Discuss a
cryptography review.

We review protocols, threat models, formal models, cryptographic libraries, and implementations. Book a call to discuss the system, scope, and schedule.

$ symbolic --engagement SCOPE FIRST
[01]scopesystem, materials, threat model
[02]design_reviewprotocol, primitives, key management
[03]implementation_reviewcode, state, side channels
[04]draft_reportfindings and remediation
[05]▶ final_reportdiscussion · retest if needed
scope, schedule, and fee agreed in writing before work begins

Review scope.

Led by a senior cryptographer
01 / Architecture

Protocol architecture review

Key exchange, authentication, key schedules, session state, and failure handling.

02 / Primitives

Cryptographic design audit

Primitive selection, parameters, composition, security goals, and trust assumptions.

03 / Code

Implementation review

Cryptographic code and protocol state across Go, Rust, TypeScript, Swift, Java, .NET, C, and Solidity.

04 / Post-quantum

Post-quantum migration review

KEM and signature choices, hybrid constructions, libraries, interoperability, and rollout plans.

05 / Verification

Formal verification

Protocol models in Verifpal, ProVerif, or Tamarin, selected according to the question being analyzed.

Selected clients

Client comments.

Quoted verbatim
We have been working together with Symbolic Software as auditors for cryptographic software. They are reliable, precise, honest, thorough and think outside the box.
— Mario Heiderich, Director, Cure53.
Symbolic Software is run by an accomplished researcher, with significant contributions in the area of applied cryptography. They're the right team for projects that require rigorous design and engineering.
— Jean-Philippe Aumasson, Chief Security Officer, Taurus Group.
Symbolic Software are a delight to work with. Their reports are incredibly thorough and they maintain an excellent line of communication. We are grateful we got the opportunity to collaborate with someone of such high calibre.
— Vishnu Mohandas, Founder, Ente.io.

Practical details.

Reports · schedule · fees
Reports The final report records the scope, findings, severity, evidence, and remediation. Public examples include 1Password B5, Thunderbird Enigmail, dWallet 2PC-MPC, and Telegram MTProto.
Schedule The schedule depends on the size of the target, the material available, and the review method. Dates and deliverables are agreed during scoping.
Fees Each engagement is quoted individually. The written proposal sets out the target, deliverables, schedule, and fee.
First contact Book a call or email a short description of the system, the material available for review, and any deadline.

Contact us.

Book a call or send a short description of what you would like reviewed.