Claims, boundaries, architecture, limitations, and verification dates.
Procurement Center
A buyer-ready index of City of Hats security claims, evidence status, architecture references, evaluation questions, and downloadable review data. Unknowns and unavailable evidence remain visible.
Version 1.0 · Reviewed 10 August 2026Current evidence snapshot
A published reporting route for security researchers.
Algorithm and data-boundary claims are documented as first-party technical material.
Do not treat internal review or documentation as an independent audit.
A buyer should request current private evidence if required for procurement.
No customer names, outcomes, or metrics are invented for this page.
Certification and legal applicability require scoped, current evidence.
Questions a serious buyer should ask
Use these questions in a vendor review. The downloadable CSV includes an evidence-status field so teams can record verified answers instead of relying on sales language.
Where does plaintext exist, and which components can access message keys?
City of Hats documents plaintext at authorized endpoints and describes the delivery service as handling ciphertext. Buyers should validate this against current implementation evidence.
Are phone numbers, emails, address books, or recovery identities required?
Creating a Hat does not require a phone number or email. Optional workflows and business services may have separate data requirements that must be reviewed.
Which algorithms and protocol versions protect messages and calls?
Current first-party documentation describes X25519 plus ML-KEM-768 hybrid key agreement, Double Ratchet-style key evolution, and AES-256-GCM. Independent verification status must be evaluated separately.
Which routing, timing, abuse-prevention, device, and account records remain outside message encryption?
The Security Evidence Center states boundaries and limitations. Encryption does not eliminate all operational metadata.
What is retained, for how long, and what does deletion actually guarantee?
Retention depends on feature lifecycle and endpoint behavior. Buyers should distinguish server deletion, endpoint deletion, backups, screenshots, and recipient copies.
How are privileged access, deployment duties, and support operations controlled and logged?
Public material does not currently provide a complete independent control assessment. Request current operational evidence where this matters.
Which claims have been independently tested, and what evidence can be shared under NDA?
No independent cryptographic audit or public penetration-test report is currently published. This limitation is explicit.
What happens during service outage, device loss, key loss, or regional blocking?
No secure service guarantees availability. Organizations need fallback communications and recovery procedures that match the no-recovery design.
Which contract, privacy, residency, and regulatory commitments apply to this deployment?
Public pages are not a substitute for a scoped contract, data-processing review, or legal advice.
How are security-relevant changes disclosed and dated?
The public Website Changelog records trust, research, and website changes. Product-release evidence should be requested separately.
Downloadable review materials
These machine-readable files are designed for due diligence and internal review. They do not constitute a certification, warranty, completed customer questionnaire, or legal opinion.
Customer evidence status
No public customer case study is currently included because we will not create customer names, testimonials, adoption figures, or outcomes without documented permission and measurable evidence. This section will list approved case studies when they exist.