The φCrypt suite, computed live in your browser via WebAssembly: no server, no pre-baked numbers. One design decision organizes everything here. The signature, the proof system, and the recursion share a single prime field, so signature verification runs natively inside the circuits that prove statements about it; the first tab verifies that, live. Around it sit two independent hardness assumptions: hash-based (φHash: φSign, φCipher) and lattice-based (Module-LWE/SIS: φKEM, φDSA). The Security model tab carries the dependency map, the measured costs, and every caveat.

Pre-production. External cryptanalysis review is in progress and has not yet reported. Until it does, treat every number on this page as this team's own estimate, not an audited guarantee.
Loading WebAssembly module…