RESEARCH
Most vendors hide their architecture.
We publish ours.
Every specification, threat model, and RFC behind CDK is public — reviewable before you adopt it, not after.
Specifications·Threat Models·Reference Implementations·RFCs
PUBLICATIONS
The specifications CDK is built on.
READ SPEC →
Trust Graph Specification
The formal model for representing software delivery evidence as a verifiable graph. Version 1.0.
READ SPEC →Evidence Model
How delivery events become signed, portable, independently verifiable attestations. Version 1.0.
READ SPEC →Security Architecture
The cryptographic foundations behind CDK's evidence and verification design. Version 1.0.
READ SPEC →Threat Model
What CDK protects against, and the assumptions its trust model depends on. Version 1.0.
READ SPEC →Software Delivery Assurance Model
The conceptual framework connecting engineering evidence to compliance outcomes. Version 1.0.
VIEW ALL →RFCs
Open proposals shaping CDK's public specifications before they're finalized.
OPEN BY DEFAULT
Nothing load-bearing stays private.
If a decision affects the evidence you rely on, it's written down somewhere you can read it.