Malwarebytes has successfully concluded its first independent security audit of AzireVPN’s infrastructure, underscoring its commitment to maintaining a no-logs policy.
The audit, which was performed by the respected security firm X41 D-Sec, provides a clear validation of Malwarebytes' strict adherence to privacy conventions. Since acquiring AzireVPN in 2024, Malwarebytes has integrated its features into its VPN service, demonstrating its emphasis on safeguarding user privacy.
Commitment to transparency and security
In an effort to differentiate itself in a sector where trust often hinges on undisclosed assurances, Malwarebytes opted for transparency by opening up its source code, server configurations, and internal processes to the audit.
Marcin Kleczynski, Founder and CEO of Malwarebytes, stated, "Trust shouldn't be a leap of faith; it should be an informed choice based on evidence. By completing this audit, we are moving beyond promises and providing our users with objective proof that their data is handled with the highest privacy and security standards."
Audit methodology and inspection
For a thorough assessment, X41 D-Sec conducted a white-box penetration test over two months. This involved a comprehensive examination of Malwarebytes’ software and hardware, utilised in its VPN service operation. The auditors had full access to:
- Core applications, encompassing source code across platforms including Windows, macOS, Android, and iOS.
- The server infrastructure, allowing an in-depth look into the global VPN node network configuration.
- The privacy architecture, confirming that the no-logs systems ensure no identifiable user data is stored or accessible.
Key audit outcomes
Malwarebytes’ proactive approach to the findings was also highlighted
The audit results decisively verified Malwarebytes' no-logs policy, with auditors reporting no evidence of user IP address logging, browsing history tracking, or DNS query records. X41 D-Sec remarked, “During our assessment, we did not observe evidence of user activity logging, and access to systems is tightly controlled, with no unnecessary remote, local, or SSH access exposed.” Furthermore, the audit concluded that Malwarebytes' systems possess a commendable security level relative to other systems of equivalent size and complexity.
Malwarebytes’ proactive approach to the findings was also highlighted. X41 confirmed that most identified vulnerabilities, including a critical one, have been addressed, with the remaining issues currently being resolved.
Elevating the benchmark for VPN providers
Jérôme Boursier, Principal Research Engineer at Malwarebytes, commented, “This thorough security audit provides the level of transparency any VPN provider and privacy company should aim for. Combining a software audit with hardware penetration testing is invaluable. It gives our users a clear understanding of how we operate and how we stand apart from competitors.”
The audit outcomes are intended to solidify Malwarebytes' commitment to security while setting a higher standard for user privacy.
Features of Malwarebytes Privacy VPN
Malwarebytes Privacy VPN offers an ultra-fast and secure internet experience, with servers distributed globally to ensure unrestricted accessibility.
Key features of the service include RAM-only, diskless servers, an independently verified no-logs policy alongside Blind Operator Mode, full infrastructure control, and consistent transparency reports with Warrant Canary notices. Recent expansions include new servers in Jakarta, Indonesia, and Johannesburg, South Africa, enhancing the VPN’s reach and capabilities.
Malwarebytes, a global pioneer in online protection, announced the completion of its first independent third-party security audit of the AzireVPN infrastructure. Malwarebytes acquired AzireVPN in 2024 to bring its bespoke privacy features to its VPN solution and now leverages the AzireVPN infrastructure. The comprehensive assessment, conducted by renowned security audit provider X41 D-Sec, validates the integrity of Malwarebytes infrastructure and its strict adherence to its no-logs policy.
In an industry where trust is often requested but rarely verified, Malwarebytes made the strategic decision to open its entire source code, server configurations, and internal processes to external scrutiny.
Highest privacy and security standards
“Trust shouldn't be a leap of faith; it should be an informed choice based on evidence,” said Marcin Kleczynski, Founder and CEO, Malwarebytes.
“By completing this audit, we are moving beyond promises and providing our users with objective proof that their data is handled with the highest privacy and security standards. If a VPN provider can’t offer that level of transparency through an independent audit, it’s worth questioning whether it should be trusted at all. We hope this helps people make better decisions about who they trust with their internet traffic and activity.”
Identifiable user metadata
The audit was conducted by X41 D-Sec over a period of two months and employed a white-box penetration testing methodology to review the software and hardware Malwarebytes developed and deployed to operate its VPN service. This provided the auditors with full access to:
- Core applications: Source code for Windows/macOS/Android/iOS apps.
- Server infrastructure: A deep dive into the configuration of Malwarebytes’s global VPN node network.
- Privacy architecture: Verification of the "no-logs" systems to ensure no identifiable user metadata is stored or accessible.
Key Findings
Zero-logs verification: Auditors confirmed that the technical architecture is consistent with Malwarebytes’s privacy policy, finding no evidence of logging user IP addresses, browsing history, or DNS queries. X41 noted, “During our assessment, we did not observe evidence of user activity logging, and access to systems is tightly controlled, with no unnecessary remote, local, or SSH access exposed.”
- Good security level: The final report concluded that the Malwarebytes “systems appear to be on a good security level compared to systems of similar size and complexity.”
- Swift response to findings: Malwarebytes worked with the X41 team to quickly inspect and address findings. X41 shared, “While vulnerabilities were identified; most have already been addressed, including one critical issue, with remaining items in the process of being resolved."
“This thorough security audit provides the level of transparency any VPN provider and privacy company should aim for,” said Jérôme Boursier, Principal Research Engineer and privacy advocate at Malwarebytes. “Combining a software audit with hardware penetration testing is invaluable. It gives our users a clear understanding of how we operate and how we stand apart from competitors. These results reinforce our commitment to security and will guide us in setting a higher standard for our users.”
Malwarebytes privacy VPN
Malwarebytes Privacy VPN is an ultra-fast, ultra-private VPN service designed to protect user privacy and provide secure, unrestricted internet access. With servers worldwide, Privacy VPN lets users access the internet safely and without geographic limits, just as if they were using it in another country.
Key features include:
- RAM-only, diskless servers
- Independently verified no-logs policy and Blind Operator Mode
- Full infrastructure control
- Ongoing transparency reports and Warrant Canary
- New server locations including Jakarta, Indonesia, and Johannesburg, South Africa
- Part of holistic dashboard across desktop and mobile