What the DJI Security Audit Is and Why It Matters
The DJI security audit is an independent technical assessment by cybersecurity firm OnDefend that examined whether selected DJI drones contain backdoors, enable hidden data exfiltration risks, or present other serious cybersecurity threats, and its findings are being used to challenge current import and communications restrictions imposed on the company’s products. OnDefend, a Florida-based firm with U.S. military and government veterans on staff, was hired by DJI but bought test units from normal retail and dealer channels, rather than receiving them from the manufacturer. The engagement focused on two systems: the consumer DJI Air 3S with RC 2 controller and the enterprise DJI Matrice 4E with RC Plus 2 Enterprise controller. For DJI, the high-stakes goal is clear: use independent drone backdoor detection and network analysis to counter the security rationale behind the existing FCC Covered List designation and the broader US drone ban debate.

Key Findings: No Backdoors, No Data Leaving the US
OnDefend’s 16-page report delivered the headline DJI hoped for: no backdoors and no evidence of data leaving the US from the tested systems. The firm reported zero critical, high, or medium-risk issues and instead listed ten low-risk findings plus several minor observations that DJI says it will fix through software updates. According to PCMag, “independent testing found no backdoors, no data leaving the US, and no viable pathways for hijacking or misuse.” Full-spectrum RF scans showed no unexplained radio emissions; every signal was tied to documented functions, and signals not listed in FCC filings were explained as artifacts of the control link design rather than covert channels. Attempts to jailbreak controllers, tamper with firmware, or hijack flight control did not yield a viable attack path, reducing the perceived data exfiltration risks and drone takeover scenarios that have shaped much of the policy debate.

How Independent Is the OnDefend Assessment?
Although DJI commissioned the work, the company emphasizes that it gave OnDefend latitude to act independently and did not provide hand-picked hardware. Consumer Air 3S units were purchased through regular retail outlets without notifying DJI, while Matrice 4E enterprise units came from existing dealer stock, so the tested systems reflected normal market distribution. OnDefend’s team, which includes former U.S. military and government professionals, applied “advanced adversarial testing across software, hardware, and radio frequency domains,” including static and dynamic app analysis, full network capture, RF scanning from 1 MHz to 6 GHz, PCB teardown, and active jamming and injection attempts. Still, the audit’s scope is limited. It covers only two product lines and focuses on platform security, not on broader geopolitical considerations. That caveat matters, but the work remains a rare, detailed piece of third-party technical evidence in a discussion often dominated by speculation.

Fuel for DJI’s Petition Against the US Drone Ban
DJI’s inclusion on the FCC Covered List in December 2025 effectively blocks new DJI gear, including non-drone products, from entering the US market. The company argues that this happened after a congressionally mandated 2024 audit was never carried out, leaving it banned without publicly presented technical evidence. The new DJI security audit aims to fill that void. DJI has submitted the OnDefend results as part of its petition asking the FCC to remove it from the list and lift the US drone ban on its latest products. Public interest is significant: PCMag notes that the petition process has drawn nearly 3,200 filings, many from users warning that restrictions would limit access to DJI’s relatively affordable, feature-rich technology. DJI says the findings “directly challenge the security rationale behind” the ban and support its claim that its data practices are transparent and its products are secure.

What It Means for Consumers and Drone Regulation
For filmmakers, first responders, and commercial operators, the OnDefend report is more than a technical curiosity. DJI remains a default choice for aerial imaging, and the US drone ban on new imports has concrete effects on fleet upgrades, replacement units, and access to accessories. The audit strengthens DJI’s argument that, at least for the tested platforms, there is no demonstrated security basis for keeping its products off the market. Petapixel reports that OnDefend “found that there are no security-related reasons for blocking DJI’s products from being imported and sold in the United States.” Regulators, however, may weigh security testing alongside wider policy goals, and the audit does not bind them to a specific outcome. Still, by putting detailed drone backdoor detection and data exfiltration analysis on record, the report pressures policymakers to ground future restrictions in verifiable technical evidence rather than broad assumptions.






