// CRYPTOGRAPHIC_BOUNDARY · NO_LOGIN_REQUIRED
// THE_SPLIT
A3E9 software scope
Owned, tested, and covered by the known-answer suite.
Ed25519 verify
RFC 8032 §6.1 · 5 vectors
RIPEMD-160
Published reference vectors · 6 vectors
ML-DSA / ML-KEM via liboqs
NIST ACVP vectors · 225 pass
195 more not reachable via the liboqs API · liboqs is not FIPS certified
Policy · normalization · audit chain
evaluated before any PKCS#11 call
Vendor module scope
Certified separately by the vendor. Not A3E9’s claim to make.
Key generation and storage
CKA_EXTRACTABLE=CK_FALSE, set by A3E9, not caller-overridable
The signing operation
the key never leaves the module
Module certification
exercised against real modules: SoftHSM2 · Craton
written, not hardware-validated: Thales · AWS CloudHSM · Utimaco
Claimed by neither
Outside A3E9’s software and outside the module’s certificate.
A FIPS 140 hardware boundary
the evaluation modules are software · no certified chassis
CAVP / CMVP validation
vectors are run and self-reported · no certificate is held
SLH-DSA (FIPS 205)
not implemented · no request enum, no wired mechanism
BIP-340 / Taproot spends
refused on every vendor · no software fallback
Limit
// WHY_LIBOQS_IS_A_SCOPE_NOTE
// REFUSALS_AT_THE_BOUNDARY
// WHAT_A_TOKEN_ADDS
A token shows which side of this line executed a given operation: the portal reports the active vendor and mechanism for a signature you submitted, which is the one thing a static diagram cannot demonstrate.
Everything above is checkable without contacting anyone, and is meant to be read first. The token exists because the remainder needs a provisioned environment — not because the evidence is being held back.