RESEARCH

Most vendors hide their architecture.
We publish ours.

Every specification, threat model, and RFC behind CDK is public — reviewable before you adopt it, not after.

Specifications·Threat Models·Reference Implementations·RFCs
PUBLICATIONS

The specifications CDK is built on.

OPEN BY DEFAULT

Nothing load-bearing stays private.

If a decision affects the evidence you rely on, it's written down somewhere you can read it.

Architecture Trust Model Threat Model Cryptography Evidence Model Schemas Specifications Reference Implementations RFCs

Start with the Trust Graph.

It's the one specification everything else in CDK is built on.