Conformance & measurement
Tyche Labs
Tyche Labs is the instrument side of the institute: the harnesses, corpora, and measurements behind the papers. Everything here follows one discipline — a claim is only as good as the test that could have refuted it, so the tests are published together with the claims, as versioned, reproducible artefacts.
Tyche Labs publishes open research artefacts and test protocols. It does not offer conformity-assessment or certification services; where its work touches accredited evaluation, the relationship is one of open research about that world, not participation in its market.
Operating today
Four instruments
verifier conformance · two independent implementations
Verifier parity harness
The action-evidence verifier exists twice — once in TypeScript, once in Python — and both are held to the same corpus of must-accept and must-reject cases: tampered payloads, swapped mandates, stripped signatures, expired and replayed evidence. The parity run executes on every build of this site; if the two implementations ever disagree about a single case, the site does not ship. Conformance here is not a claim, it is a build step.
daily measurement · EU digital identity
Trust-infrastructure observatories
Automated daily measurement of the trust infrastructure the EU digital identity ecosystem depends on, recorded as a public, versioned time series. Measurement is the lab's answer to argument: where a regulation promises an infrastructure, the observatory checks what is actually reachable, day after day.
The newest of them maps the lists that say whom to trust — two regional hubs, a scattering of islands, and the endpoints that do not answer.
negative testing · versioned corpora
Negative test corpora
Every specification the institute publishes ships with the cases a conformant implementation must reject, not only the ones it must accept. The corpora are versioned, cited in the papers they support, and deposited with DOIs, so a third party can re-run the refutations without asking us anything.
breakable demonstrations
Instruments you can break
The live demonstrations are deliberately breakable: a capture-the-flag against the real verifier, an observatory that follows a signed mandate to an external network effect, and interactive architecture walk-throughs. A demonstration that cannot embarrass its authors is a brochure.
In preparation
An open interlaboratory comparison for security evaluation
Accreditation of testing laboratories presumes proficiency testing — organised comparisons in which laboratories evaluate the same material and their results are scored against assigned values. For Common Criteria evaluation work no such scheme appears to exist: as of August 2026 the international EPTIS registry of proficiency-testing schemes lists none for it, and the word “proficiency” does not occur in the CC recognition arrangement, the EUCC regulation, or the ENISA accreditation state-of-the-art document. Every accredited laboratory is nonetheless required to have a benchmarking plan, and European accreditation practice explicitly accepts small interlaboratory comparisons — down to a handful of participants — where no scheme is organised. Tyche Labs is designing an open interlaboratory comparison set for document-analysis evaluation work and verifier conformance: shared evaluation objects, blinded defect injections, assigned values with published rationale, and versioned scoring.
Round 0 of the verifier-conformance track is open: eighteen
deterministically generated evidence packages, a fixed reason
vocabulary, and assigned values sealed by hash before the round
began, published in the aep-sandbox repository under
interlab/round0. Before any outside participant
arrived it produced a finding against us —
our
two reference implementations disagree about how to write a
number, and the standard says the one we call the reference is
the wrong side.
The long line
Evaluation capacity as a research subject
Estonia currently has no accredited cybersecurity conformity-assessment body — the national certification authority's own page states it plainly. The European scheme that would use such bodies exists; the laboratories are concentrated in a handful of member states; the entry path runs through accreditation, cross-border certification-body licensing, and witnessed evaluations. Tyche Labs studies that path as a subject: what security-evaluation capacity costs, why small member states lack it, and which parts of the verification burden can be carried by open, reproducible instruments rather than by scarce accredited seats. The instrument corpus above is built so that, should the long line ever call for it, nothing has to be rebuilt.