Our Commitment to Transparency
At Malloc, we believe privacy and trust must be earned, not assumed. This Trust Centre provides verified information about our jurisdiction, audits, data protection policies, and server architecture, allowing users to independently verify that Malloc operates with integrity and respect for privacy.
Jurisdiction
- Company: Malloc Ltd.
- Registered in: Cyprus 🇨🇾 (European Union)
- Applicable laws: GDPR, ePrivacy Directive, and other EU data protection frameworks.
- Implication: Not subject to US or UK surveillance frameworks (FISA, IPA).
Independent Audits
| Audit Type | Date | Status |
|---|---|---|
| Mobile App Security (MASA Level 2) | 2025 | ✅ Completed |
| No-Logs & Privacy Infrastructure | 2026 | 🧩 Planned |
| Server Security Architecture | 2026 | 🧩 Planned |
All future audit reports will be published here upon completion.
Server Architecture
- RAM-Only Servers (Active): All servers operate exclusively in memory. Data is never written to disk and is automatically wiped on reboot.
- No Traffic Logs: We do not monitor, log, or retain any user activity or metadata.
- Encryption: AES-256-GCM with Perfect Forward Secrecy (TLS 1.3).
Disclosure & Transparency Policy
- No-Logs Policy: We never log, monitor, or store user traffic, DNS queries, or connection timestamps.
- Data Requests: As of November 2025, Malloc has received 0 government data requests. Transparency Reports will be published twice per year.
- Third-Party Access: No external entities have access to user data or servers.
- Incident Reporting: In the event of a security incident, Malloc will disclose details within 72 hours of discovery.
Security Features Summary
| Feature | Status | Description |
|---|---|---|
| AES-256-GCM Encryption | ✅ | Industry-standard encryption |
| Perfect Forward Secrecy | ✅ | New keys for every session |
| Kill Switch | ✅ | Blocks traffic if VPN disconnects |
| DNS Leak Protection | ✅ | Ensures DNS queries stay private |
| Multi-Hop Routing | 🧩 | In development |
| RAM-Only Servers | ✅ | Fully active and privacy-safe |
| Open-Source Client | 🧩 | Planned for Q2 2026 |
Roadmap (2025–2027)
- ✅ Expand independent audits (no-logs & server security).
- ✅ Publish bi-annual transparency reports.
- ✅ Maintain full RAM-only infrastructure.
- 🧩 Launch open-source Android and iOS clients in Q2 2026.
- 🧩 Introduce European-hosted bug bounty program.
For security inquiries, audit collaboration, or transparency questions:
Contact Security TeamLast updated: November 2025
© 2025 Malloc. All rights reserved.