Skip to content

Audit status

Witness is pre-1.0 and has not received an external security, cryptographic, or protocol audit. Its release artifacts, configuration examples, signing paths, gateway, witness node, SDK, federation, Freebird integration, and external-anchor paths should be treated as unaudited.

The independent witness-auditor can verify an RFC 9162 signed-tree-head chain and persist observations, but running that component is not an external audit of Witness and does not make a gateway Byzantine-fault-tolerant.

Current known gaps

  • external cryptographic and protocol audit;
  • CI gates for formatting, clippy, tests, and release builds;
  • signed release artifacts and image provenance;
  • public API schemas and versioned test vectors;
  • end-to-end tests against current Freebird V4 and V5 verifier flows; and
  • clearer operator guidance for federation token rotation.

Operators should pin a reviewed commit or release, review changes before upgrading, preserve backups, and validate attestations independently. A clean build or passing test suite would not by itself constitute a security audit.