Built to be checked decades from now
Post-quantum signatures
Every record is signed to NIST’s post-quantum standard, FIPS 204, and the system is built to move to stronger methods as standards evolve.
Open source underneath
Built on Linux and Python, with open-source post-quantum cryptography. No proprietary cryptography: the cryptographic components are open and can be independently audited.
Keys in secure hardware
Signing keys are designed to live inside tamper-resistant hardware, and no single key, held by any single person, can produce a record alone.
Corrected, never erased
A mistake is never quietly removed. It is corrected by a new record that refers to the old one, so the history stays whole.
This website
No cookies, no scripts, no analytics and nothing loaded from other websites. Every page is served over HTTPS with strict security headers. How we handle personal data is set out in our privacy notice.
Report a security issue
If you believe you have found a vulnerability in anything Xattestation runs, write to founder@xattestation.com. Please give us reasonable time to fix it before you disclose it. Our contact details for security reports are also published at /.well-known/security.txt.