Back to CipherLink
v3 Production Hardened

Security Audit Pack

Comprehensive security documentation for independent auditors. Threat model, attack surface review, protocol state specification, and security claims mapped to code and tests.

Important: This project is a v3 production-hardened prototype. The audit pack is designed to facilitate independent security review. An external audit is recommended before high-risk production use.
156
Tests
34
Security Claims
9
Adversary Classes
24
Features
5
Attack Surfaces

Threat Model

9 adversary classes (passive observer, malicious server, nation-state, supply chain, device thief, insider, network attacker, quantum adversary, malicious contact). Security properties and coverage analysis.

Read Document

Attack Surface Review

Comprehensive entry point analysis across client crypto library, mobile app, server relay, and network transport. Risk assessment with input validation coverage.

Read Document

Protocol State Specification

Formal session lifecycle with 5 states (UNINITIALIZED to CLOSED). State transition rules, invariants, epoch management, and key rotation policy.

Read Document

Security Claims Mapping

34 security claims mapped to specific code locations and test files. Each claim lists evidence, verification status, and gaps requiring attention.

Read Document

Feature Status Table

Complete feature-by-feature status table across v1 core, v2 hardening, v3 production, server relay, and infrastructure. Implementation status with test counts.

Read Document

v2 Security Architecture

Full v2 architecture document with threat matrix, attack surface diagram, cryptographic design specifications, metadata resistance design, and phased upgrade plan.

Read Document