# Changelog ## 0.1.0 - 2026-09-28 First public release under MIT. - `checkClaims()` and `formatClaims()` check advertised cryptographic claims against the keys, ciphers and transport settings described. - `end-to-end-encrypted` and `zero-knowledge` fail when a key is held by the server, an operator or a third party, whatever the cipher strength. - `encrypted-at-rest`, `encrypted-in-transit`, `passwords-hashed` and `forward-secrecy` are each checked against the element that would enforce them. - Broken primitives (MD5, SHA-1, DES, 3DES, RC4, ECB) are reported even when nothing was claimed about them. - A claim with nothing describing it is reported as not assessed, never as a pass.