ppad detects and eliminates the most subtle timing vulnerabilities in critical production infrastructure.
We like to know our stuff isn't vulnerable. Read on to learn how we can help you know your stuff isn't vulnerable either.
(scroll ↓)
01 / 04
We audit cryptographic code and executables for timing leaks: statically, at every instruction the machine actually executes, and dynamically, down to the hardware it executes on, using state-of-the-art analysis tools that we build and operate ourselves.
See exactly what your timing profile is, across multiple architectures and when compiled or optimized via multiple backends, at both the raw assembly and microarchitectural levels.
02 / 04
We construct first-principles threat, adversary, and security models for cryptographic systems, identifying e.g. what an attacker can reach, what an attack would cost, and where a design or implementation may be unsound.
03 / 04
We remediate defects that audits find, or rapidly build things out, from spec or otherwise, in differing languages or timing-hostile runtimes, with second-to-none quality and pace.
Our track record includes examples like blazing-fast constant-time Montgomery arithmetic primitives, fastest-in-class SHA2 hash functions, and constant-time RFC8439 authenticated encryption; property, cross-library, and Wycheproof tested.
The proof of the pudding, as they say, is in the eating.
04 / 04
We ensure that your timing profile remains clean in the face of code or toolchain updates, upgrades, or migrations: quickly, effortlessly, and on demand.
Get in touch to discuss your project and its needs. We'll get an idea of the work likely to be involved and will be happy to provide you with a quote.