Skip to main content

Compatibility matrix

This matrix separates tested pilot behavior from interfaces, reference designs, and research paths. It is the source of truth for external capability claims.

Status vocabulary

StatusMeaning
Controlled validationImplemented and covered by automated or recorded non-production tests
Interface definedContract and validation rules exist; a named partner implementation is still required
Reference designIntegration and security requirements are documented; partner enforcement acceptance is the next gate
ExperimentalResearch-only; prohibited for real keys or production assets

None of these labels means production readiness, third-party audit completion, or acceptance by a named design partner.

Capability matrix

Component or pathCurrent statusEvidence available nowMissing before production
Policy, roles, approvals, request state, and evidence exportControlled validationDeterministic tests and reproducible release evidenceMulti-tenant admission, production operations, external audit, partner acceptance
FROST Ed25519, 3-of-5 on one controlled hostControlled validationReal process tests, restart recovery, signer replacement, aggregate verificationIndependent machines, administrators, failure domains, and protected key hardware
FROST Ed25519, 5-of-7 and 22-of-33 certificate profilesControlled validationRFC 9591 authorization-certificate tests for both profilesIndependent operator deployment, production DKG, protected key custody, load and fault evidence
Algorithm-neutral signer backendControlled validationFROST backend and stable backend boundaryReviewed threshold ECDSA, hardware signer, or external custody implementations
Dynamic committee selection and rotationExperimentalResearch implementations and state-machine testsGoverned candidate registry, bias-resistant randomness, Sybil controls, multi-operator rotation drills
Proactive resharing and incremental DKGExperimentalResearch implementations and lifecycle testsReviewed production protocol, participant-isolated ceremony, complaint handling, HSM/KMS custody
Remote FROST signer transport over pinned mTLSControlled validationTLS 1.3, leaf pinning, signed envelopes, bounded requestsMulti-host deployment, capacity controls, metrics, certificate automation, external review
Registry, key-epoch, and certificate lifecycleControlled validationStaging, overlap, activation, revocation, expiry, rollback rejectionMulti-operator approval, automated issuance, trusted time, HSM/KMS-backed identities
Independent evidence witness transportControlled validationSigned receipts, exact retry, restart recovery, rollback detectionSeparately administered retention-locked or WORM service
Restricted BSC ERC-20 wallet handoffControlled validationSelf-operated testnet and restricted wallet workflow with receipt reconciliationNamed partner environment, production key custody, operational acceptance
Vendor-neutral custody adapterInterface definedStable request binding, idempotency, outcome and completion semanticsProvider mapping, authenticated transport, sandbox implementation, partner sign-off
Optional Lit PKP validation backendControlled validationLive Chipotle sandbox validation, immutable Action binding, durable reconciliation, rotation drillReviewed transaction construction and broadcast path, monitoring, external review
Safe module, guard, or timelock verifierReference designExact certificate-binding and bypass requirementsReviewed onchain verifier, testnet enforcement, bypass closure, partner acceptance
Operational alert webhookControlled validationDurable deduplication, degraded/reminder/recovered transitions, restart recoveryReal alert destination, on-call ownership, escalation and response drills
Threshold ML-DSA pathExperimentalResearch tests onlyStandardized construction, external cryptographic review, production implementation

Integration decision rule

Start a design-partner pilot only when one row maps to a specific operation, owner, environment, and acceptance test. Do not combine several unaccepted paths into one pilot and describe the result as an end-to-end production system.

For any execution integration, first complete the non-bypassable checklist. If an owner, emergency key, legacy module, or provider credential can execute the same operation around Luvion, that path remains outside Luvion protection.