{
  "slug": "zksecurity",
  "name": "zkSecurity",
  "url": "https://zksecurity.xyz",
  "hq": "United States (distributed team)",
  "focus": "Cryptography audits: post-quantum, zero-knowledge proofs, MPC, FHE, TEEs",
  "summary": "zkSecurity is a cryptography-focused security firm that audits cryptographic protocols and implementations, including post-quantum schemes such as ML-KEM, ML-DSA, SLH-DSA, FN-DSA, and hash-based signatures, as well as zero-knowledge, MPC, and FHE systems. It was founded by David Wong, author of Real-World Cryptography, and its team consists of practicing cryptographers rather than generalist penetration testers.",
  "pqc_services": [
    "Implementation audits of ML-KEM, ML-DSA, SLH-DSA, FN-DSA, LMS/XMSS, and hybrid key exchange against FIPS 203/204/205, SP 800-227, and RFC 10024",
    "Protocol-level review of post-quantum migrations (TLS, messaging, blockchain signature schemes, PKI)",
    "Constant-time and side-channel review, known-answer test coverage, and specification conformance",
    "Migration planning: cryptographic inventory, hybrid design, and crypto-agility review",
    "Production-grade cryptographic implementation and research engagements"
  ],
  "evidence": [
    [
      "Public audit reports",
      "https://zksecurity.xyz/reports"
    ],
    [
      "Clients include Ethereum Foundation, Solana Foundation, Aztec, StarkWare, Aleo, Mina, Aptos, Celestia",
      "https://zksecurity.xyz"
    ]
  ],
  "rank": 1,
  "page": "https://pqaudit.org/auditors/zksecurity/",
  "updated": "2026-09-12"
}