Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. Proton VPN has made its apps’ source code public across multiple platforms and publishes links to independent security audits. The effort began with a January 21, 2020 announcement covering Windows, macOS, Android, and iOS; later Proton materials add browser and Apple TV code. Public code makes inspection possible, but does not by itself prove that every distributed app binary matches that code or that every release has been audited.

What Proton announced—and what is public now

On January 21, 2020, Proton said it was opening the source code for its Windows, macOS, Android, and iOS VPN apps and undergoing an independent security audit. The company described its announcement as the first of its kind; that is Proton’s own claim, not an independently established industry ranking. Proton’s announcement was updated on December 1, 2025, and now links repositories for Android, iOS/iPadOS, macOS, Windows, and browser code.

Proton’s November 5, 2024 roadmap says the company published Apple TV app source code in September 2024. It also says the app’s App Store availability followed a review delay. These dated statements describe a continuing expansion of public code, not proof that every platform has feature parity or that all app releases are identical to the public repositories.

Where to find the source code

Start at the repository links on Proton’s open-source announcement, which lists Android, iOS/iPadOS, macOS, Windows, and browser code. Proton’s current open-source overview also links to its GitHub presence and audit reports. For Apple TV, Proton’s dated roadmap reports the September 2024 publication of its source code.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Proton says apps that are out of beta are open source. Check the repository and release information for the particular app and version you care about; the general open-source statement should not be read as proof that every beta, build, or installed binary has been published or independently verified.

What open-source code can—and cannot—show

What inspection makes possible

Public source code allows researchers and other readers to examine how an app is implemented, including code related to encryption and data handling. It can also enable community scrutiny and contributions. That transparency is useful because outsiders need not rely solely on a vendor’s description of its client software.

What it does not establish

  • Public source alone does not prove that a particular app-store download or installed binary was built from the source shown in a repository.
  • It does not show that every release has been audited, nor does it guarantee that an app has no vulnerabilities.
  • Client code does not, by itself, verify how the VPN provider handles all traffic once it reaches the provider’s servers.

A VPN changes where some trust resides rather than removing the need for trust. Proton explains that traffic is encrypted between a device and a VPN server, while the VPN provider can see data of the kind an internet service provider could otherwise see. Open client code is therefore one form of transparency, not independent proof of every aspect of the service’s network-side practices.

Open source and security audits are related, but different

Proton’s announcement describes independent audits as an ongoing practice and names security researcher Ruben Santamarta as a contracted independent researcher. Proton’s current open-source overview says its apps are open source and independently audited, and links audit reports. Those are Proton’s statements about its program.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The linked latest audit PDF was not accessible through Proton Drive in this review, so its date, scope, platform coverage, findings, and remediation details cannot be confirmed here. Do not infer a specific audit result or assume that a report covers every app simply because Proton links to it. An audit is a point-in-time assessment with a defined scope; public source code and an audit report answer different questions.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How researchers can report a vulnerability

Proton’s public bug-bounty program rules include its Windows, macOS, Linux, iOS, and Android apps. The rules ask researchers to use responsible disclosure and avoid actions that degrade service quality, expose sensitive data, or attack user accounts. Anyone considering testing should read the current rules first and follow their scope and reporting instructions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.