Skip to content
Assurance Program

Trust, but verify - including us

A security company should hold itself to the standard it sells. Our assurance program makes our guarantees inspectable: independent review, reproducible builds, continuous conformance, and published evidence.

Pillars

How we earn trust

Independent review

Third-party cryptographic and security review of the reference core and protocol.

Reproducible builds

Releases are reproducible and recorded in a public transparency log.

Continuous conformance

Every release runs the full test-vector corpus across all SDKs.

Coordinated disclosure

A published vulnerability process with signed advisories.

Evidence

What we publish

Assurance is only meaningful if it's checkable. We publish the artifacts that let you verify our claims independently.

Conformance reports

Signed per-release reports mapping implementations to profile guarantees.

Security advisories

Signed advisories with severity, scope, and remediation guidance.

Cryptographic documentation

Published algorithms, constructions, and key-management design.

Change transparency

Specification changes tied to the RFC that introduced them.

Maturity

Assurance roadmap

Available

Open evidence

Open spec, public test vectors, transparency-logged releases, disclosure process.

In progress

Independent audits

Third-party security and cryptography assessments of the reference core.

Planned

Formal certifications

Pursuing recognized security and compliance attestations as the platform matures.

Planned

Readiness consulting

Guided assessments and readiness engagements for regulated customers.

We describe certifications as in-progress or planned only where that is accurate. We will not claim an attestation we do not hold.

Regulated mission?

Talk to us about readiness

From zero-trust alignment to readiness assessments, our team can help you plan a compliant deployment.