A3E9 logoA3E9
// AUDIENCE_FILTERShowing content for NIST / standards conformance. De-emphasized: Competitive positioning, the industry-landscape framing, and on-chain market operations — none of it is conformance evidence.

// WHY_A3E9_EXISTS · STANDARDS_CONFORMANCE

Primitives, Parameter Sets, and Where the Software Boundary Is.

A3E9 is middleware in front of a vendor PKCS#11 module. The cryptography A3E9 owns in software is vector-tested and published per case; key generation, storage and the signing operation belong to the module and are certified — or not — by its vendor. That boundary is the first thing this page states, because every number on the conformance surface sits on one side of it.

Partial

Which primitives, which parameter sets, which known-answer tests — and whose boundary?

// THE_SHORT_ANSWER

What This Answers, and How Far.

The per-case conformance surface publishes each vector with its upstream ACVP identifier, and publishes the exclusions beside the results with the reason each one could not run. Counts are read from the run record the test binaries emitted; none is restated here, because a number typed onto a page is a number that can drift from the record it came from.

The post-quantum path in evaluation runs on software liboqs, which is not a FIPS-certified module. ML-DSA (FIPS 204) and ML-KEM (FIPS 203) are reachable. SLH-DSA (FIPS 205) is not implemented: there is no request enum and no wired PKCS#11 mechanism for it.

Nothing here is a validation result. The vectors are self-reported known-answer runs, published so they can be checked, and the surface says so on the same screen as the results.

// STATED_LIMITS

What This Is Not — Stated the Same Way for Every Audience.

  • A3E9 holds no FIPS, CAVP, or CMVP certificate.
  • The software PQC path uses uncertified liboqs. SLH-DSA (FIPS 205) is not implemented.
  • Only SoftHSM2 and Craton have been exercised against real modules — both software. Thales, AWS CloudHSM, and Utimaco are written and unvalidated.
  • This is not a DORA, MiCA, or GDPR compliance conclusion.
  • Four product lines: HSM normalization, institutional RWA custody, wallet transaction security, and interaction-time assurance. The fourth is not a TINL capability — it is execution-path, governance and oracle work on its own corpus, at its own maturity.
  • Not a production or procurement claim.
  • Keys remain in the connected HSMs. A3E9 is a removable control layer, not a custodian of those keys.