[Go to site: main page, start]

Security assessments
for software that matters.
Security analysis and architectural advice
Penetration tests for online services
Infrastructure, platform and cryptography audits
Contact us
Services Learn about the Services we offer
Security analysis and architectural advice

Security advice is often most valuable before a single line of code is written. For early-stage or fast-moving projects, an initial assessment of architecture and design choices is far more effective than a late-stage penetration test.

We help you evaluate the trustworthiness of third-party components, the security posture of open-source dependencies, and whether chosen design patterns can withstand real-world threats.

Our team has guided numerous projects through their formative phases, identifying subtle risks and architectural pitfalls long before they become costly vulnerabilities.

Seeking expert input early saves time, reduces risk, and empowers teams to build securely from the ground up—free to focus on shipping code without fearing the fallout.

Penetration tests for online services

Cure53 offers classic black-box penetration tests (zero-knowledge) as well as white-box tests and code audits. Web application and mobile app developers speak many languages and so do we. From classic languages as PHP, JavaScript, ActionScript, Java, Ruby, Python and Perl to more exotic candidates like web back-ends written in C++ and Delphi – we've seen them.

During our assignments we appreciate contact to the development team to be able to discuss bugs, vulnerabilities and fixes as quickly as possible. At the time of report submission, all critical bugs we spotted are usually fixed already – or soon thereafter.

Our assignments don't end with the report submission. Ongoing communication and knowledge transfer are part of the package – we rarely experience the often mentioned gap between development and security.

Since Cure53 was founded in 2007, we have performed several hundreds of penetration tests against all kinds of web applications, online services, hardware interfaces, mobile applications, libraries and crypto tools. We value manual and thorough tests, human interaction and communication and a short yet to-the-point penetration test report without overhead or pie charts no one wants to see.

Infrastructure, platform and cryptography audits

Cure53 excels in providing detailed and targeted audits for infrastructure, platforms, and cryptographic systems. Our audits go beyond the traditional scope of application security, assessing the integrity and resilience of the underlying architecture that supports critical digital operations. Whether it's cloud infrastructure, server setups, or complex platform configurations, we ensure that every layer is scrutinized for vulnerabilities and weaknesses.

In the realm of cryptography, we specialize in assessing the security of cryptographic algorithms and their implementations. Our team is well-versed in evaluating key management systems, encryption protocols, and cryptographic libraries to ensure they meet the highest standards of protection. We provide thorough analysis to prevent potential threats like key exposure, weak encryption, or misconfigurations that could lead to significant security risks.

Our holistic approach to security auditing ensures that both the hardware and software aspects of your system are thoroughly tested. From protocol vulnerabilities to cloud security gaps, we offer expert insights and remediation strategies that help businesses safeguard their assets and maintain robust protection against evolving threats.

Publications Download articles and papers

All reports are been proudly published upon explicit request by the project maintainers, or the party that sponsored the penetration test in coordination with the project maintainer. The links below are ordered by publication date.

Reports
2024 Audit-Report Coinbase cb-mpc Library & Cryptography 12.2024 Pentest-Report ExpressVPN Aircove Firmware 11.2024 Audit-Report ExpressVPN Lightway Protocol 10.-11.2024 Pentest-Report KeePassium iOS Apps & Crypto 10.2024 Pentest-Report Obsidian Sync API, Server & Crypto 09.2024 Summary-Report Obsidian Sync API, Server & Crypto 09.2024 Pentest-Report Obsidian Clients & UI 09.2024 Summary-Report Obsidian Clients & UI 09.2024 Audit-Report MetaMask Greymass Antelope Snap Codebase & Build 09.2024 Audit-Report MetaMask Hedera Wallet Snap Codebase & Build 09.2024 Audit-Report Noble Cryptography Libraries 08.2024 Audit-Report Tuum MetaMask AuthFlow Snap Codebase & Build 08.2024 Audit-Report Nym Mobile & Desktop, VPN, Infra & Cryptography 07.2024 Pentest-Report ODK Mobile Apps, Server 07.2024 Pentest-Report Mullvad VPN Relay-Infrastructure 06.2024 Pentest-Report ExpressVPN VPN Browser Extension 05.2024 Pentest-Report Psiphon Tunnel Core Codebase 05.2024 Pentest-Report Psiphon Conduit Integration Codebase 04.-05.2024 Audit-Report Distrust Keyfork Toolkit & Library 04.2024 Audit-Report Kyraview Stellar Snap Codebase & Build 04.2024 Audit-Report MetaMask Hedera Wallet Snap Codebase & Build 04.2024 Pentest-Report Passbolt UWP Windows App 03.2024 Pentest-Report IVPN Websites & Servers 03.2024 Audit-Report MetaMask Signing Snap Codebase & Build 03.2024 Audit-Report Rubic MetaMask Snap Codebase & Build 02.2024 Audit-Report BOB MetaMask Snap Codebase & Build 02.2024 Pentest-Report Threema Desktop App 01.2024 Audit-Report SolidiFi Wallet Staking Feature 01.2024
Team Meet the Cure53 Team

Our team brings together independent security experts collaborating on a project basis. They operate with professional autonomy under robust contractual frameworks, including NDA and GDPR-compliant agreements, and follow strict security and data-protection standards to ensure trust, confidentiality, and client safety.

Dr.-Ing. Mario Heiderich mario@cure53.de | PGP Dipl.-Ing. Alex Inführ alex@cure53.de | PGP MSc. Sebastian Moritz seba@cure53.de | PGP Maxim Rupp rupp@cure53.de | PGP MSc. Dario Weißer dario@cure53.de | PGP Dr. Marta Conde marta@cure53.de | PGP Dr. Alexander Pirker apirker@cure53.de | PGP Jesper Larsson jesper@cure53.de | PGP BSc. (Hons) Edwin "EdOverflow" Foudil ed@cure53.de | PGP BSc. Anthony Roth anthony@cure53.de | PGP
MSc. Robin Peraglie robin@cure53.de | PGP MSc. Johannes Moritz johannes@cure53.de | PGP Mohan "S1r1us" Pedhapati s1r1us@cure53.de | PGP Masato Kinugawa masato@cure53.de | PGP MSc. Fabian Fäßler fabian@cure53.de | PGP MSc. Nikolai Krein niko@cure53.de | PGP Dr. Nadim Kobeissi nadim@cure53.de | PGP Dr. hab. Paula Pustułka paula@cure53.de | PGP BSc. Dennis Brinkrolf dennis@cure53.de | PGP Dr. Matt Atkinson matt@cure53.de | PGP
Jack Rudy Walker Smith jack@cure53.de | PGP Norman Hippert norman@cure53.de | PGP MSc. Elyas Damej elyas@cure53.de | PGP BSc. Christopher Kean chris@cure53.de | PGP Michael Wege mike@cure53.de | PGP Julian Hector julian@cure53.de | PGP Martin Elrod martin@cure53.de | PGP BSc. Felix Heiderich felix@cure53.de | PGP MSc. Oskar Zeino-Mahmalat oskar@cure53.de | PGP Dr.-Ing. Tilman Frosch tilman@cure53.de | PGP
Contact For business enquiries
please contact
hello@cure53.de

Email hello@cure53.de Telephone +49 1520 8675 782

We speak PGP and S/MIME

Address Cure53,
Dr.-Ing. Mario Heiderich
Wilmersdorfer Str. 106
D-10629 Berlin
Germany

Payment As well as the usual, we also accept Bitcoin (BTC), Bitcoin Cash (BCH), Ripple (XRP) and Ethereum (ETH).

Bill.com, Deel and Veem also work for us.

Insurance During our assignments we are insured by the Gothaer Allgemeine Versicherung AG

Legals Tax-ID: 24/336/01163
VAT: DE-275774772

No cookies
No trackers
No ads