Uncross your fingers.

ppad detects and eliminates the most subtle timing vulnerabilities in critical production infrastructure.

We like to know our stuff isn't vulnerable. Read on to learn how we can help you know your stuff isn't vulnerable either.

(scroll ↓)

01 / 04

Constant-time auditing

We audit cryptographic code and executables for timing leaks: statically, at every instruction the machine actually executes, and dynamically, down to the hardware it executes on, using state-of-the-art analysis tools that we build and operate ourselves.

See exactly what your timing profile is, across multiple architectures and when compiled or optimized via multiple backends, at both the raw assembly and microarchitectural levels.

you get
self-contained, independently verifiable audits in which every claim is supported by concrete evidence.
for
anyone handling keys, signatures, and other sensitive cryptographic material.

02 / 04

Security analysis

We construct first-principles threat, adversary, and security models for cryptographic systems, identifying e.g. what an attacker can reach, what an attack would cost, and where a design or implementation may be unsound.

you get
a written analysis, in the style of our published work on ppad-hmac-drbg, ppad-sha{256,512}, and ppad-fixed.
for
teams who want to understand or communicate their exact security posture, or who want a substrate upon which to employ formal methods.

03 / 04

Security engineering

We remediate defects that audits find, or rapidly build things out, from spec or otherwise, in differing languages or timing-hostile runtimes, with second-to-none quality and pace.

Our track record includes examples like blazing-fast constant-time Montgomery arithmetic primitives, fastest-in-class SHA2 hash functions, and constant-time RFC8439 authenticated encryption; property, cross-library, and Wycheproof tested.

The proof of the pudding, as they say, is in the eating.

you get
pull requests, patches, or fresh codebases, as needed, along with credible evidence that any crucial invariants are upheld.
for
teams with vulnerabilities to eliminate, or with cryptographic/security infrastructure to build correctly from the start.

04 / 04

Continuous assurance

We ensure that your timing profile remains clean in the face of code or toolchain updates, upgrades, or migrations: quickly, effortlessly, and on demand.

you get
at-will substratum and censor analyses, along with immediate remediation of any discovered defects.
for
teams who want to sleep well at night.

Engagements

Get in touch to discuss your project and its needs. We'll get an idea of the work likely to be involved and will be happy to provide you with a quote.