The repository contains the implementation.
Cryptographic behavior is owned by the Rust source. Browser and Node.js packages expose that behavior through their runtime-specific boundaries. This website explains the system; it does not replace tagged source, package manifests, or the license.
github.com/voided-network/voided ↗One system, explicit boundaries.
Source, artifact, runtime, and release state are separate proofs.
- Tagged or committed source identifies what was intended to ship.
- Package manifests and hashes bind native and WASM artifacts to a specific build.
- Runtime verification checks that the selected artifact matches the package contract before use.
- The Updates page records what is currently verified, pending, or unpublished.
Use source-aware context when the agent can inspect source.
The read-only Voided MCP searches a local checkout. When MCP is unavailable, use the reusable skill, compact AGENTS.md instruction, full text reference, or JSON facts.
MIT licensed.
The repository license text controls the software grant and warranty disclaimer. Examples on this website are implementation guidance; they do not certify the complete security of an integrating application.
Read the license ↗Public bugs. Private vulnerabilities.
Use a public issue for a minimal reproducible integration defect. Use a private security advisory for suspected vulnerabilities. Never attach plaintext, raw keys, Recovery Deck order, a derived Recovery Key, a stable root, customer data, or secret environments.