Latest audit navigation · Append-only, with history preserved
Latest-Version Security Audits and Evidence Downloads
Browse security audits and evidence by platform. Version checks, runtime materials and recovery tests for each series are grouped together; original report URLs, publication dates, historical conclusions, downloads and digital signatures remain unchanged.
2026-09-11iOS 2.5 series security auditExisting security and no-logs audit conclusions, current mobile tests and signed evidence in one place.View audit and evidence ↕
Version information is verified. This batch contains 3 reviewed screenshots; the local-address check returned an anonymized hostname. The VPNTestor test team recorded normal recovery in all 3 scenarios: screen lock, network switching and interruption. See the results report for itemized outcomes and methodology.
2026-09-11Android 2.5 series security auditExisting security and no-logs audit conclusions, current mobile tests and signed evidence in one place.View audit and evidence ↕
Sample information is verified. This batch contains 6 reviewed screenshots: two connected-node interfaces and IP-check records with different exit values. The local-address check returned a local-scope address. The VPNTestor test team recorded normal recovery in all 3 scenarios. See the results report for outcomes and methodology.
Audit and Evidence Update History
This article was first published; the original publication date remains preserved, and the v1.2 report is not rewritten by subsequent updates.
Recorded the formal installation sample, signature, and notarization verification status for macOS 2.5.6 / build 3056.
Added new-protocol security verification and evidence verification values for macOS 2.5.6 / build 3064.
Recorded release security verification and integrity evidence for macOS 2.5.7 / build 3065.
Added the installation sample and version security verification record for Windows 2.5.8 / build 3077.
Added the Windows 2.5.8 / build 3077 new-protocol security verification, with 7/7 items passing.
Applied consistent redaction to the webpage and downloadable summaries; detailed evidence remains in the restricted archive.
Published the current-version v2.0 complete security audit report with a final rating of 100/100 and completed its digital signature.
Updated iOS / Android 2.5 series version and sample verification, runtime materials, screenshot review, VPNTestor device recovery tests and signed evidence. Each conclusion retains the scope of its source record.
This timeline is a quick summary; Section 25 of the report retains the dates, results, and integrity records for each version.
SingLinkVPN Independent Security Audit Report (2026)
Audit Organization: VPNTestor Platform Independent Testing and Audit Team: Openscore VPN Lead Auditor: James Robert Smith Audit Target: SingLinkVPN Audit Type: Third-Party VPN Security Audit Audit Period: July 2026 Report Version: 1.2
Public Report Files and Integrity Verification
VPNTestor is the original publisher of this independent audit. The report body below preserves the complete canonical audit structure and conclusions. The integrity artifacts verify the frozen six-language report set; they do not, by themselves, prove execution of every underlying test.
Download James Robert Smith’s Ed25519 signature of the manifest.
Read the separate 2026 no-logs verification and signed evidence package.
In July 2026, VPNTestor Platform completed a third-party security audit of SingLinkVPN’s principal products and services.
The audit covered SingLinkVPN applications for iOS, iPadOS, Android, macOS, Windows, Linux, and Apple TV, together with the web-based user dashboard.
The assessment focused on VPN connection processes, network leak protection, internal link protection, account and session security, local data handling, cross-platform security consistency, and verification of previously implemented security fixes.
Because SingLinkVPN uses separate version numbers and release processes for different platforms, this report records the tested version and environment for each platform individually. It does not describe every client as using the same version number.
According to the audit results provided by VPNTestor Platform, no unresolved critical-, high-, medium-, or low-risk security vulnerabilities were identified within the tested versions, devices, operating systems, network environments, and audit scope described in this report.
In early 2026, SingLinkVPN identified and addressed a potential security issue related to the VPN startup process. The issue concerned requests made by the client to the backend for internal connection configuration and VPN link information during connection establishment.
SingLinkVPN subsequently strengthened authentication, access control, abnormal-request detection, rate limiting, internal data isolation, and automated-attack prevention controls.
VPNTestor Platform repeated the relevant tests on the remediated versions. The original issue could not be reproduced, and no new exploitable security issue was identified as a result of the remediation.
Based on the results of this audit, SingLinkVPN passed all listed security assessment categories and received a final score of:
100/100 Security Rating
Audit Result: Fully Passed
1. Audit Summary
| Item | Audit Information |
|---|---|
| Audit organization | VPNTestor Platform |
| Independent testing and audit team | Openscore VPN |
| Lead auditor | James Robert Smith |
| Audit target | SingLinkVPN |
| Audit type | Third-party security audit |
| Audit period | July 2026 |
| Platforms covered | iOS, iPadOS, Android, macOS, Windows, Linux, Apple TV, and web user dashboard |
| Confirmed macOS version | 2.5 series |
| Other platform versions | Recorded independently for each platform |
| Audit report version | 1.2 |
| Critical-risk findings | 0 |
| High-risk findings | 0 |
| Medium-risk findings | 0 |
| Low-risk findings | 0 |
| Previously identified security issue | Potential attack surface in the VPN startup process |
| Remediation status | Remediated |
| Remediation retest | Original issue not reproduced; no new vulnerability identified |
| Final rating | 100/100 |
| Final result | Fully passed |
2. Audit Statement
This report was prepared by VPNTestor Platform based on the tested products, test environments, technical materials, and remediation-verification results.
VPNTestor is the publishing and verification platform. Openscore VPN is the professional team that independently performs the testing and audit; VPNTestor then reviews and confirms the resulting assessment.
The audit was led by James Robert Smith.
SingLinkVPN was responsible for providing the clients, test accounts, product information, remediation versions, and environments required for the audit.
VPNTestor Platform was responsible for the testing methodology, risk classification, result assessment, remediation retesting, and final score.
The conclusions in this report apply to:
the July 2026 audit period;
the platforms listed in this report;
the product versions listed in this report;
the test devices listed in this report;
the operating systems listed in this report;
the network environments listed in this report;
the test cases listed in this report; and
the product state supplied during the audit period.
The phrase “no vulnerability identified” means that no unresolved vulnerability was identified or reproduced within the defined audit scope. It does not mean that any software product can be guaranteed to remain free of vulnerabilities in every future version and environment.
3. About VPNTestor Platform
VPNTestor Platform evaluates VPN products across the following areas:
VPN tunnel and connection security;
DNS and IP leak protection;
IPv6 and WebRTC leak protection;
network interruption and reconnection behavior;
Kill Switch and routing protection;
account and session security;
API and internal configuration protection;
local client data handling;
web dashboard access controls;
cross-platform security consistency;
third-party dependency and installation-package security;
vulnerability remediation and regression testing; and
technical transparency and open-source materials.
VPN security cannot be assessed solely through product marketing, privacy-policy statements, or a single successful connection test.
This audit therefore combined live client testing, abnormal network scenarios, simulated unauthorized requests, network traffic analysis, account authorization testing, and post-remediation regression testing.
4. Tested Platforms, Versions, and Environments
4.1 Complete Tested Platform Information
| Platform | Product/Public Version | Tested Distribution | Primary Test Devices | Operating System Environment | Evidence Reference |
|---|---|---|---|---|---|
| iOS | SingLink 2.0.7 / App Store 1.0.7 | Official App Store release | iPhone 15 Pro, iPhone SE (3rd generation) | iOS 18.x and supported releases | SLV-IOS-2026-01 |
| iPadOS | SingLink 2.0.7 / App Store 1.0.7 | Official App Store release | 11-inch iPad Pro, iPad (10th generation) | iPadOS 18.x and supported releases | SLV-IPAD-2026-01 |
| Apple TV | SingLink 2.0.7 / App Store 1.0.7 | Apple TV App Store release | Apple TV 4K (3rd generation) | tvOS 17 and later supported releases | SLV-TVOS-2026-01 |
| macOS Apple Silicon | SingLinkVPN 2.5.3 | ARM64 installation package | MacBook Pro with M3 Pro, MacBook Air with M2 | macOS 14 and macOS 15 | SLV-MAC-ARM-2026-01 |
| macOS Intel | SingLinkVPN 2.5.3 | x86_64 installation package | 2019 Intel MacBook Pro | macOS 13 and macOS 14 | SLV-MAC-INTEL-2026-01 |
| Android | SingLinkVPN 2.1.3 | Android APK | Google Pixel 9 Pro, Samsung Galaxy S24 | Android 15 and Android 16 | SLV-ANDROID-2026-01 |
| Windows | SingLinkVPN 2.0.9 | Windows x64 installation package | Intel and AMD x64 test systems | Windows 11 24H2 and Windows 10 22H2 | SLV-WIN-2026-01 |
| Linux Ubuntu | July 2026 official test package | Debian/Ubuntu package | Intel and AMD x86_64 test systems | Ubuntu 24.04 LTS | SLV-LINUX-UBU-2026-01 |
| Linux Debian | July 2026 official test package | Debian package | Intel x86_64 test system | Debian 12 | SLV-LINUX-DEB-2026-01 |
| Web user dashboard | July 2026 deployment version | Web frontend and backend API | Desktop and mobile browsers | Current releases of Chrome, Edge, Firefox, and Safari | SLV-WEB-2026-01 |
4.2 Versioning Notes
SingLinkVPN uses independent version numbers for different platforms.
This report records that:
iOS, iPadOS, and Apple TV use their corresponding App Store versions;
the tested macOS applications belong to the 2.5 series;
separate installation packages are used for Apple Silicon and Intel-based Macs;
Android uses an independent Android product version;
Windows uses an independent desktop product version;
Linux is identified by the official package supplied during the audit; and
the web user dashboard is identified by its deployment version, backend release, or Git commit.
This report therefore does not state that all platforms use version 2.5.
5. Build Numbers, Installation Files, and File Hashes
A separate build and integrity record should be retained for every tested client.
The signed PDF report and technical annex should include the following information:
| Platform | Build Information | File Verification Information |
|---|---|---|
| iOS | `CFBundleVersion` or App Store Connect build number | SHA-256 of the audited IPA |
| iPadOS | `CFBundleVersion` or App Store Connect build number | SHA-256 of the audited IPA |
| Apple TV | tvOS application `CFBundleVersion` | SHA-256 of the audited IPA |
| macOS Apple Silicon | `CFBundleShortVersionString` and `CFBundleVersion` | SHA-256 of the ARM64 DMG or PKG |
| macOS Intel | `CFBundleShortVersionString` and `CFBundleVersion` | SHA-256 of the x86_64 DMG or PKG |
| Android | `versionName` and `versionCode` | SHA-256 of the APK |
| Windows | File Version and Product Version | SHA-256 of the EXE or MSI |
| Linux | Package version and architecture | SHA-256 of the DEB, RPM, or installation package |
| Web user dashboard | Git commit, release ID, or deployment ID | Container image digest or artifact hash |
Historical Original Input Template (Preserved Record, Not a Current Audit Task)The original v1.2 content remains unchanged; see the v2.0 complete signed report at the top of the page for current conclusions and evidence.Expand historical source text
Final Report Entry Format
The template below is retained from the original canonical report. The audited IPA hashes, newer Linux package hash, and web deployment digest were not supplied for public release. Known macOS, Android, and Windows official release-file values are recorded in the evidence table immediately after the template; those later values are official distribution checksums, not audit-retained sample hashes.
iOS Build: [To be completed]
iOS IPA SHA-256: [To be completed]
Apple TV Build: [To be completed]
Apple TV IPA SHA-256: [To be completed]
macOS ARM64 Build: [To be completed]
macOS ARM64 SHA-256: [To be completed]
macOS Intel Build: [To be completed]
macOS Intel SHA-256: [To be completed]
Android Version Code: [To be completed]
Android APK SHA-256: [To be completed]
Windows Build: [To be completed]
Windows EXE/MSI SHA-256: [To be completed]
Linux Package Version: [To be completed]
Linux Package SHA-256: [To be completed]
Web Release/Commit: [To be completed]
Web Container Digest: [To be completed]Build numbers and file hashes must be obtained directly from the actual audited installation files or deployment systems. Estimated values or randomly generated strings must not be used.
Official Release-File Verification Values Added After the Audit
The following values were obtained from the current files distributed through the official SingLinkVPN website on 2026-07-27. They are published as official release-file verification values. They are not represented as hashes of original audit-retained samples, and they do not replace the build and artifact records required for a fully reproducible audit archive.
| Platform | Official release file | File size | SHA-256 |
|---|---|---|---|
| macOS Apple Silicon | SingLinkVPN 2.5.3 ARM64 DMG | 70,568,669 bytes | `5857cb3e6ded51362234bf2246958612cea10fab0d416f174faf7e9121708d24` |
| macOS Intel | SingLinkVPN 2.5.3 x86_64 DMG | 72,270,725 bytes | `5bba2c37a76ef8cb67bdfa15506c581d73faab73275bba73b83ec6ca5d110ad0` |
| Android | SingLinkVPN 2.1.3 APK | 86,649,334 bytes | `81146be4136097eded546d9175fc9feba85174739d7a74a76563b4ebdb80d152` |
| Windows | SingLinkVPN 2.0.9 x64 EXE | 31,391,424 bytes | `2eb39c432aacdcb05aa93b89451e3022b2c6f55548ba56b52de25a4499007795` |
For iOS, iPadOS, and Apple TV, the public version, Apple platform review, and code-signing state can be checked through the official App Store distribution. Apple review is not a third-party security audit, and no SHA-256 for the audit IPA is published here. The newer Linux package and the web release/commit or container digest were not available in the supplied public release-file evidence.
6. Audit Scope
6.1 VPN Connection and Tunnel Security
The audit covered:
normal VPN connection establishment;
user-initiated VPN disconnection;
unexpected VPN server disconnection;
automatic reconnection;
repeated connection requests;
forced application termination;
device sleep and wake behavior;
network transitions;
route creation and cleanup; and
consistency between the displayed VPN status and the actual tunnel state.
6.2 DNS and IP Leak Protection
The audit covered:
DNS leaks;
IPv4 exit-address behavior;
IPv6 bypass risks;
WebRTC leaks;
local network address exposure;
traffic behavior during VPN interruption;
routing behavior during reconnection; and
smart-routing and global-connection modes.
6.3 Account and Session Security
The audit covered:
sign-in processes;
token validity;
expired tokens;
token reuse after logout;
unauthenticated access;
account identifier manipulation;
cross-account data access;
subscription-data permissions;
session revocation; and
multi-device account state.
6.4 API and Internal Link Security
The audit covered:
unauthorized internal configuration requests;
invalid token requests;
expired sessions;
unofficial client requests;
request-parameter manipulation;
repeated high-frequency requests;
automated endpoint probing;
isolation of internal VPN link data; and
attack-prevention and rate-limiting controls.
6.5 Local Data and Privacy
The audit covered:
credential storage;
token storage;
error logs;
debug information;
diagnostic information;
browsing-activity records;
DNS query records;
original IP records;
local caches; and
operating-system secure storage mechanisms.
6.6 Web User Dashboard
The audit covered:
unauthenticated access;
account-page authorization;
order and subscription information;
tokens and cookies;
request-parameter manipulation;
cross-account access;
frontend and backend interfaces; and
logout and session invalidation.
6.7 Updates and Supply Chain
The audit covered:
installation-file integrity;
digital signatures;
update sources;
version downgrade risks;
third-party dependencies;
hardcoded secrets;
debug information in production builds; and
installation-package architecture and permissions.
7. Test Network Environments
To avoid drawing conclusions from a single network configuration, the audit covered the following environments:
| Network Environment | Testing Objective |
|---|---|
| IPv4 residential broadband | General VPN connection, DNS, and exit-IP testing |
| IPv4/IPv6 dual-stack network | IPv6 bypass and dual-stack DNS testing |
| 4G mobile network | Mobile connectivity and reconnection |
| 5G mobile network | High-speed mobile networking and CGNAT conditions |
| Public Wi-Fi | Untrusted local network conditions |
| Wi-Fi to 5G transition | Network migration and tunnel re-establishment |
| 5G to Wi-Fi transition | Route recovery and DNS refresh |
| Temporary network interruption | Automatic reconnection |
| Abnormal DNS environment | DNS handling and leak protection |
| High-latency and packet-loss environment | Connection-failure and recovery handling |
8. Audit Methodology
VPNTestor Platform used the following methods according to platform and feature:
live client execution testing;
black-box functional testing;
gray-box interface testing;
network packet analysis;
DNS and routing tests;
IPv4 and IPv6 exit testing;
WebRTC network testing;
unauthorized API access testing;
session and token testing;
high-frequency request and rate-limit testing;
local data inspection;
installation-package and signature inspection;
pre-remediation and post-remediation behavior comparison;
post-remediation regression testing; and
cross-platform security behavior comparison.
Every item described as “passed” or “not identified” in this report should correspond to at least one test case and evidence reference.
9. Formal Test Cases
9.1 VPN Connection and Network Security
| Test ID | Test Item | Expected Result |
|---|---|---|
| VTP-SLV-NET-001 | Establish a normal VPN connection | Tunnel is established and the public exit IP changes correctly |
| VTP-SLV-NET-002 | User-initiated VPN disconnection | Tunnel and associated routes are removed correctly |
| VTP-SLV-NET-003 | Unexpected VPN server disconnection | Client stops safely or reconnects automatically |
| VTP-SLV-NET-004 | Switch from Wi-Fi to 5G | No sustained unprotected traffic exposure |
| VTP-SLV-NET-005 | Switch from 5G to Wi-Fi | Tunnel is re-established and routing is restored |
| VTP-SLV-NET-006 | Device sleep and wake | VPN and routing state are revalidated |
| VTP-SLV-NET-007 | Force-terminate the client | No invalid proxy state or incorrect route remains |
| VTP-SLV-DNS-001 | DNS leak test | DNS requests do not bypass the designated secure path |
| VTP-SLV-IPV4-001 | IPv4 exit test | Public exit IP matches the selected VPN location |
| VTP-SLV-IPV6-001 | IPv6 leak test | IPv6 traffic does not bypass the VPN |
| VTP-SLV-WRTC-001 | WebRTC test | Local addresses that should remain private are not exposed |
| VTP-SLV-ROUTE-001 | Routing-table inspection | Routing and split-tunneling rules match the selected configuration |
9.2 Account, API, and Internal Link Tests
| Test ID | Test Item | Expected Result |
|---|---|---|
| VTP-SLV-AUTH-001 | Unauthenticated request | Unauthorized response is returned |
| VTP-SLV-AUTH-002 | Invalid token | Request is rejected |
| VTP-SLV-AUTH-003 | Expired token | Session becomes invalid |
| VTP-SLV-AUTH-004 | Reuse token after logout | Previous token can no longer be used |
| VTP-SLV-API-001 | Unauthorized internal-link request | No internal VPN link data is returned |
| VTP-SLV-API-002 | Request-parameter manipulation | Access controls cannot be bypassed |
| VTP-SLV-API-003 | Repeated high-frequency requests | Rate limiting or attack-prevention controls are triggered |
| VTP-SLV-API-004 | Unofficial client request | Protected configuration cannot be obtained |
| VTP-SLV-WEB-001 | Attempt to access another user’s data | Request is rejected |
| VTP-SLV-WEB-002 | Modify account identifier | Other users’ account data is not returned |
| VTP-SLV-WEB-003 | Direct access to a protected page | Unauthenticated users cannot view the page |
9.3 Local Data and Privacy Tests
| Test ID | Test Item | Expected Result |
|---|---|---|
| VTP-SLV-PRIV-001 | Search for browsing-activity records | No browsing-content record exists |
| VTP-SLV-PRIV-002 | Search for DNS query records | No DNS query-content record exists |
| VTP-SLV-PRIV-003 | Search for original-IP activity records | Unnecessary IP activity records are not created |
| VTP-SLV-PRIV-004 | Inspect error logs | Logs contain no tokens, keys, or internal-link data |
| VTP-SLV-PRIV-005 | Inspect account-data storage | Operating-system secure storage is used |
| VTP-SLV-PRIV-006 | Inspect diagnostic data | Full network-activity content is not included |
10. Packet-Capture and Redacted API Evidence
Security conclusions relating to DNS, IPv6, routing, WebRTC, APIs, and internal links should retain corresponding redacted evidence.
10.1 Network Packet-Capture Evidence
Recommended evidence files include:
VTP-SLV-PCAP-DNS-001.pcapng
VTP-SLV-PCAP-IPV6-001.pcapng
VTP-SLV-PCAP-NETWORK-SWITCH-001.pcapng
VTP-SLV-PCAP-RECONNECT-001.pcapng
VTP-SLV-PCAP-WEBRTC-001.pcapngBefore public disclosure, the following information must be removed or redacted:
user tokens;
real VPN server addresses;
private domain names;
account identifiers;
order information;
encryption keys; and
production authentication information.
10.2 Redacted API Records
Recommended evidence files include:
VTP-SLV-API-001-unauthorized-request-redacted.json
VTP-SLV-API-002-invalid-token-redacted.json
VTP-SLV-API-003-rate-limit-redacted.json
VTP-SLV-API-004-internal-link-redacted.jsonEach API evidence record should contain:
test time;
request method;
redacted endpoint identifier;
authentication state;
HTTP status code;
response-data structure;
whether internal link data was returned; and
final test result.
11. Security Risk Classification
Critical Risk
A critical-risk vulnerability may result in:
large-scale sensitive-data exposure;
remote code execution;
control of core systems;
complete authentication bypass; or
large-scale exposure of VPN traffic.
High Risk
A high-risk vulnerability may result in:
account takeover;
unauthorized access;
exposure of important private data;
VPN traffic bypass; or
access to internal configuration or link data.
Medium Risk
A medium-risk vulnerability generally requires specific conditions and may affect a limited platform, feature, or dataset.
Low Risk
A low-risk vulnerability has a lower direct impact but may weaken the overall security posture or increase risk when combined with other conditions.
Informational Recommendation
An informational recommendation is not directly exploitable but identifies an area where security engineering can be further improved.
12. Security Audit Results
| Risk Level | Number Identified | Number Unresolved |
|---|---|---|
| Critical | 0 | 0 |
| High | 0 | 0 |
| Medium | 0 | 0 |
| Low | 0 | 0 |
According to the testing results provided by VPNTestor Platform, no unresolved critical-, high-, medium-, or low-risk issue was identified within the tested versions and environments.
The potential attack surface associated with the VPN startup process, identified in early 2026, had been remediated before the formal audit.
The issue was included as a primary regression-testing item.
Post-remediation tests indicated that:
the original issue could not be reproduced;
unauthorized requests could not obtain internal VPN link data;
invalid sessions could not obtain protected configuration;
abnormal high-frequency requests were restricted;
request-parameter manipulation did not bypass access controls;
unofficial clients could not obtain protected data; and
the remediation did not introduce a new security vulnerability.
13. VPN Startup Process Issue and Remediation
13.1 Background
When a user starts a VPN connection, the client must obtain the configuration required to establish the connection from the backend.
This is a necessary component of the VPN connection process. However, if authentication, session verification, request restrictions, or internal data isolation are insufficient, the process may create a potential attack surface.
Potential risks included:
unauthorized attempts to obtain internal VPN link data;
unofficial clients probing the configuration interface;
automated repeated requests to the startup endpoint;
analysis of internal connection structures; and
high-frequency requests affecting normal endpoint operation.
13.2 Remediation Measures
SingLinkVPN subsequently modified the process by:
strengthening authentication for VPN startup requests;
adding session-validity checks;
restricting unofficial and unauthorized clients;
adding abnormal-request detection;
adding high-frequency request limits;
separating internal-link data from public interfaces;
reducing the amount of data returned by the interface;
adding automated-probing prevention controls; and
strengthening authorization between the client and backend.
13.3 Before-and-After Comparison
| Item | Before Remediation | After Remediation |
|---|---|---|
| VPN startup request | Backend processed internal link requests | Stronger identity and session validation added |
| Unauthorized request | Potential attack surface could be probed | Internal link data cannot be obtained |
| Unofficial client | Additional restrictions were required | Protected configuration cannot be obtained |
| High-frequency requests | Endpoint could be repeatedly probed | Rate limits and attack-prevention controls are triggered |
| Internal link data | Accessible scope needed to be reduced | Isolated from unauthorized requests |
| Post-remediation testing | Not applicable | Original issue not reproduced |
| New vulnerability | Not applicable | No new vulnerability identified |
The final status of the issue is:
Remediated, retested, and closed
14. DNS, IPv4, IPv6, and WebRTC Testing
Network security testing covered:
normal VPN connection establishment;
VPN server-initiated disconnection;
unexpected local network interruption;
Wi-Fi to 5G transition;
5G to Wi-Fi transition;
device sleep and wake;
application restart;
abnormal VPN-process termination;
IPv4/IPv6 dual-stack environments;
WebRTC-related scenarios;
smart routing; and
global connection mode.
According to the test results, no consistently reproducible instance of the following was identified:
DNS leakage;
IPv4 address leakage;
IPv6 bypass;
WebRTC leakage;
routing bypass; or
sustained exposure of unprotected traffic.
When network conditions changed, the tested clients were able to re-establish, pause, or terminate the VPN connection according to the relevant operating system’s network mechanisms.
The audit did not identify a situation in which the client continued to send traffic through an unprotected path while displaying an active VPN connection.
15. Account and Web Dashboard Security
The audit covered:
unauthenticated access;
authentication tokens;
session validity periods;
token reuse after logout;
account-identifier manipulation;
cross-account data access;
subscription-data authorization;
page-level access controls;
repeated abnormal requests; and
frontend-backend interface access.
According to the test results:
unauthenticated users could not directly access protected account information;
invalid and expired tokens could not continue to be used;
modifying ordinary request parameters did not provide access to another user’s information;
subscription and account data were protected by the corresponding account permissions;
sessions were invalidated as expected after logout; and
the web dashboard passed the account-authorization tests included in this audit.
16. Privacy and Data-Handling Assessment
The audit assessed client data handling during:
application startup;
account sign-in;
VPN connection;
VPN location selection;
network errors;
application restart;
diagnostics and error handling;
web dashboard use; and
internal configuration requests.
Within the observable and tested scope, no functionality was identified that actively created records of:
users’ browsing content;
browsing history;
DNS query content;
complete network activity;
lists of websites visited; or
raw network traffic content.
The registration email aliases and order records retained by SingLinkVPN are used for subscription inquiries and after-sales support. They are not equivalent to browsing-content records or VPN network-activity logs.
The tests also did not identify a method by which an unauthorized request could directly obtain internal VPN link data.
17. Cross-Platform Test Conclusions
| Platform | Test Conclusion |
|---|---|
| iOS | Passed VPN connection, network transition, DNS, IP, account, and local-data tests |
| iPadOS | Passed VPN connection, background recovery, and network-leak tests |
| Apple TV | Passed sign-in, server connection, network recovery, and account-state tests |
| macOS Apple Silicon | Passed TUN, DNS, routing, sleep recovery, and internal-link tests |
| macOS Intel | Passed compatibility, VPN tunnel, DNS, and routing tests |
| Android | Passed VPN Service, background connection, network transition, IPv6, and local-data tests |
| Windows | Passed tunnel, DNS, system routing, abnormal interruption, and reconnection tests |
| Linux Ubuntu | Passed VPN tunnel, DNS, routing, and permission tests |
| Linux Debian | Passed installation, service startup, tunnel, and routing tests |
| Web user dashboard | Passed sign-in, session, account-authorization, and cross-account access tests |
18. Open-Source and Technical Transparency Assessment
SingLinkVPN has launched an ongoing open-source and technical-research program.
The first stage has begun publishing:
VPN development architecture;
security and privacy models;
performance-testing methodology;
test-data formats;
research and validation tools;
vulnerability-disclosure procedures; and
evidence and report-publication standards.
Future stages are intended to publish:
security reports;
performance reports;
transparency reports;
VPN protocols;
VPN clients; and
other core technologies that have completed security, privacy, and licensing reviews.
Open source does not automatically make a product secure.
The actual security of an open-source product still depends on:
security architecture;
code quality;
access control;
remediation speed;
dependency management;
version management;
continuous testing;
community review; and
responsible-disclosure procedures.
Based on the results of this security audit, the remediation of the known issue, and SingLinkVPN’s ongoing open-source direction, VPNTestor Platform concluded that SingLinkVPN met the technical-transparency and security-control requirements applied in this assessment.
19. 100-Point Scoring Methodology
The security assessment uses a total score of 100 points divided across seven categories:
| Assessment Category | Points |
|---|---|
| VPN tunnel, DNS, and network leak protection | 25 |
| Account, API, and internal-link security | 20 |
| Local client data and privacy controls | 15 |
| Cross-platform security consistency | 10 |
| Web dashboard and session security | 10 |
| Updates, installation packages, and supply-chain checks | 10 |
| Known-issue remediation and retesting | 10 |
| **Total** | **100** |
Deduction Rules
| Risk Level | Deduction per Finding |
|---|---|
| Critical | 30 points |
| High | 15 points |
| Medium | 7 points |
| Low | 2 points |
| Informational recommendation | No direct deduction; recorded as a future improvement item |
The audit results were:
critical-risk findings: 0;
high-risk findings: 0;
medium-risk findings: 0;
low-risk findings: 0;
known VPN startup process issue: remediated before the formal audit;
remediation retest: passed; and
new vulnerability introduced by remediation: none identified.
The resulting final score was:
100/100
A score of 100 indicates that all test items listed in this report met VPNTestor Platform’s passing criteria and that no unresolved critical-, high-, medium-, or low-risk issue was identified.
The score applies only to the versions, devices, operating systems, network environments, and test scope listed in this report. It is not a permanent security guarantee for all future versions.
20. Why SingLinkVPN Received a Score of 100
SingLinkVPN received a score of 100 for the following reasons:
no critical-risk vulnerability was identified;
no high-risk vulnerability was identified;
no medium-risk vulnerability was identified;
no low-risk vulnerability was identified;
the principal platforms were included in testing;
separate version and test-environment records were used for each platform;
no consistently reproducible DNS leak was identified;
no consistently reproducible IPv4 leak was identified;
no consistently reproducible IPv6 leak was identified;
no consistently reproducible WebRTC leak was identified;
no consistently reproducible routing bypass was identified;
the account system and web dashboard passed authorization tests;
unauthorized requests could not obtain internal VPN link data;
the potential issue identified in early 2026 had been remediated;
the original issue could not be reproduced after remediation;
the remediation did not introduce a new vulnerability;
cross-platform security behavior met the test requirements; and
the technical documentation and open-source transparency program met the assessment requirements.
21. Does the User Need to Take Any Action?
Users of older SingLinkVPN versions should update to the latest official release available for their platform.
Because different platforms use independent version numbers, users should follow the official update prompt for their own platform rather than relying only on the macOS 2.5 version number.
Users should also:
download clients only from SingLinkVPN’s official channels or official application stores;
avoid modified clients from unknown sources;
keep their operating system on a supported version;
check regularly for client updates;
avoid sharing account credentials;
sign in again or update the server configuration if abnormal connection behavior occurs.
Users already running the latest official version available for their platform do not need to take additional security action based on this audit.
22. Audit Limitations
The results of this audit apply to:
the July 2026 audit period;
the tested versions listed in this report;
the test devices listed in this report;
the operating systems listed in this report;
the network environments listed in this report;
the test cases listed in this report; and
the product state provided during the audit.
The report does not cover features, protocols, third-party dependencies, or backend deployment changes introduced after the completion of the audit.
Additional security testing should be performed when SingLinkVPN makes a material change to:
VPN protocols;
iOS or iPadOS clients;
Android clients;
macOS clients;
Windows clients;
Linux clients;
Apple TV clients;
the web user dashboard;
account and authentication systems;
server-configuration systems;
third-party dependencies; or
update and release processes.
23. Final Audit Conclusion
Based on the third-party security audit completed by VPNTestor Platform in July 2026, the platform reached the following conclusions:
No critical-risk vulnerability was identified in the tested products.
No high-risk vulnerability was identified.
No medium-risk vulnerability was identified.
No low-risk vulnerability was identified.
The iOS and iPadOS clients passed the security tests.
The Apple TV client passed the security tests.
The Apple Silicon and Intel macOS clients passed the security tests.
The Android client passed the security tests.
The Windows client passed the security tests.
The Linux clients passed the security tests.
The web user dashboard passed the account and authorization tests.
No consistently reproducible DNS leak was identified.
No consistently reproducible IPv4 or IPv6 leak was identified.
No consistently reproducible WebRTC leak was identified.
No consistently reproducible routing bypass was identified.
Unauthorized requests could not obtain internal VPN link data.
The VPN startup-process issue identified in early 2026 had been remediated.
The original issue could not be reproduced after remediation.
No new vulnerability introduced by the remediation was identified.
SingLinkVPN passed all scoring categories included in this third-party security audit.
VPNTestor Platform assigned the tested SingLinkVPN products a final security rating of:
100/100
Audit Result: Fully Passed
Within the versions, devices, operating systems, network environments, and audit scope described in this report, VPNTestor Platform did not identify any unresolved critical-, high-, medium-, or low-risk vulnerability in SingLinkVPN.
SingLinkVPN met all standards applied in this audit for VPN connection security, network leak protection, cross-platform security consistency, account authorization, privacy controls, and internal-link protection.
As SingLinkVPN continues to open-source its technical documentation, research data, VPN protocols, clients, and other core technologies, its security design will become increasingly available for ongoing inspection, verification, and reproduction by external researchers.
24. Report Signature
VPNTestor Platform Independent Testing and Audit Team: Openscore VPN
James Robert Smith Audit Lead VPNTestor Platform
Report Version: 1.2 Audit Period: July 2026 Audit Target: SingLinkVPN Final Rating: 100/100 Final Result: Fully Passed
Signature Date: 2026-07-31 Organization Email: [email protected] Digital Signature: Ed25519 signature of the v1.2 six-language manifest, verifiable with the published public key Report Integrity: Per-language SHA-256 values are published in the v1.2 six-language manifest; a single self-referential report hash is intentionally not embedded here.
<!-- annual-audit-records:start -->
25. 2026 Multi-Version Security Verification Record (Continuously Updated)
This section provides a cumulative record of new versions verified after the audit was completed. The July 2026 report, original publication date, signature, and historical conclusions remain preserved; subsequent updates only add new records.
Public content includes only versions, dates, verification results, and integrity verification values. Product architecture, operating logic, configurations, network information, issue details, and complete original records are not publicly disclosed and are retained by VPNTestor Platform in a restricted audit archive.
25.1 Latest Complete Signed Report
Current status: the complete signed report and its integrity-signed English translation have been published.
VPNTestor Platform has consolidated the macOS 2.5.7, Windows 2.5.8, and new-protocol security verification records into the complete 2026 v2.0 report. The report received a final rating of 100/100, with a final result of Pass, and was digitally signed by James Robert Smith. The English document is a faithful translation of that signed v2.0 report; the multilingual translation set is covered by a separate integrity manifest and signature.
25.2 Latest Version Results
| Platform and version | Verification scope | Result | Public evidence |
|---|---|---|---|
| Windows 2.5.8 / build 3077 | New-protocol security verification | 7/7 items passed, 100% pass rate | [View public summary](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-Windows-2.5.8-3077-Sola-Runtime-Audit-Addendum-2026-08-24-en.md) |
| Windows 2.5.8 / build 3077 | Version and runtime security verification | All listed items passed, 100% pass rate | [View public summary](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-Windows-2.5.8-3077-Runtime-Audit-Evidence-2026-08-24-en.md) |
| macOS 2.5.7 / build 3065 | Release security verification | 6/6 items passed, 100% pass rate | [View public summary](/downloads/security-audits/singlinkvpn-v2.5-2026/SingLinkVPN-macOS-2.5.7-3065-DMG-Evidence-2026-08-24-en.md) |
| macOS 2.5.6 / build 3064 | New-protocol security verification | 7/7 items passed, 100% pass rate | [View public summary](/downloads/security-audits/singlinkvpn-v2.5-2026/Sola-Protocol-Runtime-Audit-Evidence-2026-08-16-en.md) |
All listed security verification items passed for the versions and retained test records above, with no unresolved security issues identified.
25.3 Public Evidence Protection Principles
Public summaries retain the version, build number, date, verification conclusion, and evidence verification values.
Complete original records are retained in a restricted audit archive and are not available for public download.
Public materials do not disclose product architecture, implementation methods, operating logic, configurations, network information, device information, or issue details.
Each update creates a new record and does not delete or overwrite dates or conclusions from earlier versions.
VPNTestor Platform independently conducts and records verification and does not substitute product promotional content for test results.
25.4 Version and Evidence History
| Record date | Platform and version | Cumulative update | Status |
|---|---|---|---|
| 2026-07-28 | SingLinkVPN v2.5 | Initial publication of the 2026 security audit report | Published; original publication date retained |
| 2026-08-01 | macOS 2.5.6 / build 3056 | Added formal installation-sample verification record | Verified |
| 2026-08-16 | macOS 2.5.6 / build 3064 | Added new-protocol security verification and evidence verification values | 7/7 items passed, 100% pass rate |
| 2026-08-19 | macOS 2.5.7 / build 3065 | Added formal installation-sample and release security records | 6/6 items passed, 100% pass rate |
| 2026-08-24 | Windows 2.5.8 / build 3077 | Added version, installation-sample, and runtime security records | All listed items passed, 100% pass rate |
| 2026-08-24 20:22 | Windows 2.5.8 / build 3077 | Added new-protocol security verification and cumulative evidence verification values | 7/7 items passed, 100% pass rate |
| 2026-08-24 20:28 | Public-material protection update | Applied consistent redaction to the webpage and downloadable summaries; detailed evidence remains in the restricted archive | Completed |
| 2026-08-24 20:58 | Current-version complete report v2.0 | Consolidated macOS 2.5.7, Windows 2.5.8, and new-protocol verification records; froze the report and four evidence summaries | Complete, 100/100, signed and successfully verified |
25.5 Integrity and Historical Preservation
The July 2026 v1.2 report, its six-language verification manifest, and digital signature remain preserved as historical records. The current version uses a separate v2.0 complete report and source-report signature, together with a separately signed multilingual translation manifest, and does not modify the frozen historical report.
The original publication date of this page remains 2026-07-28, while the page also displays the latest update date. Future audits will continue to be appended by date.
26. Mobile Security Audit Supplement: Android / iOS 2.5 Series
Testing and reporting: VPNTestor test team. Test date: 2026-09-11. This report consolidates Android / iOS 2.5 series sample verification, runtime records and real-device connection and recovery tests.
Confirmed audit conclusions: SingLinkVPN passed this platform's 2026 security audit and the independent no-activity-logs verification dated 2026-07-29. In the original security audit's tested versions and environments, no consistently reproducible DNS, IPv4, IPv6 or WebRTC leaks or routing bypasses were found. This mobile 2.5 series record adds version, connection and recovery results.
26.1 Android 2.5 Series
The specific sample is Android 2.5.8, build 5066. The installation file was obtained from the official distribution channel on 2026-09-11 and is 60,353,364 bytes in size. File integrity, the version embedded in the package, and the release signature have been verified successfully.
Sample SHA-256: 3d60e21b610bc12988992e055f45eceaf4d4cab46204de60dbb3d65869f20659.
A partial static review of the installation sample has been completed. No hard-coded private keys or tokens were found among the common credential patterns examined, and no known vulnerabilities were found in the limited set of identifiable dependencies queried. This review does not cover every dependency or all runtime behavior.
The VPNTestor test team's Android runtime records include one public video and eight screenshots covering connection status, service access, speed-testing processes, node selection, device management, support, rule settings and desktop widgets.
View the Android 2.5 series runtime demonstration. The public title of this video identifies version 2.5.6, and it is retained as series-level runtime material; the precise identity of the 2.5.8 sample is governed by the installation-file record in this section. No verifiable binding has been established between the screenshots or video and that installation file.
26.2 iOS 2.5 Series
The official distribution channel, App Store information, and application metadata from a connected device have been verified. The sample that can be verified in this review is App Store version 2.5.1, build 18; its App Store ID is 6759948234. This document uses iOS 2.5 Series as the product-scope name while retaining the precise version in the sample record.
This section records distribution and installed-version identity. iOS runtime and device-test results appear in Sections 27 and 28.
26.3 Evidence Scope and Public Materials
Security audit: passed. Sections 14 and 23 of the 2026 security audit record no consistently reproducible network leaks in the original tested versions and environments, with all listed assessment categories passed.
No-activity-logs verification: passed. The 2026-07-29 independent no-logs report used read-only production inspection to confirm that the inspected system design matched the strict no-activity-logs policy. It found no persistent records of users' websites, DNS queries, original IP addresses or communication content. This conclusion comes from the dedicated backend and infrastructure audit.
Sections 26–28 document the current mobile version checks and device results. Security and no-logs conclusions retain the dates, versions and systems identified in their source reports; the feature-adaptation record does not replace those security tests.
Accounts, device identifiers, subscriptions, traffic information and internal technical details in original screenshots remain in the restricted archive. This revision signs the six-language consolidated report and screenshot checksum lists, verifying file integrity and the publishing key.
Download this public supplement. Download the six-language file checksum manifest. The checksum manifest is provided for file-integrity verification.
26.4 Added-Record Timeline
2026-09-11: Completed identity, integrity, and signature verification for the Android 2.5.8 installation file and recorded the scope of the partial static review.
2026-09-11: Reviewed the public Android 2.5 series runtime video and eight test screenshots, recording their version attribution and privacy-protection boundaries.
2026-09-11: Completed verification of the official iOS 2.5 series distribution channel and installed-version metadata, and added this public supplement.
27. iOS 2.5 series: additional runtime evidence and signature record
2026-09-11: the VPNTestor test team recorded seven iOS runtime screenshots, public-video page verification and connected-device version verification.
Seven iOS test screenshots record connected client and widget states, feature and settings interfaces, and in-app network-check responses. The download test shows an instantaneous reading of 1,032.52 Mbps, archived as an in-progress measurement.
The public video page, title and preview were checked. Its title identifies an iOS 2.5 internal-test build, archived as a series demonstration; installed-version identity follows the device metadata record.
On 2026-09-11, a read-only query of the connected iPhone 16 Pro Max confirmed SingLinkVPN 2.5.1, build 18, matching the sample archive.
The VPNTestor test team records the release change scope as protocol adaptation and feature optimization. Historical security conclusions retain their original version scope; current connection and recovery results appear in Section 28.
All three device recovery checks were normal; itemized results appear in Section 28.
Accounts, device identifiers, subscriptions, traffic information and internal technical details in original screenshots remain in the restricted archive. This revision signs the six-language consolidated report and screenshot checksum lists, verifying file integrity and the publishing key.
27.1 Evidence and verification downloads
28. Android / iOS 2.5 series: connection and recovery test results
Connection and recovery test results | 2026-09-11 | Revision 4
The VPNTestor test team completed this batch of connection, browser local-address and real-device recovery tests. The test records follow.
| Record | Android 2.5 series | iOS 2.5 series |
|---|---|---|
| Screenshots in this batch | 6 | 3 |
| Version archive (previously verified) | 2.5.8, build 5066 | 2.5.1, build 18 |
| State during submitted IP checks | VPN enabled | VPN enabled |
| Local-address check materials | 2 result screenshots | 1 result in 2 views |
The version archive indexes earlier sample records; this screenshot batch is filed under the 2.5 series.
Connection and address checks
| Test item | Reviewed result | Evidence source |
|---|---|---|
| Android node connection | Both node interfaces display connected status | Connection screenshots in this batch |
| Android exit address | Two IP-check records display different exit values | IP-check screenshots in this batch |
| Android local-address enumeration | A local-scope network address was detected; no public address was listed in the results | 2 browser-result screenshots |
| iOS local-address enumeration | An anonymized hostname was detected; no numeric IP address was listed in the result | 2 views of the same browser result |
Device recovery tests
| Test item | Android result | iOS result | Evidence source |
|---|---|---|---|
| Recovery after screen lock | Normal; usable on opening | Normal; usable on opening | VPNTestor device test records |
| Recovery after network switching | Normal; usable on opening | Normal; usable on opening | VPNTestor device test records |
| Recovery after network interruption | Normal; usable on opening | Normal; usable on opening | VPNTestor device test records |
Result summary: All 3 recovery scenarios on each platform were normal. Screenshots document Android connection status and exit-value changes. Android local enumeration returned a local-scope address; iOS returned an anonymized hostname.
Method: VPNTestor device operations and screenshot records. The browser check measures local-address visibility without external STUN/TURN services. Recovery checks record post-operation usability qualitatively rather than in milliseconds. DNS, IPv6 and continuous traffic-leak conclusions refer to the original security audit scope cited in Section 26.3.
Evidence and privacy: Checksums register 9 original images. Specific IP addresses, accounts and device identifiers are not public. The revision signature verifies file integrity and the publishing key; it does not change test provenance or expand the conclusions.
28.1 Evidence and signature downloads
Historical signed archives (superseded editions)