Encryption model & independent audits
How this is scored
What the vendor can prove about its security design: end-to-end encryption with named algorithms and key derivation, which fields are encrypted on the device and which are not, independent audits and penetration tests with published results, a bug bounty, and incident history disclosed.
0 — Security described in adjectives ("bank-grade", "military encryption") with no architecture, no audit and no statement of what the vendor can read.
3 — Encryption algorithms named and "zero knowledge" claimed, but no whitepaper, no statement of which fields stay unencrypted, and audits mentioned without dates, auditors or results.
5 — A published security whitepaper naming algorithms, key derivation and the client-side encryption model, a stated list of what is and is not encrypted (including URLs and metadata), and a named independent audit or certification (ISO 27001, SOC 2) with its date.
8 — Recurring independent penetration tests or code audits with reports or summaries published, a public bug bounty or vulnerability disclosure policy, past security incidents documented with their impact, and open-source clients or cryptography that can be reviewed.
10 — The design is verifiable end to end: full source or cryptographic design public, every field encrypted client-side including metadata, audits by named firms repeated yearly with full reports, a threat model that states what a compromise of the vendor's servers would expose, and incident post-mortems published.
The Compliance Auditor
The security pages go beyond adjectives: AES-256 and elliptic-curve cryptography are named, key derivation is stated as PBKDF2 with 1,000,000 iterations, and the encrypted-field list explicitly covers URLs, custom fields, file attachments and TOTP codes. Periodic penetration tests by named firms, a Bugcrowd-managed bounty, a public disclosure programme and annual ISO 27001 audits are all on the record — but we found no public information on published test reports or summaries, on past security incidents and their impact, or on open-source clients or cryptography for review. 5 6 12 1 3