Security
Secure by construction.
Network 1 roots every key in hardware, finalises every block with quantum-safe signatures and requires the paying account's signature for anything that moves money or changes state.
Security model
Layer by layer.
Post-quantum consensus
Tenzro DAG Consensus signs finality certificates with ML-DSA-65 and keys validator channels with X25519 and ML-KEM-768. No consensus signature relies on a scheme a quantum computer can break.Learn moreHardware-rooted keys
Every key is rooted in a TPM 2.0, a Secure Enclave or a passkey. There are no key files and no seed phrases to steal.Learn moreHybrid signatures
Passkey operations and transactions carry a post-quantum ML-DSA-65 signature alongside a classical one, bound together and bound to the account.Closed by default
The RPC surface is split into open, owner and admin methods. Anything that moves money or changes state needs a signature from the account that pays.Verified attestation
Trusted execution environments are evidence, not custody. Attestation is checked against each hardware vendor's chain before it counts.Learn moreIsolation
Hosted functions and skills run deny-by-default, and managed databases are isolated per tenant.
Accounts
Losing a device is not losing the account.
Link several devices to one identity and add guardians. Recovery onto a new device waits out a timelock that any of your existing devices can veto, and an alert tells you it has started.
Operators
Accountable to their own promises.
Operators publish signed policies and are slashed only for provable breaches of them. Validators that sign conflicting checkpoints can be slashed with the certificates themselves.
Responsible disclosure
Report a vulnerability.
If you believe you have found a security issue in Tenzro Network, email eng@tenzro.com or use GitHub's private vulnerability reporting on the affected repository. Please do not open a public issue. We will acknowledge your report and keep you informed as we investigate.