, the platform reached the following conclusions:

  1. No critical-risk vulnerability was identified in the tested products.

  2. No high-risk vulnerability was identified.

  3. No medium-risk vulnerability was identified.

  4. No low-risk vulnerability was identified.

  5. The iOS and iPadOS clients passed the security tests.

  6. The Apple TV client passed the security tests.

  7. The Apple Silicon and Intel macOS clients passed the security tests.

  8. The Android client passed the security tests.

  9. The Windows client passed the security tests.

  10. The Linux clients passed the security tests.

  11. The web user dashboard passed the account and authorization tests.

  12. No consistently reproducible DNS leak was identified.

  13. No consistently reproducible IPv4 or IPv6 leak was identified.

  14. No consistently reproducible WebRTC leak was identified.

  15. No consistently reproducible routing bypass was identified.

  16. Unauthorized requests could not obtain internal VPN link data.

  17. The VPN startup-process issue identified in early 2026 had been remediated.

  18. The original issue could not be reproduced after remediation.

  19. No new vulnerability introduced by the remediation was identified.

  20. SingLinkVPN passed all scoring categories included in this third-party security audit.

VPNTestor Platform assigned the tested SingLinkVPN products a final security rating of:

100/100

Audit Result: Fully Passed

Within the versions, devices, operating systems, network environments, and audit scope described in this report, VPNTestor Platform did not identify any unresolved critical-, high-, medium-, or low-risk vulnerability in SingLinkVPN.

SingLinkVPN met all standards applied in this audit for VPN connection security, network leak protection, cross-platform security consistency, account authorization, privacy controls, and internal-link protection.

As SingLinkVPN continues to open-source its technical documentation, research data, VPN protocols, clients, and other core technologies, its security design will become increasingly available for ongoing inspection, verification, and reproduction by external researchers.

24. Report Signature

VPNTestor Platform Independent Testing and Audit Team: Openscore VPN

James Robert Smith Audit Lead VPNTestor Platform

Report Version: 1.2 Audit Period: July 2026 Audit Target: SingLinkVPN Final Rating: 100/100 Final Result: Fully Passed

Signature Date: 2026-07-31 Organization Email: [email protected] Digital Signature: Ed25519 signature of the v1.2 six-language manifest, verifiable with the published public key Report Integrity: Per-language SHA-256 values are published in the v1.2 six-language manifest; a single self-referential report hash is intentionally not embedded here.

<!-- annual-audit-records:start -->

25. 2026 Multi-Version Security Verification Record (Continuously Updated)

This section provides a cumulative record of new versions verified after the audit was completed. The July 2026 report, original publication date, signature, and historical conclusions remain preserved; subsequent updates only add new records.

Public content includes only versions, dates, verification results, and integrity verification values. Product architecture, operating logic, configurations, network information, issue details, and complete original records are not publicly disclosed and are retained by VPNTestor Platform in a restricted audit archive.

25.1 Latest Complete Signed Report

Current status: the complete signed report and its integrity-signed English translation have been published.

VPNTestor Platform has consolidated the macOS 2.5.7, Windows 2.5.8, and new-protocol security verification records into the complete 2026 v2.0 report. The report received a final rating of 100/100, with a final result of Pass, and was digitally signed by James Robert Smith. The English document is a faithful translation of that signed v2.0 report; the multilingual translation set is covered by a separate integrity manifest and signature.

25.2 Latest Version Results

Platform and versionVerification scopeResultPublic evidence
Windows 2.5.8 / build 3077New-protocol security verification7/7 items passed, 100% pass rate[View public summary](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-Windows-2.5.8-3077-Sola-Runtime-Audit-Addendum-2026-08-24-en.md)
Windows 2.5.8 / build 3077Version and runtime security verificationAll listed items passed, 100% pass rate[View public summary](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-Windows-2.5.8-3077-Runtime-Audit-Evidence-2026-08-24-en.md)
macOS 2.5.7 / build 3065Release security verification6/6 items passed, 100% pass rate[View public summary](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-macOS-2.5.7-3065-DMG-Evidence-2026-08-24-en.md)
macOS 2.5.6 / build 3064New-protocol security verification7/7 items passed, 100% pass rate[View public summary](/downloads/security-audits/singlinkvpn-v2.5-2026/Sola-Protocol-Runtime-Audit-Evidence-2026-08-16-en.md)

All listed security verification items passed for the versions and retained test records above, with no unresolved security issues identified.

25.3 Public Evidence Protection Principles

  • Public summaries retain the version, build number, date, verification conclusion, and evidence verification values.

  • Complete original records are retained in a restricted audit archive and are not available for public download.

  • Public materials do not disclose product architecture, implementation methods, operating logic, configurations, network information, device information, or issue details.

  • Each update creates a new record and does not delete or overwrite dates or conclusions from earlier versions.

  • VPNTestor Platform independently conducts and records verification and does not substitute product promotional content for test results.

25.4 Version and Evidence History

Record datePlatform and versionCumulative updateStatus
2026-07-28SingLinkVPN v2.5Initial publication of the 2026 security audit reportPublished; original publication date retained
2026-08-01macOS 2.5.6 / build 3056Added formal installation-sample verification recordVerified
2026-08-16macOS 2.5.6 / build 3064Added new-protocol security verification and evidence verification values7/7 items passed, 100% pass rate
2026-08-19macOS 2.5.7 / build 3065Added formal installation-sample and release security records6/6 items passed, 100% pass rate
2026-08-24Windows 2.5.8 / build 3077Added version, installation-sample, and runtime security recordsAll listed items passed, 100% pass rate
2026-08-24 20:22Windows 2.5.8 / build 3077Added new-protocol security verification and cumulative evidence verification values7/7 items passed, 100% pass rate
2026-08-24 20:28Public-material protection updateApplied consistent redaction to the webpage and downloadable summaries; detailed evidence remains in the restricted archiveCompleted
2026-08-24 20:58Current-version complete report v2.0Consolidated macOS 2.5.7, Windows 2.5.8, and new-protocol verification records; froze the report and four evidence summariesComplete, 100/100, signed and successfully verified

25.5 Integrity and Historical Preservation

The July 2026 v1.2 report, its six-language verification manifest, and digital signature remain preserved as historical records. The current version uses a separate v2.0 complete report and source-report signature, together with a separately signed multilingual translation manifest, and does not modify the frozen historical report.

The original publication date of this page remains 2026-07-28, while the page also displays the latest update date. Future audits will continue to be appended by date.

26. Mobile Security Audit Supplement: Android / iOS 2.5 Series

Testing and reporting: VPNTestor test team. Test date: 2026-09-11. This report consolidates Android / iOS 2.5 series sample verification, runtime records and real-device connection and recovery tests.

Confirmed audit conclusions: SingLinkVPN passed this platform's 2026 security audit and the independent no-activity-logs verification dated 2026-07-29. In the original security audit's tested versions and environments, no consistently reproducible DNS, IPv4, IPv6 or WebRTC leaks or routing bypasses were found. This mobile 2.5 series record adds version, connection and recovery results.

26.1 Android 2.5 Series

The specific sample is Android 2.5.8, build 5066. The installation file was obtained from the official distribution channel on 2026-09-11 and is 60,353,364 bytes in size. File integrity, the version embedded in the package, and the release signature have been verified successfully.

Sample SHA-256: 3d60e21b610bc12988992e055f45eceaf4d4cab46204de60dbb3d65869f20659.

A partial static review of the installation sample has been completed. No hard-coded private keys or tokens were found among the common credential patterns examined, and no known vulnerabilities were found in the limited set of identifiable dependencies queried. This review does not cover every dependency or all runtime behavior.

The VPNTestor test team's Android runtime records include one public video and eight screenshots covering connection status, service access, speed-testing processes, node selection, device management, support, rule settings and desktop widgets.

View the Android 2.5 series runtime demonstration. The public title of this video identifies version 2.5.6, and it is retained as series-level runtime material; the precise identity of the 2.5.8 sample is governed by the installation-file record in this section. No verifiable binding has been established between the screenshots or video and that installation file.

26.2 iOS 2.5 Series

The official distribution channel, App Store information, and application metadata from a connected device have been verified. The sample that can be verified in this review is App Store version 2.5.1, build 18; its App Store ID is 6759948234. This document uses iOS 2.5 Series as the product-scope name while retaining the precise version in the sample record.

This section records distribution and installed-version identity. iOS runtime and device-test results appear in Sections 27 and 28.

26.3 Evidence Scope and Public Materials

Security audit: passed. Sections 14 and 23 of the 2026 security audit record no consistently reproducible network leaks in the original tested versions and environments, with all listed assessment categories passed.

No-activity-logs verification: passed. The 2026-07-29 independent no-logs report used read-only production inspection to confirm that the inspected system design matched the strict no-activity-logs policy. It found no persistent records of users' websites, DNS queries, original IP addresses or communication content. This conclusion comes from the dedicated backend and infrastructure audit.

Sections 26–28 document the current mobile version checks and device results. Security and no-logs conclusions retain the dates, versions and systems identified in their source reports; the feature-adaptation record does not replace those security tests.

Accounts, device identifiers, subscriptions, traffic information and internal technical details in original screenshots remain in the restricted archive. This revision signs the six-language consolidated report and screenshot checksum lists, verifying file integrity and the publishing key.

Download this public supplement. Download the six-language file checksum manifest. The checksum manifest is provided for file-integrity verification.

26.4 Added-Record Timeline

  • 2026-09-11: Completed identity, integrity, and signature verification for the Android 2.5.8 installation file and recorded the scope of the partial static review.

  • 2026-09-11: Reviewed the public Android 2.5 series runtime video and eight test screenshots, recording their version attribution and privacy-protection boundaries.

  • 2026-09-11: Completed verification of the official iOS 2.5 series distribution channel and installed-version metadata, and added this public supplement.

27. iOS 2.5 series: additional runtime evidence and signature record

2026-09-11: the VPNTestor test team recorded seven iOS runtime screenshots, public-video page verification and connected-device version verification.

Seven iOS test screenshots record connected client and widget states, feature and settings interfaces, and in-app network-check responses. The download test shows an instantaneous reading of 1,032.52 Mbps, archived as an in-progress measurement.

The public video page, title and preview were checked. Its title identifies an iOS 2.5 internal-test build, archived as a series demonstration; installed-version identity follows the device metadata record.

On 2026-09-11, a read-only query of the connected iPhone 16 Pro Max confirmed SingLinkVPN 2.5.1, build 18, matching the sample archive.

The VPNTestor test team records the release change scope as protocol adaptation and feature optimization. Historical security conclusions retain their original version scope; current connection and recovery results appear in Section 28.

All three device recovery checks were normal; itemized results appear in Section 28.

Accounts, device identifiers, subscriptions, traffic information and internal technical details in original screenshots remain in the restricted archive. This revision signs the six-language consolidated report and screenshot checksum lists, verifying file integrity and the publishing key.

27.1 Evidence and verification downloads

28. Android / iOS 2.5 series: connection and recovery test results

Connection and recovery test results | 2026-09-11 | Revision 4

The VPNTestor test team completed this batch of connection, browser local-address and real-device recovery tests. The test records follow.

RecordAndroid 2.5 seriesiOS 2.5 series
Screenshots in this batch63
Version archive (previously verified)2.5.8, build 50662.5.1, build 18
State during submitted IP checksVPN enabledVPN enabled
Local-address check materials2 result screenshots1 result in 2 views

The version archive indexes earlier sample records; this screenshot batch is filed under the 2.5 series.

Connection and address checks

Test itemReviewed resultEvidence source
Android node connectionBoth node interfaces display connected statusConnection screenshots in this batch
Android exit addressTwo IP-check records display different exit valuesIP-check screenshots in this batch
Android local-address enumerationA local-scope network address was detected; no public address was listed in the results2 browser-result screenshots
iOS local-address enumerationAn anonymized hostname was detected; no numeric IP address was listed in the result2 views of the same browser result

Device recovery tests

Test itemAndroid resultiOS resultEvidence source
Recovery after screen lockNormal; usable on openingNormal; usable on openingVPNTestor device test records
Recovery after network switchingNormal; usable on openingNormal; usable on openingVPNTestor device test records
Recovery after network interruptionNormal; usable on openingNormal; usable on openingVPNTestor device test records

Result summary: All 3 recovery scenarios on each platform were normal. Screenshots document Android connection status and exit-value changes. Android local enumeration returned a local-scope address; iOS returned an anonymized hostname.

Method: VPNTestor device operations and screenshot records. The browser check measures local-address visibility without external STUN/TURN services. Recovery checks record post-operation usability qualitatively rather than in milliseconds. DNS, IPv6 and continuous traffic-leak conclusions refer to the original security audit scope cited in Section 26.3.

Evidence and privacy: Checksums register 9 original images. Specific IP addresses, accounts and device identifiers are not public. The revision signature verifies file integrity and the publishing key; it does not change test provenance or expand the conclusions.

28.1 Evidence and signature downloads

Historical signed archives (superseded editions)

Every claim in this note rests on the site's published method. Read it in full on the methodology page, or return to the notebook.