Value/Effort: high / M (mostly organizational). docs/threat-model.md was written "for external-audit readiness" — cash that cheque. A solo-maintained crypto library earns institutional trust through third-party review: scope the audit to the fail-closed pipeline properties, the three proof families, and the hand-rolled parsers that face attacker-controlled bytes (CBOR, JCS, multibase, bitstring, the TSL XML path).
Scope: prepare the audit pack (threat model, invariants, fuzz corpora, the adversarial-review history); pursue EU open-source funding routes (NGI/NLnet, Sovereign Tech Fund — openvc's EUDI relevance is the pitch); publish findings + fixes. Pairs with the W3C/OIDF conformance evidence from the medium-term milestone as the credibility story.
Value/Effort: high / M (mostly organizational).
docs/threat-model.mdwas written "for external-audit readiness" — cash that cheque. A solo-maintained crypto library earns institutional trust through third-party review: scope the audit to the fail-closed pipeline properties, the three proof families, and the hand-rolled parsers that face attacker-controlled bytes (CBOR, JCS, multibase, bitstring, the TSL XML path).Scope: prepare the audit pack (threat model, invariants, fuzz corpora, the adversarial-review history); pursue EU open-source funding routes (NGI/NLnet, Sovereign Tech Fund — openvc's EUDI relevance is the pitch); publish findings + fixes. Pairs with the W3C/OIDF conformance evidence from the medium-term milestone as the credibility story.