Security claims without publicly verifiable source code provide little real assurance. Closed-source encryption systems ask users for unearned trust, requiring them to believe that keys are protected, backdoors are absent, and algorithms match documentation. By open-sourcing the core engine and client libraries of Firefly, Lupyd replaces trust with independent verification.
Verifiable Cryptography: We Don't Claim, We Prove
Software that protects human communication must be auditable. By releasing Firefly under open licenses, cryptographers, security researchers, and developers can inspect the protocol state machines, verify epoch ratcheting logic, and confirm that plaintext is never exposed to the network layer.
The code is hosted publicly on GitHub at github.com/lupyd/firefly.
Key Components of the Open-Source Release
1. High-Performance Rust Core
The core handles TreeKEM group state machines, public key package validation, Welcome bundle processing, and commit verification. Rust's strict ownership model prevents memory leaks and concurrency vulnerabilities by construction.
2. Native WebAssembly (WASM) Compilation
Firefly compiles cleanly to WebAssembly, enabling browsers and lightweight desktop clients to execute cryptographic routines at native speeds without relying on slow or insecure JavaScript cryptography libraries.
3. Client-Enforced Group Governance
Group membership rules, channel permissions, and role escalations are handled as custom MLS proposals. These rules are verified by peer devices before committing new epochs, guaranteeing that administrative authority is cryptographically enforced rather than maintained by server policies.
4. End-to-End Encrypted Interactive Bots
Because Firefly runs in WASM, developers can build automated assistants and interactive agents that participate directly in the MLS tree. Unlike traditional bot integrations that route messages through third-party servers, Firefly bots execute client-side within the encrypted boundary.
- ✓ Firefly core and client-facing cryptographic libraries are fully open source on GitHub.
- ✓ Verifiable cryptography allows researchers and engineers to audit TreeKEM key derivation and epoch transitions.
- ✓ WebAssembly compilation brings native-speed MLS state machines directly into modern web browsers.
- ✓ Supports native E2EE chat bots that join the cryptographic tree as native participants rather than external relays.
- ✓ Group governance proposals enforce member roles and channel rules via client-side mathematical consensus.