From 12 to 25 September 2026, an independent security auditor spent two weeks trying to break into NullShip. The test ran on the live service itself, through the .onion and through nullship.eu, looking at it as a visitor, as a customer and as a reseller on our API. Breaking in was the job, and we paid for it. Here is what we can tell you, what stays private, and why.
Privacy is what we sell. You trust us with addresses, with money, and with the plain fact that you ship at all. We keep as little as we can, but what we do keep, and every step from choosing a rate to downloading your label, has to hold up against someone who is really trying.
Our own reviews can't prove that. Whoever builds a system tends to test it the way it is meant to be used; an outsider tests it the way it can be abused. This was our second external test this year, after one in May, with internal audits in between.
The auditor started where any customer starts: an ordinary account, with no admin rights. The scope was the full web application, from the public pages to the checkout, the customer panel and the reseller API, reached through both entrances, the .onion and nullship.eu.
Findings arrived in rounds. We triaged each round the day it arrived; the fixes went live within 48 hours and were tested again against the live site, not just on a developer's machine. Where a fix can be tested automatically, it now is, so a later update can't undo it without us noticing.
The auditor's public summary counts 27 findings. They are in the places where web services usually fail: edge cases in how orders and payments flow, how input is checked, how sessions, tokens and redirects behave, how much one person can do in a minute, and what error pages and headers give away.
Two answers matter more than the rest. No finding gave anyone access to another customer's addresses, labels or balance. And none let anyone buy a label for less than its real price.
You won't find a list of findings, severities or fixes here. That was agreed with the auditor, and we think it is the right call: a detailed map of how the site was probed helps the next attacker far more than it helps you. The outcome is above, and the auditor's own summary is public.
A test is a snapshot: two weeks, one very capable attacker. It doesn't make any service bulletproof, and we won't pretend it does. What it does show is how we work: we ask to be attacked, and we move fast on what turns up. We will keep doing it.
Found something yourself? Write to us from the contact page, and encrypt it with our PGP key if it is sensitive. We read every report.