Skip to content
Tyche Institute

Conformance & measurement

Tyche Labs

Tyche Labs is the instrument side of the institute: the harnesses, corpora, and measurements behind the papers. Everything here follows one discipline — a claim is only as good as the test that could have refuted it, so the tests are published together with the claims, as versioned, reproducible artefacts.

Tyche Labs publishes open research artefacts and test protocols. It does not offer conformity-assessment or certification services; where its work touches accredited evaluation, the relationship is one of open research about that world, not participation in its market.

Operating today

Four instruments

verifier conformance · two independent implementations

Verifier parity harness

The action-evidence verifier exists twice — once in TypeScript, once in Python — and both are held to the same corpus of must-accept and must-reject cases: tampered payloads, swapped mandates, stripped signatures, expired and replayed evidence. The parity run executes on every build of this site; if the two implementations ever disagree about a single case, the site does not ship. Conformance here is not a claim, it is a build step.

The specifications behind it →

daily measurement · EU digital identity

Trust-infrastructure observatories

Automated daily measurement of the trust infrastructure the EU digital identity ecosystem depends on, recorded as a public, versioned time series. Measurement is the lab's answer to argument: where a regulation promises an infrastructure, the observatory checks what is actually reachable, day after day.

The observatories →

The newest of them maps the lists that say whom to trust — two regional hubs, a scattering of islands, and the endpoints that do not answer.

negative testing · versioned corpora

Negative test corpora

Every specification the institute publishes ships with the cases a conformant implementation must reject, not only the ones it must accept. The corpora are versioned, cited in the papers they support, and deposited with DOIs, so a third party can re-run the refutations without asking us anything.

Papers with their artefacts →

breakable demonstrations

Instruments you can break

The live demonstrations are deliberately breakable: a capture-the-flag against the real verifier, an observatory that follows a signed mandate to an external network effect, and interactive architecture walk-throughs. A demonstration that cannot embarrass its authors is a brochure.

The Lab pages →

In preparation

An open interlaboratory comparison for security evaluation

Accreditation of testing laboratories presumes proficiency testing — organised comparisons in which laboratories evaluate the same material and their results are scored against assigned values. For Common Criteria evaluation work no such scheme appears to exist: as of August 2026 the international EPTIS registry of proficiency-testing schemes lists none for it, and the word “proficiency” does not occur in the CC recognition arrangement, the EUCC regulation, or the ENISA accreditation state-of-the-art document. Every accredited laboratory is nonetheless required to have a benchmarking plan, and European accreditation practice explicitly accepts small interlaboratory comparisons — down to a handful of participants — where no scheme is organised. Tyche Labs is designing an open interlaboratory comparison set for document-analysis evaluation work and verifier conformance: shared evaluation objects, blinded defect injections, assigned values with published rationale, and versioned scoring.

Round 0 of the verifier-conformance track is open: eighteen deterministically generated evidence packages, a fixed reason vocabulary, and assigned values sealed by hash before the round began, published in the aep-sandbox repository under interlab/round0. Before any outside participant arrived it produced a finding against us — our two reference implementations disagree about how to write a number, and the standard says the one we call the reference is the wrong side.

The long line

Evaluation capacity as a research subject

Estonia currently has no accredited cybersecurity conformity-assessment body — the national certification authority's own page states it plainly. The European scheme that would use such bodies exists; the laboratories are concentrated in a handful of member states; the entry path runs through accreditation, cross-border certification-body licensing, and witnessed evaluations. Tyche Labs studies that path as a subject: what security-evaluation capacity costs, why small member states lack it, and which parts of the verification burden can be carried by open, reproducible instruments rather than by scarce accredited seats. The instrument corpus above is built so that, should the long line ever call for it, nothing has to be rebuilt.