Our 2026 independent security audit
We invited an outside team to break our encryption. Here’s what they tested, what they found and what we changed.
Our 2026 independent security audit
We invited an outside team to break our encryption. Here’s what they tested, what they found and what we changed.
Trust should be earned and verified. Every year we hire an outside team to try to break Enbox, and we publish what they find — the good parts and the uncomfortable ones.
What we asked them to test
- End-to-end encryption and key handling
- Account recovery and two-factor flows
- Server infrastructure and data at rest
The review ran for three weeks against a production-equivalent environment.
What they found
No critical issues in the encryption design. A handful of lower-severity findings, all since fixed:
| Finding | Severity | Status |
|---|---|---|
| Rate-limit gap on login | Medium | Fixed |
| Verbose error message | Low | Fixed |
| Outdated dependency | Low | Fixed |
A closer look at the rate-limit fix
The /login endpoint now backs off aggressively after repeated failures:
{
"maxAttempts": 5,
"lockoutSeconds": 900
}
Finding detail
Severity
Medium — no data was exposed, but it made brute-forcing easier.
Status
Resolved in v4.2 and deployed within 48 hours.
What we changed in our process
- Dependency scanning on every release
- A second reviewer for all authentication code
- Quarterly internal red-team drills
Closing the loop:
- All findings fixed
- Report published
- Next audit booked for 2027
An audit you do not publish is just marketing.
Read the full report.