status

current state of 1seal

honest status. no vaporware.

Public: minimal DSSE/JCS verifier.
Not public: semantic/accountable LMV verifier, detection algorithms, production invariant engine.

what's public

what's not public

  • semantic/accountable LMV verifier — in private development, not ready for public use
  • detection algorithms and production invariant engine — implementation details, private/pre-release
  • timelines or roadmap — no promises that can't be kept
  • customer or partner names — confidential unless they choose to share
  • unpublished security research — coordinated vulnerability disclosure

design partner program

what it is: early access for organizations willing to provide feedback and help shape the product.

what you get:

  • early access to implementation
  • direct feedback channel
  • input on protocol evolution

what's needed:

  • real-world deployment context
  • feedback on false positives and edge cases
  • patience with rough edges

intake: design partner intake is limited and not broadly open. external review for v0.3.x takes priority before wider access.

timeline, acceptance, or product availability can't be guaranteed.

recent updates

  • 2026-02-02: GHSA-gx3x-vq4p-mhhv published (cert-manager)
  • 2026-02-01: website published with thesis, protocols, and published advisories
  • 2026-01-29: CVE-2026-24846, CVE-2026-24845 published (malcontent)
  • 2026-01-22: CVE-2026-24137, CVE-2026-24117, CVE-2026-23831 published (sigstore)

see /research for the complete advisory list.

contact