Open code. Ready to inspect.
IcyZip’s browser encryption code and runnable security tests are freely available here. Read, download and test them yourself — no account or phone number required.
Clone with Git — including history
git clone https://icyzip.com/open-source/icyzip-e2ee.git cd icyzip-e2ee npm test
The repository is publicly readable. You can inspect and test changes in your own clone. Browse all commits.
Download the complete Git repository (.bundle)
git clone icyzip-e2ee.bundle icyzip-e2ee
What is published here
The package contains the complete browser E2EE module, its integration and receive logic, small standalone tests, attack regressions, and protocol and verification documentation. The proprietary server software is outside this package. Relay messages and trust boundaries are documented in the protocol.
The encryption uses WebCrypto: P-256 ECDH, HKDF-SHA-256, HMAC-SHA-256 and AES-GCM. A test using independent Node cryptography APIs also checks the results.
Run the tests
Extract the archive and run these commands in the extracted directory. Node.js 20 or newer is sufficient; the tests need no package installation, server, account or network.
tar -xzf icyzip-e2ee.tar.gz cd icyzip-e2ee sha256sum -c SHA256SUMS npm run test:minimal npm test
On macOS, use shasum -a 256 -c SHA256SUMS in place of sha256sum. On Windows, extract the archive with an archive utility and run the npm commands in the extracted folder.
Start here: test/minimal.test.mjs · TESTING.md
Compare with the live website
npm run check:live
This optional network check compares the entire encryption module and the three published integration sections byte for byte with the browser files currently served by IcyZip. PROVENANCE.md explains the scope and provenance. PROVENANCE.md
Docker review lab
The ready-to-run lab on Docker Hub packages this source release with Node.js, Git, OpenSSL, Python and inspection tools. It supports AMD64 and ARM64. After downloading, one command runs the protocol tests and reproducible mutation checks offline with synthetic data.
IMAGE=docker.io/icyzip/e2ee-review@sha256:827fa29a1b1f98c7dac1df1b068ef7eac1113908876acfcffc5658ac70c4a75f docker pull "$IMAGE" docker run --rm --network=none --read-only --cap-drop=ALL \ --security-opt=no-new-privileges --memory=768m --pids-limit=128 \ --tmpfs /tmp:rw,nosuid,nodev,size=128m "$IMAGE"
A passing run confirms the checks performed; it does not prove that the code or service has no weakness. The guide explains the inventory, licenses, scope and custom experiments.
Source and documentation
.gitignore29 bytes · Raw file.dockerignore597 bytes · Raw fileDockerfile3,978 bytes · Raw fileCONTAINER.md5,287 bytes · Raw filecontainer-lock.json1,271 bytes · Raw fileLICENSE11,358 bytes · Raw filePROTOCOL.md6,351 bytes · Raw filePROVENANCE.json1,439 bytes · Raw filePROVENANCE.md3,056 bytes · Raw fileREADME.md5,755 bytes · Raw fileSECURITY.md2,097 bytes · Raw fileTESTING.md3,046 bytes · Raw fileTHREAT-MODEL.md4,801 bytes · Raw filepackage.json1,018 bytes · Raw filesrc/e2ee.js14,319 bytes · Raw filesrc/snapshot.js23,738 bytes · Raw filetest/crypto.test.mjs14,259 bytes · Raw filetest/endpoint.mjs1,295 bytes · Raw filetest/file-receive.test.mjs14,293 bytes · Raw filetest/minimal.test.mjs1,099 bytes · Raw filetest/provenance.test.mjs5,246 bytes · Raw filetest/security-regressions.test.mjs2,057 bytes · Raw filetest/container.test.mjs4,547 bytes · Raw filetools/snapshot.mjs8,559 bytes · Raw filetools/fuzz.mjs6,617 bytes · Raw filetools/inspect.mjs3,456 bytes · Raw filetools/lab.mjs977 bytes · Raw filetools/sbom.mjs7,983 bytes · Raw file
Verify downloads
SHA-256 checksums identify the offered bytes. The archive also includes SHA256SUMS for every published file. The source ID is the SHA-256 of that checksum list; identical source IDs identify the same list.
Reviews and findings welcome
Inspect the code with your own synthetic test data and add reproducible cases. Please report suspected security weaknesses privately; general feedback can be sent without a name or email address.