The construction, source and test vectors are public for review. An independent cryptographic audit is planned and is not complete. Passing implementation checks is not an independent security audit or proof of security.
Cyber Essentials covers organisational security controls; it does not validate the cryptographic construction. SOC 2 examination and ISO 27001 certification remain on the roadmap, as detailed below.
Limits and scope
Decoys provide an alternative message, not a guarantee against coercion, legal compulsion or evidence from other sources. File metadata, access patterns and the surrounding context can distinguish messages. Keep real control files separate.
Tripwires observe matching inputs at supported deny.sh decrypt endpoints. Offline decryption and a fake credential tested directly with another provider are not automatically observed. Alert delivery and key rotation have no guaranteed timing.
Agent integrations depend on trusted code keeping real keys outside model-accessible context, tools, logs and errors. They do not prevent misuse of an authorised tool or compromise of the trusted runtime.
Hosted encryption receives messages and passwords during processing. Local browser and SDK encryption keep those inputs in your environment. BYOK revocation blocks future unwrapping, not copies already obtained.
Read the full threat model · Processing boundaries · Certification and review details