Trust Center
Independent audits, source code, privacy practices, network data, and other information you can verify for yourself.
Last updated: October 1, 2026
SECTION 1
Independent security audits
Psiphon commissions independent security reviews of its software and publishes the resulting reports.
Pentest-Report Psiphon Circumvention Enhancements
Penetration testing all external facing servers and Market website. Report available upon request: security@psiphon.ca
Web application and infrastructure penetration testing. Report available upon request: security@psiphon.ca
SECTION 2
Open source
Psiphon's client applications and core tunnelling technology are open source. Anyone can read the code, build it, or contribute.
View the repositories →SECTION 3
Legal requests
We cannot provide information we do not have.
When we receive lawful requests for information, we can only disclose information that we actually have.
Psiphon has received requests seeking identifying information about users. We were unable to provide the information requested because we did not possess it.
This reflects how Psiphon is designed, not a case-by-case decision. Our Privacy Policy explains what information we process and, equally importantly, what we do not.
Read Policies & Data Handling →SECTION 4
Privacy & data handling
Psiphon is designed to operate without building an identity or browsing profile around its users. We process limited technical information needed to operate, secure, and improve the network, helping us adapt to censorship and keep people connected on adversarial networks.
Our Policies & Data Handling page provides the authoritative description of what is processed, why it is processed, who it may be shared with, and how long it is retained.
Read Policies & Data Handling →SECTION 5
Live network data
We publish aggregate statistics about the scale of the Psiphon network, updated regularly, with no login required.
SECTION 6
Report a vulnerability
We welcome responsible disclosure of security vulnerabilities.
Contact information, our disclosure policy, and encryption details are published in our security.txt file.
View security.txt →SECTION 7
Verify your download
Each Psiphon for Android client is shipped as an Android APK file (".apk") that is digitally signed by Psiphon Inc. The Psiphon Inc. certificate public key is as follows:
Owner: CN=Psiphon Inc., OU=Psiphon Inc., O=Psiphon Inc., L=Unknown, ST=Unknown, C=CA Issuer: CN=Psiphon Inc., OU=Psiphon Inc., O=Psiphon Inc., L=Unknown, ST=Unknown, C=CA Serial number: 349480e5 Valid from: Fri Jun 01 12:04:42 EDT 2012 until: Tue Oct 18 12:04:42 EDT 2039 Certificate fingerprints: MD5: BB:08:CD:91:22:FC:EB:17:1A:4A:3B:90:65:CE:2E:58 SHA1: 49:2C:3A:49:20:F3:6B:AE:95:90:EB:69:A6:36:E9:88:A7:41:7A:95 SHA256: 76:DB:EF:15:F6:77:26:D4:51:A1:23:59:B8:57:9C:0D: 7A:9F:63:5D:52:6A:A3:74:24:DF:13:16:32:F1:78:10 Signature algorithm name: SHA256withRSA Version: 3
An APK may be validated by (1) extracting the certificate from the archive and checking that its fingerprints matches the value above and (2) verifying that the APK is signed with the certificate. For example, using Unix and Java command-line tools:
$ unzip -p PsiphonAndroid.apk META-INF/PSIPHON.RSA | keytool -printcert $ jarsigner -verbose -verify PsiphonAndroid.apk
Psiphon for Android auto-updates itself, and this process automatically verifies that each update is authentic.
SECTION 8
Company & jurisdiction
Psiphon Inc. is a Canadian corporation headquartered in Toronto, Canada, and operates under Canadian law.