| Acceptance run (normal user rights) | 19 steps passed, 0 failed, 0 skipped | End to end with the command-line program: create, add, lock, open, extract, password and recovery |
|---|
| Build tests | User 50/50, Administrator 11/11, installer 61/61 | Test suites that run during the build |
|---|
| Known cryptographic test vectors | All passed | NIST GCM document Test Cases 13–16 for AES-256-GCM, RFC 7914 for PBKDF2-HMAC-SHA256 and RFC 5869 for HKDF; the vectors were also checked independently with Node.js |
|---|
| Tampering | All caught | A single bit (11 positions), swapping chunks, cutting off the last chunk, a chunk from another file or an older state, another vault's header, lowering the round count, putting an old index back |
|---|
| Name leakage in a locked vault | No file names, content markers or extensions found | The raw bytes of a locked vault were searched as UTF-8 and UTF-16; names on disk are random identifiers only |
|---|
| Killing the program while writing | Earlier files intact, no half-written files | The process was killed at 5 specific stages and at 6 random moments |
|---|
| Changing the password | Encrypted files stayed byte for byte identical | Test and an acceptance step: only the password wrapping is redone |
|---|
| Large file | A 2.2 GB synthetic file was added and decrypted, SHA-256 identical, memory growth under 200 MB | A sparse test file was streamed and verified without being written to disk |
|---|
| Panel security | Attempts from other sites and processes were rejected | Only 127.0.0.1, Host check, cookie, CSRF and Origin checks, no inline scripts |
|---|
| Mutation run | All 40 of 40 inserted faults were caught | Faults were deliberately put into the code to see whether the tests caught them |
|---|
| Interface, 21 languages | 214 screens measured: horizontal scrolling, overflowing text and script errors all 0 | Automatic measurement; the images were looked at by eye only in Arabic, Urdu, Tamil and German |
|---|