Design-level security
for the AI era.
An applied cryptography practice. We audit at the layer above implementation — protocol architecture, primitive selection, threat modeling, formal verification — where AI bug-finders cannot help and humans still must.
Security has to start at the design level.
Protocol architecture, primitive selection, threat modeling, formal verification — everything downstream is a consequence of those decisions. More than 250 engagements since 2017 have started from that premise.
Our practice areas
Audits
Protocol architecture, cryptographic review, threat modeling, formal verification.
Tools
Verifpal, Crucible, hpke-ng, Kyber-K2SO, PQ Migration Playbook.
Teaching
Applied Cryptography. Free for 50 Lebanese students this summer.
Lab
Post-Quantum Migration Playbook, advisories, papers, the audit floor.
From the audit floor
Recurring bug classes from our audit work, anonymized.
Constant-time leak in ECC point doubling
AEAD nonce reuse under concurrent state
Incorrect rounding in lattice solver
Public key not validated to correct subgroup
Unchecked length field in TLV parser
Crucible.
Bug classes,
encoded as tests.
129 tests across 12 categories, each tagged with the bug class, the FIPS spec section, and the audit it came from. Wire any ML-KEM or ML-DSA implementation up over stdin/stdout. Pass or fail in seconds.
From the lab
Verifpal 0.70.0: Post-Quantum Key Exchange, and an Attacker That Works Backwards
Verifpal 0.70.0 removes Diffie-Hellman equations from the modelling language, adds a generic KEM for post-quantum and hybrid key exchange, rebuilds the active attacker around a search that works backwards from each query, and narrates every attack it finds as numbered causal steps.
Read →Meet the Symbolic Software Summer 2026 Team
Five people joined us this summer: two research interns formalizing zkVM soundness bounds in Lean, and three teaching assistants running the Applied Cryptography course. Here they are, in their own words.
Read →Why I Teach Cryptography in Lebanon
Cedarcrypt's first edition has concluded. On what a year of teaching cryptography in and for Lebanon has meant, why the conference met in Cyprus rather than Beirut, and the decades of work ahead.
Read →