Trust, but verify - including us
A security company should hold itself to the standard it sells. Our assurance program makes our guarantees inspectable: independent review, reproducible builds, continuous conformance, and published evidence.
How we earn trust
Independent review
Third-party cryptographic and security review of the reference core and protocol.
Reproducible builds
Releases are reproducible and recorded in a public transparency log.
Continuous conformance
Every release runs the full test-vector corpus across all SDKs.
Coordinated disclosure
A published vulnerability process with signed advisories.
What we publish
Assurance is only meaningful if it's checkable. We publish the artifacts that let you verify our claims independently.
Conformance reports
Signed per-release reports mapping implementations to profile guarantees.
Security advisories
Signed advisories with severity, scope, and remediation guidance.
Cryptographic documentation
Published algorithms, constructions, and key-management design.
Change transparency
Specification changes tied to the RFC that introduced them.
Assurance roadmap
Open evidence
Open spec, public test vectors, transparency-logged releases, disclosure process.
Independent audits
Third-party security and cryptography assessments of the reference core.
Formal certifications
Pursuing recognized security and compliance attestations as the platform matures.
Readiness consulting
Guided assessments and readiness engagements for regulated customers.
We describe certifications as in-progress or planned only where that is accurate. We will not claim an attestation we do not hold.
Talk to us about readiness
From zero-trust alignment to readiness assessments, our team can help you plan a compliant deployment.