Xattestation

Security

A record is only worth something if it can still be trusted decades from now. Security is designed in from the start, not added later.

Built to be checked decades from now

Post-quantum signatures

Every record is signed to NIST’s post-quantum standard, FIPS 204, and the system is built to move to stronger methods as standards evolve.

Open source underneath

Built on Linux and Python, with open-source post-quantum cryptography. No proprietary cryptography: the cryptographic components are open and can be independently audited.

Keys in secure hardware

Signing keys are designed to live inside tamper-resistant hardware, and no single key, held by any single person, can produce a record alone.

Corrected, never erased

A mistake is never quietly removed. It is corrected by a new record that refers to the old one, so the history stays whole.

This website

No cookies, no scripts, no analytics and nothing loaded from other websites. Every page is served over HTTPS with strict security headers. How we handle personal data is set out in our privacy notice.

Report a security issue

If you believe you have found a vulnerability in anything Xattestation runs, write to founder@xattestation.com. Please give us reasonable time to fix it before you disclose it. Our contact details for security reports are also published at /.well-known/security.txt.

Write to the founder

founder@xattestation.com

Rizwan Khan, Founder
Ujjain, Madhya Pradesh, India