VeraCrypt is based on the source code of TrueCrypt, which passed an independent security audit. Phase I of the audit was successfully completed on 14 April 2014, finding "no evidence of backdoors or malicious code."
Phase II of the audit was successfully completed on 2 April 2015, finding "no evidence of deliberate backdoors, or any severe design flaws that will make the software insecure in most instances."
An independent code audit of VeraCrypt 1.18 was conducted by
on behalf of the
, taking 32
and published on 17 October 2016.
The major vulnerabilities identified in this audit were resolved in VeraCrypt 1.19, released the same day.