The linked press release makes no mention of whether or not server side code was audited only stating that:
This year, Recurity Labs(new window), an ISO 27001-certified IT security consultancy, tested everything a Proton Pass user interacts with: the Proton Pass browser extensions(new window), mobile and desktop applications(new window), and Command Line Interface(CLI).
This is still excellent to see. However, personally with something as sensitive as a cloud based password manager I would like to see an audit of that server side code as well, for further transparency.
Also of note: It does not appear that this most current audit is available at the time of posting at the audit list link provided by Proton in the article. Only a Cure53 audit from June of 2023 shows up for me.
According to the Executive Summary from the actual audit
The backend of the solution was also cursory reviewed, with this part of the
assessment performed in a black-box manner, without source code or infrastructure access.
Which I understand to mean no server-side code was audited with source-code review; it was inspected only via black‑box testing.
Thanks for linking the full audit.
Correct me if I’m wrong, but to my understanding Proton Pass is open sourced.
But if an app wasn’t open sourced, would you be satisfied if they passed external audits as proof of their trustworthiness? I believe this is what 1Password does. It’s their argument for not being open sourced.
404
Right ISO 27001. I mean i am glad they pass the minimum barier. Not that impressive.
You gotta slap a “Military Grade” onto it for extra security
14 person-days for this broad level of scope seems tight. I wonder what process Proton used for vendor selection.