← back to the showcase

Trust and delivery

What you receive from TAKT, how to check it yourself, how to compare it in a controlled test environment before switching, and what happens to your code while we work on it. The Terms of Service, the NDA, the DPA and the Recipients Schedule govern; this page explains them in practice.

What you receive

Every paid build comes as one signed package:

Part What it is for
bin/ or lib/ + include/ The optimised build: an executable, or a static or dynamic library with your C headers
verify/pure.sh Observes, on your test runs, network calls, program starts and file writes: it runs the build with no network at all and under strace; a check that cannot run here reports INCOMPLETE, not PASS
verify/diff.sh Your original build against the TAKT build on your own inputs: stdout and exit status, byte for byte; ready for your CI
run/takt-shadow Runs your original build, the TAKT build, or both for comparison in a test environment
SBOM.cdx.json The components (CycloneDX 1.5), from your Cargo.lock
REPORT.* What was measured and checked before you paid
escrow/ When requested and agreed before payment: the order-specific encrypted source escrow box (see below)
SHA256SUMS, SHA256SUMS.sig Hashes of every file, signed by TAKT

Check it yourself

ssh-keygen -Y verify -f allowed_signers -I [email protected] -n takt-delivery \
  -s SHA256SUMS.sig < SHA256SUMS && sha256sum -c SHA256SUMS
verify/pure.sh -- bin/YOUR-PROGRAM ARGS...
verify/diff.sh --original 'YOUR-ORIGINAL ARGS' --takt 'bin/YOUR-PROGRAM ARGS' --runs 3

The signing key: /.well-known/takt-delivery-allowed-signers (ED25519, fingerprint SHA256:dVe5e+0WFtQXVcmQYVPLXh9Z3pukqbnNCTWAKEIpKH0). The same line ships in every package.

You may fuzz the build, run sanitizers and any other security tests, including by contractors under confidentiality (NDA, clause 6). For timing, use the open-source takt-harness.

Compare before you switch

Source escrow

Source escrow is available on written request before payment under Terms 8 and the escrow box rider. It is an order-specific bootable image containing encrypted transformed source, its manifest, build environment and the release rule. The Client runs it at its cost on the platform recorded for the order. The image gives source only on the rider's release events; ordinary checks show hashes and results, not the source.

Before confirming an escrow order, the platform and provisioning/handover procedure must qualify. The Schedule records protections and trust model, hashes, PCRs, keys, costs and acceptance. TAKT provisions in an account it controls, binds deployment verification to the receiving channel, then transfers control. The Client removes Provider access and independently verifies the recorded VM and boot over the agreed bound channel before acceptance. An instance label, ordinary SSH connection or local prototype alone does not establish these requirements.

The source must rebuild the delivered binary byte for byte. VM/vTPM loss, replacements, external-source availability and data-disk rollback limits are defined by the rider. The old independent-agent arrangement does not describe new box-model orders. If the required platform qualification is not complete, an escrow order is not confirmed or paid; a Client can choose an ordinary order without escrow or wait for qualification.

Your code while we work on it

For procurement

Source text: index.md

Telegram