PUBLIC BUYER BRIEF · VERSION 1.0 · 10 AUGUST 2026

Architecture and evidence brief

This concise brief routes reviewers to the current public evidence for City of Hats. It is first-party material, not a certification, warranty, independent audit, or substitute for a scoped security assessment.

Start with the live evidence: Security Evidence Center. It documents product claims, architecture boundaries, algorithms, limitations, and verification dates.

Documented architecture boundary

Current first-party material describes authorized endpoints as the places where plaintext and message keys are available, while the delivery service handles ciphertext. It describes hybrid X25519 plus ML-KEM-768 key agreement, Double Ratchet-style key evolution, and AES-256-GCM for content protection. Buyers must distinguish a published design claim from independent implementation assurance.

Identity and metadata

A Hat can be created without a phone number or email address. This reduces coupling to an address-book identity; it does not eliminate routing, timing, device, abuse-prevention, recipient, network, or operational metadata.

Current public evidence status

Public Security Evidence CenterAvailableClaims, boundaries, architecture, limitations, and verification dates.
Responsible disclosure and security.txtAvailableA published reporting route for security researchers.
Public cryptographic architecture descriptionAvailableAlgorithm and data-boundary claims are documented as first-party technical material.
Independent cryptographic auditNot publishedDo not treat internal review or documentation as an independent audit.
Public penetration-test reportNot publishedA buyer should request current private evidence if required for procurement.
Public customer case studiesNot publishedNo customer names, outcomes, or metrics are invented for this page.
Formal compliance certificationsNot claimed hereCertification and legal applicability require scoped, current evidence.

Review routes