Annual security audit scheduled for 2025

IVPN News By Nick Pestell | Posted on May 8, 2025

Consistent with our commitment to regular independent security audits, we have scheduled our seventh annual security audit with Cure53, to be conducted over the course of two weeks in May.

As in previous years, audits will target systems and services undergoing significant updates. As part of a broader rollout planned later this year we are launching two new privacy-focused services (optional and free additions for all IVPN Pro accounts). Scope of audits:

IVPN Email Forwarding Service

IVPN DNS Service

Looking ahead, our ongoing IVPN infrastructure upgrade - including transitioning to RAM-only servers - remains a priority with test deployments under way. Audits next year will focus specifically on evaluating new infrastructure rolled out throughout the rest of 2025.

Nicholas Pestell
CEO
IVPN

Audit Apps Transparency
We invite you to discuss this post in our Reddit community or on Twitter. You can also send your feedback to blog@ivpn.net.
IVPN News

A security incident on our Bitcoin payment server

By IVPN Staff

IVPN News

Annual security audit scheduled for 2026

By Nick Pestell

Under the Hood

Unlinked Access: reducing cross-service account linkage with HSM-backed token derivation

By Juraj Hilje

IVPN News

A security incident on our Bitcoin payment server

Posted on August 11, 2026 by IVPN Staff

Summary: on 7 August a critical vulnerability was disclosed in BTCPay Server, the open-source software we self-host to accept Bitcoin payments. It was being exploited before disclosure, and we were among the merchants hit: an attacker extracted our Lightning node credentials and transferred out our operating funds.
Annual security audit scheduled for 2026
IVPN News

Annual security audit scheduled for 2026

Posted on June 19, 2026 by Nick Pestell

Consistent with our commitment to regular independent security audits, we have scheduled our eighth annual security audit with Cure53, to be conducted over the course of two weeks in July. As in previous years, audits target systems and services that have undergone significant updates and where review provides the most value to customers in terms of security and auditability.
Spotted a mistake or have an idea on how to improve this page?
Suggest an edit on GitHub.