Security claims are easy. Receipts are harder.
We hand our hardware and code to independent experts whose job is to find where we were wrong, then publish the results.
Both Passport Core and Passport Prime have undergone independent security audits by Keylabs. We publish the reports in full, including the findings and our responses.
Passport Prime
Keylabs audited the hardware and firmware, including secure boot, tamper response, wireless isolation, physical attacks, fault injection and key extraction.
No critical or high-severity vulnerabilities were identified. The five low-impact findings were addressed and documented publicly.
Audit:
https://foundation.xyz/security/passport-prime-keylabs-audit-2025.pdfOur response:
https://foundation.xyz/security/passport-prime-audit-response-2025.pdfPassport Core
The pre-production review found issues in the boot process, firmware handling and downgrade protections. We fixed them, Keylabs sanity-checked the fixes, and we published the unmodified report.
Audit:
https://foundation.xyz/security/passport-core-keylabs-audit-2021.pdfOur response:
https://foundation.xyz/security/passport-core-audit-response-2021.pdfOur ongoing bug bounty keeps the door open for researchers to report new vulnerabilities across Foundation products and services.
All security resources:
https://foundation.xyz/security