Skip to content

Latest commit

 

History

History
147 lines (112 loc) · 6.53 KB

File metadata and controls

147 lines (112 loc) · 6.53 KB

Qualified-reviewer research shortlist

Research date: 2026-07-31

Status: research only. No candidate has been contacted, selected, assigned, or authorized to begin work. Availability, conflicts, exact team, scope, schedule, publication terms, and cost are unknown.

The shortlist is deliberately small and unranked. It uses current first-party service descriptions and public reports to establish plausible relevance, not to endorse a firm or predict the quality of a future engagement.

NCC Group Cryptography Services

Why it merits diligence:

  • NCC describes a dedicated cryptographic-services practice reviewing primitives and security protocols.
  • Its public Matrix Olm review covered a deniable Double Ratchet, group ratchet, prekey identity binding, replay, fuzzing, findings, remediation, and follow-up review.
  • Its 2024 XMTP report covers a Rust secure-messaging implementation built on MLS.
  • Its public opaque-ke assessment covers a Rust cryptographic protocol implementation; other public work covers encrypted backups and offline key recovery.

First-party evidence:

Questions before selection:

  • Which named practitioners with current PQXDH/Double Ratchet, Rust, storage, and messaging experience would perform the work?
  • Can the team cover the full cross-layer scope rather than only primitive cryptography?
  • Will the engagement include a public initial/final disposition and reserved retest?

Trail of Bits

Why it merits diligence:

  • Trail of Bits describes protocol, implementation, post-quantum, end-to-end encryption, and Rust cryptography assessment capability.
  • Its published methodology explicitly connects threat models, specification/cryptanalysis, implementation review, constant-time and serialization risks, malformed/replay testing, fuzzing, reporting, and fix review.
  • Its public library includes an assessment of the SimpleX secure-messaging design/implementation and a ZeroTier protocol-design assessment.

First-party evidence:

Questions before selection:

  • Which named practitioners would cover secure messaging, Rust, state/persistence, and service abuse bounds?
  • Does the proposed team have direct ML-KEM/PQXDH composition experience?
  • Are the requested complete public finding/disposition and retest artifacts acceptable?

Least Authority

Why it merits diligence:

  • Least Authority describes source-code, specification/white-paper, advanced cryptographic-protocol, and decentralized-system architecture reviews.
  • It publicly states that its team can review Rust and that its normal process includes finding review, verification, and an optional published final report.
  • Its stated privacy and open-source focus is relevant to the project's operator-minimized and public-review goals.

First-party evidence:

Questions before selection:

  • Which named practitioners have non-blockchain secure-messaging, Rust, ratchet, and local-store experience?
  • Can one engagement cover the complete endpoint/storage/transport scope at sufficient depth?
  • Will the initial and final report, every finding disposition, and retest be public?

Cure53

Why it merits diligence:

  • Cure53 describes white-box code, architecture, infrastructure/platform, and cryptographic audits with continuing remediation communication.
  • Its public work includes cryptographic-library review, end-to-end encrypted storage architecture, VPN/protocol work, and Android/iOS cryptography/client assessment.
  • Public reports generally identify work packages, team, effort, findings, severity, and correction state.

First-party evidence:

Questions before selection:

  • Which named practitioners would cover PQXDH/Double Ratchet, Rust, durable state, and protocol/parser review?
  • Can Cure53 allocate a cryptographer and systems reviewers for the full package rather than a narrower client penetration test?
  • Will the report preserve every finding and retest disposition under the proposed public-disclosure terms?

Selection diligence still required

Before any contact or commitment, record:

  1. founder authorization to issue the RFP;
  2. the exact package revision and digest;
  3. desired timing and an approved budget range;
  4. candidate-specific conflict and relationship checks;
  5. named practitioner CVs and actual allocation;
  6. full-scope coverage and explicit exclusions;
  7. source/data handling and deletion terms;
  8. ownership and publication rights for report and test artifacts;
  9. coordinated-disclosure and retest terms; and
  10. whether grant or public-interest funding changes independence, publication, scheduling, or credit.

A declined, unavailable, unaffordable, conflicted, or narrow-scope candidate stays a research record; it is not evidence that review occurred.