{
  "slug": "cryspen",
  "name": "Cryspen",
  "url": "https://cryspen.com",
  "hq": "Berlin, Germany",
  "focus": "Formally verified cryptography and high-assurance post-quantum implementations",
  "summary": "Cryspen builds formally verified post-quantum implementations (libcrux ML-KEM and ML-DSA, verified with hax and F*) and performs verification-driven reviews. Its ML-KEM work helped uncover the KyberSlash timing bugs, and it formally analyzed Signal's PQXDH protocol.",
  "pqc_services": [
    "Formally verified ML-KEM and ML-DSA implementations (Rust and C)",
    "Protocol verification (Signal PQXDH, post-quantum MLS)",
    "High-assurance code review"
  ],
  "evidence": [
    [
      "Verified ML-KEM in Rust",
      "https://cryspen.com/post/ml-kem-implementation/"
    ],
    [
      "Formally verified post-quantum cryptography",
      "https://cryspen.com/post/fospqc/"
    ]
  ],
  "rank": 4,
  "page": "https://pqaudit.org/auditors/cryspen/",
  "updated": "2026-09-12"
}