INDEPENDENT REVIEW

The path to an independent review.

VENTEX Connect has not yet been independently reviewed. This page sets out what is to be reviewed, what is already prepared, what is still missing – and what applies until then. We will only give dates once they are fixed.

WHAT IS TO BE REVIEWED

Five areas, from encryption to operations.

A good review does not look only at encryption, but at everything that touches messages along the way.

  1. Encryption method

    How two devices set up a conversation securely and how keys are continuously renewed afterwards.

    Today
    Checked internally: 308 requirements, each with its own counter-test. Test data and a protocol description are available.
    Planned review
    Review by cryptography specialists: design, implementation and the transitions between the old and new protocol versions.
  2. The app on the device

    The part where messages are actually decrypted and where keys are kept on the device.

    Today
    Tested in real browsers. Known limitation: on iPhones the browser cannot store keys in specially protected form; this is publicly documented.
    Planned review
    Code review and attack testing of the app, including key storage and signing out lost devices.
  3. Server and interfaces

    Accounts, permissions and everything the server has to see in order to deliver messages.

    Today
    Permission checks are evidenced internally with counter-tests. The data the server sees is described in the Evidence Center.
    Planned review
    Attack testing of the interfaces with a focus on permissions: can anyone see or do what they should not?
  4. Operations and infrastructure

    How the servers are secured, updated and backed up – and how to check that the software delivered is the reviewed source code.

    Today
    Every release is signed and automatically checked against published commitments.
    Planned review
    Review of configuration, backups, updates and the path from source code to delivered software.
  5. Privacy and metadata

    Which data is created during use, who can see it and when it is deleted.

    Today
    Metadata is reduced but not eliminated: the service still needs information about delivery, membership and time.
    Planned review
    Assessment of whether the published privacy boundaries match actual behaviour.
PROCESS

Six steps to a published result.

  1. Reporting route and advisory register

    Vulnerabilities can be reported in an orderly way, and a public register lists security advisories.

    Done
  2. Review materials

    A protocol description, test data and implementation material are available and can be provided confidentially.

    Done
  3. Define the scope

    Which version, which areas, which test environment, what is excluded and how results will be published.

    Next step
  4. Select and commission a review firm

    Depends on scope and budget. The firm will be named here once it has been commissioned.

    Open
  5. Review, fixes, re-test

    Findings are fixed and re-tested by the review firm before any result is published.

    Open
  6. Publish the result

    Tied to scope, version and date – never as a blanket “certified”.

    Open
PUBLICATION

How the results are to be published.

  • The review firm, reviewed version, scope and date come first in every publication.
  • All findings appear with their severity and the status of their fix – including the uncomfortable ones.
  • Serious findings are published in detail only after they have been fixed, so nobody can exploit them in the meantime.
  • Anything that was not reviewed is named explicitly.
  • The result applies to the reviewed version. Later changes are not quietly presented as “reviewed”.
UNTIL THEN

What applies until then.

  • Every security claim on this website is based on internal checks. Each one states how it is checked and where its limits are.

    Evidence Center
  • VENTEX Connect is not approved for classified information and does not replace certified systems for protecting it.

    What VENTEX is – and is not
  • Organisations currently use VENTEX Connect in limited pilots with a clearly agreed scope.

    Pilot programme
  • Anyone who finds a vulnerability can report it confidentially at any time.

    Report a vulnerability
HELP US

You can shorten this path.

An independent review takes time and money. Three ways you can help:

  • You review software professionally

    Do you work for a review firm or as an independent security expert? We would welcome a proposal or an initial conversation about the scope.

  • You do research

    Universities and research groups can examine parts of the method as part of their own work. We provide materials confidentially.

  • You want to use VENTEX Connect

    If your organisation requires a review, talk to us. Together, the scope can often be tailored precisely to your use.

Get in touch

Frequently asked questions

Why is there no independent review yet?

A thorough review of an encryption method is demanding and expensive. VENTEX is a small project; we are preparing the review so that the budget goes into the review itself rather than into gathering documents.

Can I use VENTEX Connect anyway?

Yes, as part of a pilot with a clearly agreed scope. For classified information or uses that require certification, VENTEX Connect is not suitable today.

Who pays for the review – and is it really independent then?

As is usual for such reviews, VENTEX commissions and pays the review firm. Independent means: the firm decides on its findings, and they are published under the rules above – including the uncomfortable ones.

What do the internal checks mean if they are not independent?

They show that every published security claim has a test that would fail if the claim stopped being true. But they do not replace an outside view, which also finds mistakes in our own assumptions.