Sovereign communications · Mindhawk vertical

ZeroHawk

Sealed messages with provable expiry and a tamper-evident record — on a server that holds no private key and therefore cannot read what it stores.

Working · adversarially tested · not certified

Named for what it does

Zeroize is the standard term in defence cryptography for destroying key material.

Expiry here does not delete your data. It destroys the key that reads it, and deliberately keeps the ciphertext — so the guarantee can be demonstrated rather than asserted. The bytes are still on the server, and nobody can read them.

Deleting data is a policy promise: it fails the moment one server quietly keeps a copy, and in this threat model that server is the adversary. Destroying the key is a mathematical promise — it holds even against the machine that cheated.

What it guarantees — and what it does not

Every guarantee is paired with its limit. The common failure in secure communications is not weak cryptography but a claim that outruns it.

Independently checkable

Nothing here asks to be taken on trust.

The implementation ships with suites an evaluator runs themselves: the cryptographic guarantees, interoperability between two independent implementations, hardware custody against real silicon, and an adversary holding root on the node — which reports its own outstanding finding rather than only its successes.

ZeroHawk is not certified. It has not completed FIPS 140-3 or Common Criteria evaluation, and no claim of certification will be made before a certificate exists.

Read the technical whitepaper