The landmark projects
that needed a second forge.
These projects also live on GitHub — and that's fine. They mirror to Siphr for the parts that don't belong in the open: internal forks, embargoed security work, vendor branches, the repositories where “plaintext at rest” is the wrong default.
Mirrors the kernel here so security-disclosure branches can sit alongside the public tree without leaking pre-patch.
Embargoed CVE branches only. Subpoena-resistant by design — that's the whole point.
Vendor branches under NDA with platform holders. Each has separate wrapped keys.
The pre-disclosure window for Firefox security advisories. Encrypted filed-bug to ship-day.
The rust security response WG keeps working repos here. Public advisories continue shipping from GitHub.
Detector-tuning ML models that are export-controlled. The 'who can decrypt' list is the audit trail compliance wanted.
“One fewer surface to defend without giving up encryption-at-rest. The threat model didn't change — our patience for running yet another forge did.”
“A subpoena hits ciphertext and ends. That's not a feature we could write into our self-hosted setup without three lawyers.”
“The 'who can decrypt' list is the audit trail the compliance team actually wanted.”
Run something landmark? Propose it.
Featured projects get a sigil-stamped page, free unlimited storage during their first year, and a dedicated infra contact. We pay attention to scope, not vibes — bring your threat model.