Summary is AI-generated, newsdesk-reviewed
  • Malwarebytes completes independent audit, verifying VPN’s no-logs policy and privacy standards.
  • X41 D-Sec confirms Malwarebytes VPN infrastructure secure, no evidence of user data logging.
  • Audit reinforces Malwarebytes' commitment to transparency and high security standards.

Malwarebytes has successfully concluded its first independent security audit of AzireVPN’s infrastructure, underscoring its commitment to maintaining a no-logs policy.

The audit, which was performed by the respected security firm X41 D-Sec, provides a clear validation of Malwarebytes' strict adherence to privacy conventions. Since acquiring AzireVPN in 2024, Malwarebytes has integrated its features into its VPN service, demonstrating its emphasis on safeguarding user privacy.

Commitment to transparency and security

In an effort to differentiate itself in a sector where trust often hinges on undisclosed assurances, Malwarebytes opted for transparency by opening up its source code, server configurations, and internal processes to the audit.

Marcin Kleczynski, Founder and CEO of Malwarebytes, stated, "Trust shouldn't be a leap of faith; it should be an informed choice based on evidence. By completing this audit, we are moving beyond promises and providing our users with objective proof that their data is handled with the highest privacy and security standards."

Audit methodology and inspection

For a thorough assessment, X41 D-Sec conducted a white-box penetration test over two months. This involved a comprehensive examination of Malwarebytes’ software and hardware, utilised in its VPN service operation. The auditors had full access to:

  • Core applications, encompassing source code across platforms including Windows, macOS, Android, and iOS.
  • The server infrastructure, allowing an in-depth look into the global VPN node network configuration.
  • The privacy architecture, confirming that the no-logs systems ensure no identifiable user data is stored or accessible.

Key audit outcomes

Malwarebytes’ proactive approach to the findings was also highlighted

The audit results decisively verified Malwarebytes' no-logs policy, with auditors reporting no evidence of user IP address logging, browsing history tracking, or DNS query records. X41 D-Sec remarked, “During our assessment, we did not observe evidence of user activity logging, and access to systems is tightly controlled, with no unnecessary remote, local, or SSH access exposed.” Furthermore, the audit concluded that Malwarebytes' systems possess a commendable security level relative to other systems of equivalent size and complexity.

Malwarebytes’ proactive approach to the findings was also highlighted. X41 confirmed that most identified vulnerabilities, including a critical one, have been addressed, with the remaining issues currently being resolved.

Elevating the benchmark for VPN providers

Jérôme Boursier, Principal Research Engineer at Malwarebytes, commented, “This thorough security audit provides the level of transparency any VPN provider and privacy company should aim for. Combining a software audit with hardware penetration testing is invaluable. It gives our users a clear understanding of how we operate and how we stand apart from competitors.”

The audit outcomes are intended to solidify Malwarebytes' commitment to security while setting a higher standard for user privacy.

Features of Malwarebytes Privacy VPN

Malwarebytes Privacy VPN offers an ultra-fast and secure internet experience, with servers distributed globally to ensure unrestricted accessibility.

Key features of the service include RAM-only, diskless servers, an independently verified no-logs policy alongside Blind Operator Mode, full infrastructure control, and consistent transparency reports with Warrant Canary notices. Recent expansions include new servers in Jakarta, Indonesia, and Johannesburg, South Africa, enhancing the VPN’s reach and capabilities.

In case you missed it

How can physical security technology promote better executive protection?
How can physical security technology promote better executive protection?

Like other disciplines in the world of corporate security, executive protection is evolving from reactive to proactive. Unlike reactive bodyguards, modern executive protection prof...

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...