Evaluation Kits · v0.2.0
Qualified evidence, packaged for controlled technical evaluation.
Binary-only RSA-oriented and ECC packages expose functional, dependency and resource evidence without disclosing proprietary implementation source.
VERIFY → MEASURE → DECIDE
Evaluation catalog
Separate packages for each technology, generation and runtime boundary.
Every customer archive is tied to its platform, architecture, profile, source commit, workflow evidence, manifest and SHA-256 checksums. Evaluation permission does not grant integration or production use.
RSA-oriented engineering · hostedFive RSA Hosted Evaluation Complete Kits v0.2.0 Multiplatform
Lean plus four OpenSSL runtime boundaries
Executable black-box evaluation across the desktop/server matrix.
The hosted RSA Evaluation line keeps Lean, external-runtime and self-contained packages separate. Its current OpenSSL-backed variants are qualified with OpenSSL 3.5.7 and 4.0.1; every Complete Kit preserves the matching platform, architecture, loader, manifest and execution evidence.
RSA Hosted · LeanHosted Evaluation Lean
Low-dependency executable evaluation without OpenSSL.
- No libcrypto or libssl dependency
- Eight native desktop/server targets
- Functional execution and package audit
RSA Hosted · OpenSSL 3.5.7Hosted Evaluation OpenSSL 3.5 External
Uses the architecture-matched customer-supplied runtime.
- Dynamic libcrypto; no libssl
- External loader guidance
- Exact runtime identity recorded
RSA Hosted · OpenSSL 3.5.7Hosted Evaluation OpenSSL 3.5 Self-Contained
Includes the approved architecture-matched crypto runtime.
- Bundled libcrypto and licence
- Runtime files covered by checksums
- No external Windows DLL-path step
RSA Hosted · OpenSSL 4.0.1Hosted Evaluation OpenSSL 4.0 External
Uses the separately supplied qualified 4.0 runtime.
- Dynamic libcrypto; no libssl
- Exact 4.0.1 build/runtime declaration
- Platform loader validation
RSA Hosted · OpenSSL 4.0.1Hosted Evaluation OpenSSL 4.0 Self-Contained
Includes the approved OpenSSL 4.0.1 runtime.
- Architecture-matched bundled runtime
- Licence, manifest and checksums
- Packaged functional retest
Five separately qualified Complete Kits
Lean plus four OpenSSL runtime boundaries.
The RSA Binary Footprint Evaluation line is supplied as five distinct multiplatform Complete Kits. Each package preserves its own dependency, loader, manifest, checksum and execution evidence; external-runtime and self-contained packages are never mixed.
RSA · LeanBinary Footprint Evaluation Lean
Low-dependency Complete Kit without OpenSSL.
- No libcrypto or libssl dependency
- Functional execution and package verification
- Linux x86-64 glibc/musl · Linux ARM64 glibc/musl · Windows x64/ARM64 · macOS ARM64/x86-64
RSA · OpenSSL 3.5.7Binary Footprint Evaluation OpenSSL 3.5 External
Complete Kit using the customer-supplied qualified crypto runtime.
- Dynamic libcrypto dependency; no libssl
- Windows requires the matching DLL directory on PATH
- Runtime identity recorded in the manifest
RSA · OpenSSL 3.5.7Binary Footprint Evaluation OpenSSL 3.5 Self-Contained
Complete Kit bundling the approved crypto runtime.
- Bundled libcrypto and applicable licence
- No external Windows DLL-path step
- Runtime files covered by checksums
RSA · OpenSSL 4.0.1Binary Footprint Evaluation OpenSSL 4.0 External
Complete Kit with a separately validated external crypto runtime.
- Dynamic libcrypto dependency; no libssl
- Exact 4.0.1 build/runtime declaration
- Platform loader and dependency audit
RSA · OpenSSL 4.0.1Binary Footprint Evaluation OpenSSL 4.0 Self-Contained
Complete Kit with the approved crypto runtime included.
- Architecture-matched bundled runtime
- No OpenSSL headers, tools or source
- Binary hygiene and packaged retest
ECC Field256 · hosted desktop/serverLean and OpenSSL 3.5.7/4.0.1 · external-runtime and self-contained
ECC Hosted Evaluation matrix
ECC v1 and ECC v2 remain separate across every dependency boundary.
For each generation, the hosted line includes Lean packages without OpenSSL and OpenSSL-backed packages qualified with versions 3.5.7 and 4.0.1. External-runtime and self-contained packages remain distinct on Linux, macOS and Windows.
ECC v1/v2 · LinuxLinux Evaluation Complete Kits
One Complete Kit for each generation, each aggregating 20 qualified packages.
- 4 Lean: x86-64/ARM64, glibc/musl
- 16 OpenSSL packages: 3.5.7/4.0.1, external/self-contained
- Binary-only black-box executables
ECC v1/v2 · macOSmacOS Evaluation Complete Kits
One Complete Kit for each generation, each aggregating 10 qualified packages.
- 2 Lean: Apple Silicon and Intel
- 8 OpenSSL packages: 3.5.7/4.0.1, external/self-contained
- Mach-O architecture and loader validation
ECC v1/v2 · WindowsWindows Evaluation Complete Kits
One Complete Kit for each generation, each aggregating 10 qualified packages.
- 2 Lean: Windows x64 and ARM64
- 8 OpenSSL packages: 3.5.7/4.0.1, external/self-contained
- External DLL guidance and self-contained alternatives
ECC Field256 · embeddedLean only · no OpenSSL · 12 Complete Kits / 24 qualified packages
Cortex-M4Cortex-M33Cortex-M7Cortex-A53RISC-V RV32IMACRISC-V RV64IMAFDC + Zicsr
Shared Embedded Evaluation contract
The same qualification and delivery boundary applies to ECC v1 and ECC v2.
- Lean profile with no OpenSSL dependency
- Separate
O2 and Os executable firmware packages - Stripped ELF with no public header or linkable library
- QEMU functional execution and package retest
- RNG platform hook, zero heap and cross-generation rejection
- Manifest, binary-hygiene evidence and SHA-256 checksums
ECC v1 · Embedded EvaluationSix target-specific Complete Kits
The first fixed domain is packaged independently across the complete ARM and RISC-V target matrix.
- Lean profile; no OpenSSL dependency
- Stripped ELF; no header or linkable library
- QEMU execution and package retest
- Generation-bound public-key blobs
- RNG hook, zero heap and cross-generation rejection
- Manifest, hygiene evidence and checksums
ECC v2 · Embedded EvaluationSix target-specific Complete Kits
The second fixed domain is packaged independently with the same target and optimization matrix.
- Lean profile; no OpenSSL dependency
- Stripped ELF; no header or linkable library
- QEMU execution and package retest
- Generation-bound public-key blobs
- RNG hook, zero heap and cross-generation rejection
- Manifest, hygiene evidence and checksums
Every supplied package
Qualification is part of the deliverable boundary.
Functional executionDependency allowlistBinary hygienePackage retestManifest validationSHA-256 integrityConfidentiality auditExact provenance
Assessable without source disclosure
Evaluation remains distinct from integration.
Evaluation Kits allow authorized customers to execute the supplied binary, inspect declared dependencies, reproduce permitted evidence and verify package integrity. They contain no public linkable library or integration header.
Stable customer-facing interfaces, examples and linkable libraries belong to the corresponding Integration Kits. Source access, production licensing and platform-specific development remain separate written matters.