Skip to content

Audit status

HyperToken has not received an external security audit. Tests cover selected core, sync, projection, persistence, and Cuttle crypto/hardening behavior, but passing tests are not a security certification.

Security-sensitive areas include network/E2EEncryption.ts, key identity and projection policy, hidden-information sanitization, authoritative handlers, relay limits, persistence, and document growth. The E2E module is intentionally not a generic wired-in network feature. Review the source and threat model before relying on any of these controls.

Report deployment-specific risks with a reproducible case and do not include secrets in issues or patches. Security claims should name the actor, asset, boundary, and residual risk they address.