Security & Trust
How ForgeMesh endpoints are protected today, stated so you can verify it yourself.
Transport (verified 2026-09-29)
Every ForgeMesh endpoint negotiates TLS 1.3 with the X25519MLKEM768 hybrid key exchange at the edge. That is NIST FIPS 203 ML-KEM on every handshake today, so recorded traffic is not a harvest-now-decrypt-later target.
Check it yourself:
echo | openssl s_client -connect forgemesh.io:443 -servername forgemesh.io -tls1_3 2>/dev/null | grep "Negotiated TLS1.3 group"
# → Negotiated TLS1.3 group: X25519MLKEM768Requires OpenSSL 3.5 or newer. Swap in any ForgeMesh hostname.
Payments
On-chain x402 settlement uses the chain’s native signature scheme (secp256k1 on Base), which is not yet post-quantum. We keep payer balances minimal, use receive-only addresses for revenue, and track the Base/Ethereum post-quantum roadmap. We do not describe payments as quantum-safe.
What we don’t claim
- No homemade cryptography.
- No “quantum-safe” claims beyond the transport statement above.
- Symmetric integrity (HMAC-SHA256) on app-layer signatures, with an algorithm tag published in signed payloads so verifiers can migrate.
Report an issue
[email protected]. See also our Privacy Policy and Terms & Disclaimer.