Skip to content
Public audits

Independent post-quantum audits

Security reviews of public cryptography projects: the verdict, findings by severity, and the reviewers behind each one. Repository owners can claim their audit and receive a tamper-proof, on-chain certificate.

Fixed upstream

1 of 3 reviews have every finding fixed upstream

We report findings to maintainers before publishing, and we publish the merge that closes each one. 1 pull request across 1 project, each linked from the finding it resolves, so nothing here rests on our word.

Free for open source

Have your project reviewed

Send us a repository and we will read the cryptography in it. You see every finding privately first, with time to fix it, and nothing is published until the fix can be published alongside. No cost, and no NDA to sign.

fig.11: repository to published reviewyou send · we read · both publish
github.com/you/reporeviewby severitypublished reviewfix mergedfree, and public
private to the maintainer firstfix merged upstream

Request an audit

Maintain an open source cryptography project? Tell us where it lives and we will take a look.

GitHub repository
Your email

We review open source projects free of charge, report findings to maintainers privately first, and publish only with the fix alongside.