HELIXAUTHOBJECT-BOUND TRUST← Return home
SECURITY STATEMENT

Security by separated signals

HelixAuth treats identity, cryptographic integrity, custody, registry state, and physical continuity as separate controls.

Last updated August 10, 2026
01

Access

External experiences use invitation-bound, domain-bound passkeys. The founders workspace has a separate identity and authorization boundary. Server-side checks protect every privileged mutation.

02

Cryptographic controls

  • Exact SHA3-512 content and metadata hashing.
  • Policy-controlled ML-DSA and SLH-DSA signatures, with experimental algorithms clearly labeled.
  • AES-256-GCM key envelopes bound to owner, algorithm, purpose, and wrap version.
  • Portable .hlx packages and independently inspectable verification signals.
03

Records and recovery

Custody, revocation, and transparency events are append-oriented and linked to versioned records. Issuance jobs are resumable so partial work is not mistaken for a completed credential.

04

Current boundaries

Application-managed encrypted key custody is not represented as HSM custody. Physical carrier resistance and object matching remain validation tracks until manufactured test evidence supports stronger claims.

05

Responsible reporting

If you identify a security issue, do not access other users’ data or disrupt the service. Report it privately to the Helix project contact or administrator who issued your access, including reproducible steps and impact.