OTF & Assured AB’s Independent Security Audit of Save

With support from the Open Tech Fund’s Red Team Lab, OpenArchive has completed a new independent security audit of Save, conducted by Assured AB.
At OpenArchive, the safety and privacy of the people who use Save remain central to our work. Save helps individuals, journalists, researchers, human rights defenders, and civil society organisations securely verify, preserve, and share mobile media. Independent security testing is an important part of ensuring that the app continues to meet the needs of the communities that rely on it.
This assessment builds on Save’s previous independent security audits and reflects the continued development of the app since its 2023 review.
What the audit covered
Assured AB conducted a white-box penetration test of both the Android and iOS versions of Save between 18 February and 11 March 2026. Verification testing was then carried out between 26 June and 1 July to confirm the fixes and mitigations implemented in response to the initial findings.
The assessment covered the mobile applications and their source code. It considered both remote attacks and attacks involving physical access to a locked or unlocked device. Testing was conducted in accordance with the OWASP Mobile Application Security Testing Guide. Save does not include a central backend as part of its architecture, so no backend infrastructure was included in the scope.
The source code for both apps is publicly available:
Audit findings and outcome
The initial assessment identified three high-severity, one medium-severity, and eight low-severity vulnerabilities across the two applications. It also documented five examples of good security practice already present in the apps. No critical vulnerabilities were identified.
OpenArchive addressed every identified vulnerability. Assured AB subsequently retested the applications and independently verified that all findings had been fixed, either through the recommended approach or through an equally effective or stronger solution.
Assured noted that several of the implemented fixes went beyond the original recommendations and resulted in a more robust privacy and security posture across both apps. There are no remaining, partially resolved, or accepted vulnerabilities from this audit.
The assessment also confirmed several existing security and privacy protections, including secure credential storage practices, strong Android Keystore encryption settings, restricted application components, protection against unintended Android backups, and the absence of personal or sensitive information in application logs and analytics traffic.
The updated Android and iOS apps containing the independently verified fixes are expected to be available by the end of July 2026.
Read Assured AB’s full audit report
We are grateful to the Open Tech Fund’s Red Team Lab for supporting this important work, and to Assured AB for the care, professionalism, collaboration, and technical expertise they brought to the assessment.
Save remains always free, always open source.