What the assurance pack contains
| Layer | Contents | Audience |
|---|
| A1 — Security & privacy contract | Platform security PRD · client data privacy PRD · auth & key management | Security · legal |
| A2 — Threat & crypto normative | ADRs on asset owner domain · off-client boundaries · transfer-link cryptography · circuits threat catalog | Auditors · crypto reviewers |
| A3 — Control map | Engineering controls mapped to threats | SOC-style reviewers |
| A4 — Claims register | Allowed vs forbidden market language | Sales · partners · docs |
Full index: assurance/README.md.
Security posture (summary)
| Property | Tenebrae stance |
|---|
| Key custody | Your wallet signs — bring-your-own-wallet |
| Private proving | Client-side ZK Proofs (Noir) — not server-side decrypt |
| Off-client services | Modeled untrusted — no server decrypt of transfer target metadata |
| On-chain visibility | Deposit and withdraw amounts are public — private settlement between |
| Compliance | Two-layer model — institution upstream · Protocol at submit (architecture, not license) |
Detail: privacy model · compliance two-layer.
Open risks (disclosed)
We document known gaps — we do not hide them behind marketing language:
| Risk | Status |
|---|
| Compliance policy witness binding (T10) | Open P0 — do not claim “provably compliant” from circuits alone |
| Mainnet production | Not shipped — testnet train |
| Third-party analytics partnerships | Roadmap / GTM-gated until MAP + counsel |
Source: circuits threat model · Stack.
Requesting the full pack
| Channel | Use |
|---|
| Enterprise diligence | Contact team via tenebrae.xyz — reference assurance pack A1–A4 |
| Partner pilots | demo and testnet gates (partner channel — contact BD) (partner audience) |
| Integrator self-serve | Start with quickstart — full pack on request |
Related public pages
| Page | Why |
|---|
| Stack | Product ceiling for testnet |
| Architecture | System boundaries |
| Stack | Offer layers — wallet · surfaces · Protocol · hosts |