Security Audits

MapleCloud undergoes independent third-party security audits. Results are published in full.

Cryptography & Key Management Audit

Conducted by Cure53 · October 2025

Passed

Reviewed the SRP-6a authentication flow, OpenPGP key hierarchy, share key derivation, and block-level file encryption. No critical vulnerabilities found. Two medium-severity issues (now resolved) were reported relating to session token entropy.

Full report available on request

Web Application Penetration Test

Conducted by NCC Group · March 2025

Passed

Comprehensive penetration test of the web application, API endpoints, and authentication flows. No critical or high-severity findings. Three low-severity issues resolved within 14 days of report.

Full report available on request

Bug bounty

We operate a responsible disclosure programme. If you discover a security vulnerability, please email [email protected]. We respond within 24 hours and offer rewards for qualifying reports.