Last updated: 2026-06-16
This is the canonical documentation root for pqcrypto. Use doc/ links for
project documentation; the older documentation directory has been retired.
| Area | Current state |
|---|---|
| Package version | 0.4.0 |
| Runtime dependencies | None. Partial FIPS 202 SHA3/SHAKE is vendored in lib/src/common/keccak.dart. |
| ML-KEM | Supported for ML-KEM-512, ML-KEM-768, and ML-KEM-1024 with checked-in KAT and interop evidence. |
| ML-DSA | FIPS 204-aligned for ML-DSA-44/65/87; byte-exact on the checked-in KAT corpus (raw/pure/hashed × det/hedged). Not CMVP/FIPS 140 validated. |
| FIPS 202 / SP 800-185 | FIPS 202 is partial today (SHA3-224/256/384/512, SHAKE128/256, incremental SHAKE XOFs). SP 800-185 targets 0.6.0, with 0.7.0 spillover if needed. |
| SLH-DSA | FIPS 205-aligned. All 12 sets (SHAKE + SHA-2) ship in 0.4.0; 1,248/1,248 ACVP cases pass. Not CMVP/FIPS 140 validated. |
| Native interop | OpenSSL and liboqs tool suites cover ML-KEM, ML-DSA, and SLH-DSA outside the runtime package boundary. |
| Certification claim boundary | Implementation/KAT evidence, not CMVP/FIPS 140 module validation. See FIPS_140_BOUNDARY.md. |
| Need | Start here | Then read |
|---|---|---|
| Current assurance boundary | MLKEM_TESTING.md | FIPS_COMPLIANCE.md |
| FIPS 202 / SP 800-185 work | FIPS202_SP800185_RELEASE_GUIDE.md | PROGRESS_TRACKER.md |
| ML-DSA release work | MLDSA_FIPS204_RELEASE_GUIDE.md | PROGRESS_TRACKER.md |
| SLH-DSA release work | SLHDSA_FIPS205_RELEASE_GUIDE.md | ROADMAP.md |
| Native interoperability | OPENSSL_INTEROP.md | ENGINEERING_GUIDE.md |
| Architecture and code layout | ARCHITECTURE.md | PERFORMANCE.md |
| Security review | SECURITY_AUDIT.md | BUGS.md |
| Implementation planning | PROGRESS_TRACKER.md | ROADMAP.md |
| Multi-agent PQC workflows | UNIVERSAL_MULTI_AGENT_PQC_FRAMEWORK.md | SERVERPOD_FLUTTER_GUIDE.md |
| Future algorithms | ALGORITHM_EXPANSION_GUIDE.md | IMPROVEMENTS.md |
| Serverpod/Flutter use | SERVERPOD_FLUTTER_GUIDE.md | OPENSSL_INTEROP.md |
| Project ideas by domain | cookbook/README.md | PROJECT_CATALOG.md |
| Public website and AI discovery | Website | ../llms.txt |
| Document | Purpose |
|---|---|
| MLKEM_TESTING.md | Checked-in ML-KEM KAT corpus, hashes, coverage, release gates, and claim boundary. |
| FIPS202_SP800185_RELEASE_GUIDE.md | A-Z compliance and release plan for full FIPS 202 plus SP 800-185 support. |
| MLDSA_FIPS204_RELEASE_GUIDE.md | FIPS 204 implementation, validation, hardening, and release guide for ML-DSA. |
| SLHDSA_FIPS205_RELEASE_GUIDE.md | FIPS 205 implementation and release plan for all 12 SLH-DSA parameter sets. |
| OPENSSL_INTEROP.md | OpenSSL and liboqs native-provider interop matrix, harness commands, and boundaries. |
| ARCHITECTURE.md | Current module layout, API surface, data flow, and package boundaries. |
| FIPS_COMPLIANCE.md | Evidence-scoped FIPS 203/204/202/180-4/SP 800-185 status. |
| FIPS_140_BOUNDARY.md | Why we claim algorithm conformance but not CMVP/FIPS 140 module validation. |
| SECURITY_AUDIT.md | Current security posture, resolved issues, open risks, and audit priorities. |
| BUGS.md | Known bugs and regressions, especially ML-DSA blockers. |
| IMPROVEMENTS.md | Prioritized engineering improvements with current status. |
| PROGRESS_TRACKER.md | Cross-document tracker for open work and validation gates. |
| ROADMAP.md | Release direction after 0.4.0. |
| PERFORMANCE.md | Performance baseline, optimization ideas, and benchmark guidance. |
| ENGINEERING_GUIDE.md | Contributor setup, test commands, coding conventions, and security practices. |
| ALGORITHM_EXPANSION_GUIDE.md | Guidance for SLH-DSA, HQC, FN-DSA, and future PQC work. |
| SERVERPOD_FLUTTER_GUIDE.md | Example ML-KEM + ML-DSA handshake pattern for Serverpod and Flutter. |
| UNIVERSAL_MULTI_AGENT_PQC_FRAMEWORK.md | Project-level Codex/Claude/Antigravity agent framework for PQC integration planning. |
| cookbook/README.md | Builder-facing project-idea catalog and reusable recipes across domains. |
| ../tool/visibility/README.md | Generated GitHub Pages, AI discovery files, and coding-agent rule surfaces. |
The current local verification snapshot used for this documentation pass:
dart analyzeexits 0.- The focused VM gates are green, including the ML-KEM KAT runner (1000 vectors each at 512/768/1024) and the ML-DSA KAT runner (18 files; 300 byte-exact key generations and 1800 byte-exact signatures that all verify, across ML-DSA-44/65/87 × {det, hedged} × {raw, pure, hashed}).
- The SLH-DSA gate is byte-exact on 1,248 ACVP cases (120 keyGen, 624 sigGen,
504 sigVer) across all 12 sets, plus component/API/negative regressions.
Optional verify-after-sign has focused coverage. The full
s-set runner is intentionally expensive. - The portable SLH-DSA benchmark tool supports all 12 sets. The published single-sample table currently records the SHAKE sets under VM JIT, compiled JavaScript, and compiled Wasm. Results and exact commands are in PERFORMANCE.md.
- The complete portable package suite is green under both
dart2jsanddart2wasm(217/217 each). The VM suite is green as a decomposed matrix: 256/256 non-SLH-KAT tests plus all six per-parameter SLH-DSA ACVP gates. - Package publication dry-run validates the approximately 190 KB archive; its only warning is the expected uncommitted feature-worktree state.
dart format --set-exit-if-changed .passes; the 12 files touched by this SLH-DSA milestone pass the configured Markdown lint. Repository-wide Markdown cleanup remains separate from the SLH-DSA evidence gate.- The native interop workflow is maintained separately in
.github/workflows/interop.yml,tool/openssl_interop/, andtool/liboqs_interop/.
Do not upgrade readiness wording unless a fresh verification run supports it.
The KAT corpora are described in test/data/MLKEM/README.md and
test/data/MLDSA/README.md.