All articles
Security1 min read

Our 2026 independent security audit

We invited an outside team to break our encryption. Here’s what they tested, what they found and what we changed.

Our 2026 independent security audit

We invited an outside team to break our encryption. Here’s what they tested, what they found and what we changed.

Trust should be earned and verified. Every year we hire an outside team to try to break Enbox, and we publish what they find — the good parts and the uncomfortable ones.

What we asked them to test

  • End-to-end encryption and key handling
  • Account recovery and two-factor flows
  • Server infrastructure and data at rest

The review ran for three weeks against a production-equivalent environment.

What they found

No critical issues in the encryption design. A handful of lower-severity findings, all since fixed:

Finding Severity Status
Rate-limit gap on login Medium Fixed
Verbose error message Low Fixed
Outdated dependency Low Fixed

Audit summary dashboard

A closer look at the rate-limit fix

The /login endpoint now backs off aggressively after repeated failures:

{
  "maxAttempts": 5,
  "lockoutSeconds": 900
}

Finding detail

Severity

Medium — no data was exposed, but it made brute-forcing easier.

Status

Resolved in v4.2 and deployed within 48 hours.

What we changed in our process

  1. Dependency scanning on every release
  2. A second reviewer for all authentication code
  3. Quarterly internal red-team drills

Closing the loop:

  • All findings fixed
  • Report published
  • Next audit booked for 2027

An audit you do not publish is just marketing.


Read the full report.

Ready for a more private digital life?

Ten apps, one private home. Start a 30-day free trial — no ads, no trackers, cancel anytime.

Get started free