On 29 July 2026, the Openscore VPN team reviewed the official VPN Cat website, privacy policy, terms, Apple App Store record and Apple's lookup metadata. VPNTestor then checked the sources and scoring. The assessed record is VPN Cat 2.12.5, bundle ID com.vpn.cat, sold by SAFDAR NETWORK SMC-PRIVATE LIMITED.
The full machine-readable record contains every source, finding, deduction and untested control as public JSON evidence.
Verified product and publisher identity
- App Store item:
1134784923. - Current version:
2.12.5, released 18 March 2026. - Bundle ID:
com.vpn.cat; minimum iOS version: 15.0. - Seller and website company name: SAFDAR NETWORK SMC-PRIVATE LIMITED.
- Apple lists iPhone and iPad support and compatibility with Apple-silicon Macs running macOS 13 or later.
These facts establish which App Store record the first-party website points to. They do not prove the security of the binary or backend. Multiple unrelated apps use similar “VPN Cat” names, so this report does not cover those products.
Why the application binary is unverified
The first-party download button leads only to Apple's App Store. Apple provides public listing metadata but no unauthenticated IPA download that an outside reviewer can freeze, hash and inspect. VPNTestor therefore did not claim to verify the code signature, entitlements, embedded SDKs, dependencies, permissions, network-security settings or update chain.
App Store distribution is a useful platform gate, so it receives limited credit. It is not a substitute for inspecting the exact reviewed binary, reproducing its hash or executing security tests.
Privacy disclosures and internal conflicts
The policy says VPN Cat does not store browsing history, content or DNS queries and says an IP address used to establish a VPN connection is discarded after the session. The same policy also defines usage data as IP addresses, device information and access times. It states that Google Mobile Ads may collect IP address, device ID, advertising data and user interactions.
Apple's privacy label—supplied by the developer and explicitly not verified by Apple—lists coarse location and advertising data for third-party advertising, User ID for app functionality and crash data. The public documents do not provide retention periods or a data-flow table separating tunnel operations, account functions and advertising.
The App Store description says no registration is required, while the terms say users must register and provide personally identifiable information. The policy also describes name, email and payment data collected during registration. The product should document which free, paid and recovery flows require an account.
Security transparency
No public third-party audit, signed assessment statement, source-code repository, protocol specification, software bill of materials, release checksum, permission inventory or remediation log was located in the reviewed first-party record. The App Store description calls the protocol proprietary but does not publish cryptographic or connection details.
As a result, this assessment cannot verify logging operations, server ownership, DNS handling, IPv6 behavior, Kill Switch behavior or backend access controls. A privacy policy is a first-party commitment, not evidence that those controls were tested.
Open findings
- High: no independently retrievable application artifact.
- Medium: zero-log wording conflicts with disclosed usage and advertising data collection.
- Medium: registration statements are inconsistent.
- Medium: no public independent security or no-logs audit.
- Informational: protocol and platform security-control documentation is absent.
Public-distribution assessment score: 34/100
- Artifact integrity and provenance: 14/30.
- Platform signing and binary assurance: 10/30.
- Privacy and security surface: 6/20.
- Public security transparency: 4/20.
The score rewards the reproducible first-party App Store path, matching seller identity, version and bundle metadata, and public legal pages. It withholds points for controls that could not be inspected or executed. A provider does not lose points merely because Apple distributes its app; it loses assurance points when no equivalent reproducible artifact, technical documentation or independent report is available.
What still needs testing
- Binary signature, entitlements, dependencies and embedded SDK inventory.
- Installation, account lifecycle, local storage and uninstall remnants.
- IPv4, IPv6, DNS, WebRTC and route leakage.
- Kill Switch behavior across interruption, sleep and network switching.
- Update authenticity and rollback resistance.
- Server logging, retention, ownership and infrastructure access controls.
- Streaming access, sustained speed, latency and reliability.