Audit status
Witness is pre-1.0 and has not received an external security, cryptographic, or protocol audit. Its release artifacts, configuration examples, signing paths, gateway, witness node, SDK, federation, Freebird integration, and external-anchor paths should be treated as unaudited.
The independent witness-auditor can verify an RFC 9162 signed-tree-head chain
and persist observations, but running that component is not an external audit
of Witness and does not make a gateway Byzantine-fault-tolerant.
Current known gaps
- external cryptographic and protocol audit;
- CI gates for formatting, clippy, tests, and release builds;
- signed release artifacts and image provenance;
- public API schemas and versioned test vectors;
- end-to-end tests against current Freebird V4 and V5 verifier flows; and
- clearer operator guidance for federation token rotation.
Operators should pin a reviewed commit or release, review changes before upgrading, preserve backups, and validate attestations independently. A clean build or passing test suite would not by itself constitute a security audit.