INVITE ONLY
OBSERVATORY

08 Security · Transparency

Read the deviations before the passes.

An audit index that hides its deviations is marketing. Every artifact below ships with its honest state — including the ones that are not ready.

Count the deviations. There are three.

NIAP — ready with deviations, evaluation in progress

The pre-evaluation ETR (2026-05) is not a completed EAL 4+ certification. Deviations are enumerated; formal evaluation is in progress.

CNSA 2.0 — asymmetric core conformant (ML-KEM-1024 + ML-DSA-87 at Category V; SHA-512 at or above the hash floor). Production AEAD today is ChaCha20-Poly1305 (RFC 8439), a documented deviation; the AES-256-GCM NSS suite is implemented and reserved as suite 0x0002, staged for rollout. Pre-evaluation checklist: 0 non-conformant findings, 3 documented deviations (NIAP ETR, 2026-05).

1. SLH-DSA fail-closed scaffolding — present in the tree, not yet active. 2. ChaCha20-Poly1305 as production AEAD in place of the AES-256-GCM NSS suite. 3. SHA-1 retained solely for TURN/TOTP legacy interop, outside the cryptographic core.

Algorithm-conformant; implemented via a library lineage holding FIPS 140-3 cert #4631; QERYX’s own module is not yet CMVP-certified. Test vectors are pinned in the tree — module validation is a separate claim we do not yet make.

Drafts authored (draft-qeryx-*-00/-01); submission packages prepared. This line will say “submitted” when receipts exist, and not before.

Re-run the proofs. The model hashes are published.

Five core primitives carry Verifpal symbolic proofs — 5 of 5 PASS1 — plus five Q-Entangle-Bell models. Model hashes are published so a reviewer re-runs exactly what we ran.

Q-FormalVerify v1 — proven claims per primitive
PrimitiveVerified claimResult
Q-Ratchet forward secrecy under later long-term key compromise + bidirectional authentication PASS 4/4
Q-KEM-Trinity confidentiality under partial component break PASS 3/3 + negative control fails as designed
Q-GroupCipher post-eviction payload + root confidentiality + commit authentication PASS 3/3
Q-Anamorph duress payload confidentiality under compelled cover-key surrender PASS 2/2
Q-Threshold secrecy under t−1 share leakage PASS 3/3 + negative control fails as designed

The negative controls matter: upgrading the modeled attacker past the claimed bound makes the prover produce a concrete attack trace, demonstrating the passes are non-vacuous rather than vacuously true.

Check the build chain in the present tense.

Build-attestation manifest published (ML-DSA-87, ctx QERYX-attest-v1); update-authenticity trust-root registry not yet claimed.

The current software bill of materials is pinned to an earlier tree and is not yet signed. It is being re-generated against the shipping tree; until then it is listed here as stale rather than presented as current. Dependencies themselves are version-pinned in the repositories.

2-of-3 multi-witness quorum (verify-only today — operator equivocation is detected, not prevented) plus three external Ed25519 auditor slots that ship dormant: all three hold placeholder keys, so no external cosignature is carried yet. Registry expansion is release-gated by design.

Look for a live canary. There is none to read.

Canary — reissue ceremony pending

The canary reissue ceremony and its monthly cadence have not yet begun for this site. This block will state the signed date, the clause set, and the transparency-log reference when they exist — a canary’s value is its freshness, and we will not display a stale one as live. The full clause semantics are documented at /security/disclosure.

The hard questions.

Because an evaluator finds them anyway, and a vendor who found them first — and documented them — is showing the evaluator the review actually happened. Each deviation carries its remediation path in the ETR.

The evaluator surface is /trust: conformance evidence, the maximal-claim table, and the methodology every number on this site footnotes to.