English · Français

Diligence

Trust & security

A compact page for evaluators. Source, docs, and local setup live in the public MIT repository: github.com/mgagp/ezkey. See also Source code & evaluation.

Trust model (plain language)

Ezkey is backend-first cryptographic MFA: your integration backend and the mobile app participate in an explicit chain of enrollment and authentication. The browser is not the center of the ceremony.

What Ezkey claims — and what it does not

The project aims to be materially stronger than passwords and classic TOTP-style flows for some self-hosted, backend-oriented contexts. It is not a WebAuthn / FIDO2 implementation and does not claim formal equivalence to those ecosystems. Ezkey is alpha — not production-ready and not Duo / Okta / Keycloak parity.

Security posture reflects deliberate, opinionated trade-offs. For the maintainer’s framing of limits and ambition, see Why Ezkey exists.

Open source & visibility

License: MIT. The main repository is public on GitHub: https://github.com/mgagp/ezkey. There are still no published release packages. Progress notes remain on Monthly digests.

Report a security issue

Use security@ezkey.org. Do not use public GitHub issues for suspected vulnerabilities. The published policy is SECURITY.md in the repository.

Technical documentation

Prefer the in-repo docs; use this site for high-level evaluation material:

← Back to home