What happens after the first conversation?
We define the target and review method with you. The written proposal sets out the scope, deliverables, schedule, and fee before work begins.
Tell us what you are building and what needs to hold up under attack. We will work with you to define the review, from an early protocol design to a release or post-quantum migration.
300+ engagements. Every engagement is led by a senior cryptographer.
System, materials, and threat model.
Protocol, primitives, and key management.
Code, state, and side channels, where in scope.
Findings and remediation.
Discussion and retesting if needed.
Scope, schedule, and fee agreed in writing before work begins.
Start the conversation
Tell us about the system and the decision you need to make. If the scope is still uncertain, describe the concern you want the review to address.
[email protected]The draft opens in your email app with a few prompts you can edit.
What you are building, who uses it, and what it needs to protect.
The design, code, library, or migration decision you would like us to examine.
What documentation or code is available, and any release date or other deadline.
What you receive
Scope, schedule, and fee agreed in writing before work begins.
Read a sample report (PDF)The system reviewed, attacker capabilities, security goals, and the limits of the analysis.
What can go wrong, the conditions that make it possible, its severity, and the evidence behind the finding.
Recommendations your engineers can work from, discussion of the findings, and retesting where agreed in the scope.
We have been working together with Symbolic Software as auditors for cryptographic software. They are reliable, precise, honest, thorough and think outside the box.
Symbolic Software is run by an accomplished researcher, with significant contributions in the area of applied cryptography. They're the right team for projects that require rigorous design and engineering.
Symbolic Software are a delight to work with. Their reports are incredibly thorough and they maintain an excellent line of communication. We are grateful we got the opportunity to collaborate with someone of such high calibre.
We define the target and review method with you. The written proposal sets out the scope, deliverables, schedule, and fee before work begins.
No. A design review can begin with a protocol specification, architecture, or threat model. Implementation review can be included when code is available and it fits the scope.
Yes. A review can focus on a protocol, cryptographic library, key-management design, or migration decision. The boundaries and relevant dependencies are established during scoping.
Each engagement is quoted individually. Timing and fees depend on the size of the target, the material available, and the review method. Dates and deliverables are agreed during scoping.
Scope, schedule, and fee agreed in writing before work begins.