Trust

Trust, in plain terms

Before you buy, you should know what is proven, what is still early, and what we will never do. Here it is, without the fine print.

The short version

What you can rely on

We contract for the outcome and answer for it. “Done” is written down before work starts. Every claim here links to something you can check — or is labelled as not yet proven.

What is still early

11 of our 20 open-source projects are rated “Documented” — public, but not yet independently verified. None has a published third-party audit yet. We test anything on your workload before recommending it.

What we never do

Hold your funds or keys, trade for you, promote tokens, promise returns, or pass off our own review as an independent audit.

Ratings

How to read a maturity rating

Four steps. A project moves up only when there is something to show for it — a page saying “supports X” is the first step, not the last.

  1. Step 1

    Documented

    The design and code are public, but nobody outside the team has verified the claims yet.

    For you: Fine for evaluation and prototypes. Test it yourself before relying on it.

    11 projects today

  2. Step 2

    Publicly tested

    There is a public test suite or a published package that anyone can run and check.

    For you: You can verify the basics independently. Still needs testing on your workload — and an independent audit before it holds funds.

    9 projects today

  3. Step 3

    Field-proven

    It has run in a realistic environment, such as a testnet or production-like setup, with recorded results.

    For you: Reasonable to pilot with real traffic, within the documented limits.

    0 projects today

  4. Step 4

    Customer-accepted

    A paying customer accepted it against written acceptance criteria.

    For you: It has passed someone else’s definition of “done” in production.

    0 projects today

Register

Every project, rated

Where you can get it, whether it has been audited, and what to know before you use it. Being listed here does not make a project right for your production system — that is decided on your workload.

BC

blockchain-compression

Rust library

Publicly tested Maturity 2 of 4
Get it
crates.io
Audit
Not applicable (library)
Know before you use it
  • Headline ratios apply to archival Solana data with the MaxCompression preset; measure on your data
CR

commit-reveal

Crypto / Python library

Publicly tested Maturity 2 of 4
Get it
PyPI
Audit
No third-party audit report published
Know before you use it
  • Pure-Python arithmetic is not guaranteed constant-time; review its published threat model before use
DG

dgbit

Trading framework

Publicly tested Maturity 2 of 4
Get it
PyPI (pip install dgbit), Docker image; Bybit testnet supported
Audit
Not applicable (client software)
Know before you use it
  • Bybit-specific by design
  • Backtests are not a forecast of live performance
NK

nklave

Validator security

Publicly tested Maturity 2 of 4
Get it
Source; Web3Signer-compatible API
Audit
No third-party audit report published
Know before you use it
  • Enforces EIP-3076 rules; it does not prevent every class of staking penalty
  • Migration of existing protection history must be rehearsed per setup
PB

PolyBot

Trading bot

Publicly tested Maturity 2 of 4
Get it
Source; paper trading by default
Audit
Not applicable (client software)
Know before you use it
  • Software only; strategy performance is not promised
  • Venue access subject to each venue’s terms and jurisdiction
SC

SolScript

Compiler

Publicly tested Maturity 2 of 4
Get it
Source; compiles to Rust/Anchor you can review
Audit
No third-party audit report published
Know before you use it
  • Not every Solidity pattern maps cleanly to Solana accounts; some code needs redesign
  • Generated programs still need their own audit
SX

StxScript

Compiler

Publicly tested Maturity 2 of 4
Get it
Source + CLI (build, check, test)
Audit
No third-party audit report published
Know before you use it
  • Generated Clarity still needs review; the transpiler is not a substitute for an audit
TE

Tesseract

Cross-chain / DeFi

Publicly tested Maturity 2 of 4
Get it
Source + public test suite (not all scenarios pass yet); deployable to EVM testnets
Audit
No third-party audit report published
Know before you use it
  • Coordination performance is not the full settlement model; review failure handling per route
  • Mainnet use requires an independent audit
ZE

Zig-EVM

EVM / Runtime

Publicly tested Maturity 2 of 4
Get it
Source + test suite; FFI bindings for Python, Rust, JS, C
Audit
No third-party audit report published
Know before you use it
  • Opcode coverage is partial relative to the latest hard fork; check compatibility for your workload
  • Parallel speed-ups depend on conflict rates
DM

DataMgmt Node

Enterprise data

Documented Maturity 1 of 4
Get it
Source on GitHub
Audit
No third-party audit report published
Know before you use it
  • Compliance claims depend on your deployment and jurisdiction; not a certified system
DF

DFPN

Solana / DePIN

Documented Maturity 1 of 4
Get it
Source on GitHub
Audit
No third-party audit report published
Know before you use it
  • Detection accuracy depends on the operator models; no published accuracy benchmark
  • Token economics not exercised on mainnet
EV

EVMORE

PoW token / ERC-20

Documented Maturity 1 of 4
Get it
Contracts and miner on GitHub
Audit
No third-party audit report published
Know before you use it
  • A token project; Cryptuon does not promote or sell it as an investment
ME

Mentat

Solana / Prediction markets

Documented Maturity 1 of 4
Get it
Source on GitHub
Audit
No third-party audit report published
Know before you use it
  • Operating real-money prediction markets is regulated in many jurisdictions
  • zkTLS resolution depends on supported data sources
MM

Moby Market

DeFi / Institutional

Documented Maturity 1 of 4
Get it
Source on GitHub
Audit
No third-party audit report published
Know before you use it
  • Not deployed for institutional flow; requires audit and integration testing
  • Cryptuon does not trade or take custody
NJ

Njord

Solana / Payments

Documented Maturity 1 of 4
Get it
Solana devnet program; mainnet pending
Audit
Audit pending before mainnet
Know before you use it
  • Not for customer funds until audited and on mainnet
  • Pay-per-action API and x402 adapter are roadmap items
SA

Sarpoy

Solana / Game

Documented Maturity 1 of 4
Get it
Source on GitHub
Audit
No third-party audit report published
Know before you use it
  • Real-money prize pools require jurisdiction-specific legal review
LM

SolanaLM

Solana / AI

Documented Maturity 1 of 4
Get it
Source on GitHub
Audit
No third-party audit report published
Know before you use it
  • No production inference network; evaluate against managed providers
  • Federated-learning path is experimental
SV

SolanaVault

Solana / Storage

Documented Maturity 1 of 4
Get it
Source on GitHub
Audit
No third-party audit report published
Know before you use it
  • Compression ratios are workload-dependent; verify on your data
  • P2P storage network not live
SS

StreamSync

Solana / Indexing

Documented Maturity 1 of 4
Get it
Source on GitHub
Audit
No third-party audit report published
Know before you use it
  • Query-latency targets are design goals, not published field benchmarks
  • Operator network not live
SB

Switchboard

Cross-chain

Documented Maturity 1 of 4
Get it
Source on GitHub
Audit
No third-party audit report published
Know before you use it
  • Chain coverage must be verified per chain pair
  • Latency figures are design targets
Reporting

When we quote a number, or talk about security

The same standard applies on this site, in proposals, and in delivery reports.

Every benchmark tells you

  • Which version was tested
  • The workload and data, or how to recreate them
  • The hardware, region, and network conditions
  • Percentiles (p50 / p95 / p99), not just an average
  • How much contention there was, if parallelism is involved
  • A script you can run to reproduce it

Security claims stay scoped

  • We describe the threat model and its scope — never “unhackable” or “impossible to slash”.
  • We name the standard we implement (for example EIP-3076) and say what it does not cover.
  • For cross-chain work, we separate how fast things coordinate from what happens when a step fails.
  • An engineering review is not an audit. When you need an audit, a third party does it.
Boundaries

We deliver and operate defined technology

We do not promise investment returns.

We do

  • Contract for the outcome as principal contractor, and answer for everyone we bring in
  • Write acceptance criteria down before any build starts
  • Recommend another provider or project when it fits better
  • Bring in an independent auditor when one is needed, priced separately
  • Publish limitations next to every claim, including on this page

We don’t

  • Take custody of funds or hold keys
  • Trade on your behalf or give investment advice
  • Promote tokens or promise returns
  • Present an engineering review as an independent audit
  • Ask for private keys, seed phrases, or credentials

Full commercial terms are on the engagements & pricing page.

What happens to what you send us

  • Never send private keys, seed phrases, or signing credentials. No engagement needs them — not in the brief, not by email, not ever.
  • To start, a redacted bill, an architecture summary, or a public repository link is enough.
  • Sensitive repositories, logs, and financial records are exchanged later, through a process agreed with you, under NDA where needed.
  • We never use your information in public content without written permission.
FAQ

Questions about trust

Has any Cryptuon project had a third-party security audit?

Not yet. No project in the register has a published third-party audit report. That is why generated or integrated code that will hold funds goes through an independent audit as part of the engagement, priced separately.

Can I use a “Documented” project in production?

Not without your own testing. “Documented” means the design and code are public but nobody outside the team has verified the claims. In a paid engagement we test any component on your workload before recommending it — and often recommend an alternative.

Why publish your weaknesses?

Because buyers find them anyway, usually at the worst moment. Stating maturity up front makes our recommendations easier to trust and keeps us honest about what we sell.

Who decides when a rating goes up?

A rating moves up only when there is an artefact to show for it: a public test suite, recorded results from a realistic environment, or a customer’s written acceptance (cited only with permission).

What happens if something you delivered fails?

Cryptuon is the principal contractor, so the responsibility is ours, as defined in the written scope. If we are only making an introduction to another supplier, that is stated in writing before any work starts.

Ask us to prove it

If a claim matters to your decision, ask for the evidence. The assessment is where we test it on your workload.