Audit status¶
HyperToken has not received an external security audit. Tests cover selected core, sync, projection, persistence, and Cuttle crypto/hardening behavior, but passing tests are not a security certification.
Security-sensitive areas include network/E2EEncryption.ts, key identity and
projection policy, hidden-information sanitization, authoritative handlers,
relay limits, persistence, and document growth. The E2E module is intentionally
not a generic wired-in network feature. Review the source and threat model
before relying on any of these controls.
Report deployment-specific risks with a reproducible case and do not include secrets in issues or patches. Security claims should name the actor, asset, boundary, and residual risk they address.