SIPHR
sign increate key
↳ /featured · curated by the siphr editorial team · updated weekly

The landmark projects
that needed a second forge.

These projects also live on GitHub — and that's fine. They mirror to Siphr for the parts that don't belong in the open: internal forks, embargoed security work, vendor branches, the repositories where “plaintext at rest” is the wrong default.

0 featured projects↳ propose one · editorial@siphr.dev
editorial· what featured looks like

Imagine: Microsoft moves Windows Core security research to Siphr.

The kernel team still lives on GitHub for public Windows components. But the embargoed CVE pipeline — unreleased patches and proof-of-concept exploits — would move here. The argument is uncomplicated: encrypted at rest, wrapped to a known set of public keys, signed commits, no recovery path through us.

“Plaintext at rest was never the right answer for embargoed work.”

↳ the argument behind every featured project
example
org/embargoed-work
e2eeverified org★ editor's pick
Featured is curated by the Siphr editorial team. Once a repo is featured here, it gets:
  • A sigil-stamped page
  • Free unlimited storage during year one
  • A dedicated infra contact
38 fc 81 c8 4a 6b 9b 8f 1e 54 5c 91 b5 3e c4 9f 90 df a8 c2 bb 0c 1e 23 d0 68 4b 03 99 c3 c0 0e ae e3 09 04 cb 89 d5 5a 42 42 21 ec 19 f2 48 cb
↳ examples of what could be featured here
concept
operating systems
reactos/kernel

Mirrors the kernel here so security-disclosure branches can sit alongside the public tree without leaking pre-patch.

↳ illustrative● also mirrors github
concept
operating systems
linux/embargoed-cve

Embargoed CVE branches only. Subpoena-resistant by design — that's the whole point.

↳ illustrative● also mirrors github
concept
game engines
epic/unreal/restricted

Vendor branches under NDA with platform holders. Each has separate wrapped keys.

↳ illustrative● also mirrors github
concept
browsers
mozilla/0day-pipeline

The pre-disclosure window for Firefox security advisories. Encrypted filed-bug to ship-day.

↳ illustrative● also mirrors github
concept
languages
rust-lang/sec-audit

The rust security response WG keeps working repos here. Public advisories continue shipping from GitHub.

↳ illustrative● also mirrors github
concept
scientific
cern/atlas-ml-models

Detector-tuning ML models that are export-controlled. The 'who can decrypt' list is the audit trail compliance wanted.

↳ illustrative● also mirrors github
↳ why these teams would mirror to Siphr instead of self-hosting

One fewer surface to defend without giving up encryption-at-rest. The threat model didn't change — our patience for running yet another forge did.

g. lessard · security lead, reactos

A subpoena hits ciphertext and ends. That's not a feature we could write into our self-hosted setup without three lawyers.

anonymous · disclosed program · mozilla

The 'who can decrypt' list is the audit trail the compliance team actually wanted.

cern · atlas ml infra

Run something landmark? Propose it.

Featured projects get a sigil-stamped page, free unlimited storage during their first year, and a dedicated infra contact. We pay attention to scope, not vibes — bring your threat model.

Propose your projectRead the criteria