This technical report documents the findings from a penetration test and source code audit conducted on the IVPN DNS application, focusing on its user interfaces, APIs, and overall setup. The assessment was commissioned by IVPN Limited and executed by Cure53 in May 2025. The testing methodology employed a white-box strategy, utilizing both manual testing and automated tools to evaluate the application's security posture. The report outlines the scope of the testing, which included two work packages: one for the user interface and another for the API. The findings revealed a solid security foundation with only minor vulnerabilities identified, such as issues with two-factor authentication rate limiting and weaknesses in the TOTP backup code generation process. The report provides a detailed breakdown of the identified vulnerabilities, including their severity and recommendations for remediation. Overall, the application was found to maintain strong security practices, effectively mitigating common web vulnerabilities.