The path to an independent review.
VENTEX Connect has not yet been independently reviewed. This page sets out what is to be reviewed, what is already prepared, what is still missing – and what applies until then. We will only give dates once they are fixed.
Five areas, from encryption to operations.
A good review does not look only at encryption, but at everything that touches messages along the way.
Encryption method
How two devices set up a conversation securely and how keys are continuously renewed afterwards.
- Today
- Checked internally: 308 requirements, each with its own counter-test. Test data and a protocol description are available.
- Planned review
- Review by cryptography specialists: design, implementation and the transitions between the old and new protocol versions.
The app on the device
The part where messages are actually decrypted and where keys are kept on the device.
- Today
- Tested in real browsers. Known limitation: on iPhones the browser cannot store keys in specially protected form; this is publicly documented.
- Planned review
- Code review and attack testing of the app, including key storage and signing out lost devices.
Server and interfaces
Accounts, permissions and everything the server has to see in order to deliver messages.
- Today
- Permission checks are evidenced internally with counter-tests. The data the server sees is described in the Evidence Center.
- Planned review
- Attack testing of the interfaces with a focus on permissions: can anyone see or do what they should not?
Operations and infrastructure
How the servers are secured, updated and backed up – and how to check that the software delivered is the reviewed source code.
- Today
- Every release is signed and automatically checked against published commitments.
- Planned review
- Review of configuration, backups, updates and the path from source code to delivered software.
Privacy and metadata
Which data is created during use, who can see it and when it is deleted.
- Today
- Metadata is reduced but not eliminated: the service still needs information about delivery, membership and time.
- Planned review
- Assessment of whether the published privacy boundaries match actual behaviour.
Six steps to a published result.
- Done
Reporting route and advisory register
Vulnerabilities can be reported in an orderly way, and a public register lists security advisories.
- Done
Review materials
A protocol description, test data and implementation material are available and can be provided confidentially.
- Next step
Define the scope
Which version, which areas, which test environment, what is excluded and how results will be published.
- Open
Select and commission a review firm
Depends on scope and budget. The firm will be named here once it has been commissioned.
- Open
Review, fixes, re-test
Findings are fixed and re-tested by the review firm before any result is published.
- Open
Publish the result
Tied to scope, version and date – never as a blanket “certified”.
How the results are to be published.
- The review firm, reviewed version, scope and date come first in every publication.
- All findings appear with their severity and the status of their fix – including the uncomfortable ones.
- Serious findings are published in detail only after they have been fixed, so nobody can exploit them in the meantime.
- Anything that was not reviewed is named explicitly.
- The result applies to the reviewed version. Later changes are not quietly presented as “reviewed”.
What applies until then.
Every security claim on this website is based on internal checks. Each one states how it is checked and where its limits are.
Evidence CenterVENTEX Connect is not approved for classified information and does not replace certified systems for protecting it.
What VENTEX is – and is notOrganisations currently use VENTEX Connect in limited pilots with a clearly agreed scope.
Pilot programmeAnyone who finds a vulnerability can report it confidentially at any time.
Report a vulnerability
You can shorten this path.
An independent review takes time and money. Three ways you can help:
You review software professionally
Do you work for a review firm or as an independent security expert? We would welcome a proposal or an initial conversation about the scope.
You do research
Universities and research groups can examine parts of the method as part of their own work. We provide materials confidentially.
You want to use VENTEX Connect
If your organisation requires a review, talk to us. Together, the scope can often be tailored precisely to your use.
Frequently asked questions
Why is there no independent review yet?
A thorough review of an encryption method is demanding and expensive. VENTEX is a small project; we are preparing the review so that the budget goes into the review itself rather than into gathering documents.
Can I use VENTEX Connect anyway?
Yes, as part of a pilot with a clearly agreed scope. For classified information or uses that require certification, VENTEX Connect is not suitable today.
Who pays for the review – and is it really independent then?
As is usual for such reviews, VENTEX commissions and pays the review firm. Independent means: the firm decides on its findings, and they are published under the rules above – including the uncomfortable ones.
What do the internal checks mean if they are not independent?
They show that every published security claim has a test that would fail if the claim stopped being true. But they do not replace an outside view, which also finds mistakes in our own assumptions.
