Protocol specification, core encryption modules, group cryptography, architecture overview, and MIT license.
Community-supported security
Open security work needs independent support.
City of Hats publishes the architecture, protocol specification, and production encryption modules behind its secure communication platform.
Your contribution helps us maintain that work, expand public documentation, improve security testing, and prepare for independent review.
Inspect the work
Security claims should come with evidence.
The cryptographic layer is available for inspection, criticism, and improvement. The repository documents both its design and its limits.
Protocol architecture
Key exchange flows, Double Ratchet parameters, group sender keys, wire formats, and cryptographic primitives.
Read PROTOCOL.md Production sourceCore encryption
Hybrid key exchange, message encryption, ratchets, metadata padding, safety numbers, and local key protection.
Review crypto.ts Production sourceGroup encryption
Sender-key distribution, HMAC chain ratchet, authenticated encryption, and sender signature verification.
Review groupCrypto.tsCurrent funding focus
Preparing for independent security review.
The implementation and protocol specification are public. The next objective is structured external review, broader test coverage, remediation of findings, and clearer reproducibility for independent researchers.
- Independent cryptographic review
- Security test suites
- Protocol documentation
- Vulnerability research and remediation
Designed to address
What the open work covers
- End-to-end encryption by default
- Forward secrecy and per-message key evolution
- Hybrid X25519 + ML-KEM-768 key exchange
- Identity abstraction through Hat IDs
- Metadata-conscious message formats
Honest boundaries
What we do not yet claim
- Protection from compromised endpoints
- Complete resistance to global traffic analysis
- Formal mathematical verification
- A completed independent security audit
- Open sourcing of proprietary platform systems
Deliberate scope
Open where scrutiny matters. Clear about what remains closed.
Backend infrastructure, product interfaces, and proprietary intelligence systems.
Before you contribute
Clear terms. No fine-print surprises.
Is City of Hats a charity?+
No. City of Hats Inc. is a for-profit Canadian company. Contributions are voluntary and are not charitable donations.
Is my contribution tax deductible?+
No. City of Hats Inc. is not a registered charity or qualified donee and cannot issue an official donation receipt or promise a charitable tax benefit.
What does my contribution purchase?+
It does not purchase equity, ownership, a financial return, product access, or preferential treatment. It helps support City of Hats work, including the open security components described on this page.
Is this a recurring payment?+
No. Every contribution made through this page is a single, one-time payment. There is no subscription or automatic renewal.
Who processes the payment?+
Stripe processes the payment for City of Hats Inc. City of Hats does not receive your complete card number.
Can I contribute without a City of Hats account?+
Yes. A Hat ID or City of Hats account is not required. Stripe will request the information needed to process your payment and provide a receipt.
Build in the open
Help security withstand public scrutiny.
One contribution. No subscription. No product tier. Just support for work the community can inspect.