v4.4.0 · 2026-09-06 · fixed exports + session cleanup

Post-quantum remote access, without hiding the trade-offs.

Evelin is a self-hosted, SSH-shaped secure tunnel built in Rust. Every connection uses ML-KEM-1024 for key establishment, ML-DSA-87 for mutual authentication, ChaCha20-Poly1305 for records, and HKDF-SHA-512 for key derivation. It is deliberately not SSH wire-compatible, has one implementation, and has not completed a paid third-party cryptographic audit.

Pure PQ, NIST category 5Explicit server pinningLinux security parity firstAGPL or commercial
evelin-client · v4.4.0
# Quiet by default: stdout stays clean
$ evelin-client --config ~/.config/evelin/client.toml exec uptime
 22:18:07 up 34 days,  4:42,  1 user

# Connection details go to stderr
$ evelin-client -v --config ~/.config/evelin/client.toml exec hostname
INFO handshake complete · protocol v2
evelin-host

# scp-shaped copy, integrity checked
$ evelin-client --config ~/.config/evelin/client.toml \
    cp ./backup.tar remote:/srv/backups/backup.tar
[████████████████████████████] 100%
4.4.0current release
2fixed-export formats
20Cargo workspace crates
17,662 B3-message handshake
EN / PToperator documentation
L5NIST PQ security category
Current release

v4.4.0 adds fixed exports and closes session resources on disconnect.

Receive a server-defined PostgreSQL dump or Forgejo data archive through a dedicated Linux service. Existing keys remain usable; fixed exports are disabled by default.

01

Server-defined exports

fixed-export selects an authorized producer ID and expected definition hash. The server controls the producer; clients cannot submit remote commands, paths or credentials.

02

Validate, commit, publish

Private staging, independent SHA-256 and format checks, disk synchronization and a fresh challenge-bound acknowledgement precede publication without replacing an existing file.

03

Session cleanup

Transport shutdown closes waiting channels, late replies to canceled opens are cleaned up, and session cancellation tears down PTY processes and forwarded-agent connections.

04

EN + pt-BR operator guides

Current installation, pinned toolchain and dependencies, exact SHA-256 labels, export setup and recovery are documented in English and Brazilian Portuguese.

Dedicated Linux deployment. Fixed exports require fully enforced pre-runtime Landlock ABI v3, explicit exporter authorization and a private receiver directory. They cannot share an enabled shell/filecopy instance. The Forgejo archive intentionally omits sensitive configuration and database files; it is not a complete backup by itself. Read the fixed-export guide.
Earlier release

v4.2.0 strengthened documentation and hot paths without inventing benchmark gains.

English + pt-BR documentation

v4.2

Governance documents and five operator guides were added in English and mirrored in Brazilian Portuguese. English remains the conflict-resolution source.

Fewer copies and allocations

measured scope

In-place receive decryption, pre-reserved AEAD tag space, shorter mux lock scope, and cloned SHA-256 state for resume remove work. The project explicitly makes no throughput claim from these changes.

Advisories cleared

audit green

crossbeam-epoch and anyhow were updated for 2026 RustSec advisories. The source release passed 439 tests and the audit/deny gates.

Positioning

A narrow tool for a specific threat model—not a universal SSH replacement.

The responsible deployment question is not “which table has more green cells?” It is whether post-quantum authentication and a small Rust implementation are worth the ecosystem and maturity costs for your environment.

Where Evelin fits

  • You control both endpoints and can deploy a separate service port.
  • Recorded confidentiality must remain protected for many years.
  • You want post-quantum authentication now, not only PQ key exchange.
  • You value a fixed suite, explicit trust pins, strict policy, and a smaller codebase.
  • You can evaluate a young protocol and operate it beside—not instead of—OpenSSH during migration.

Where OpenSSH remains the safer default

  • You need universal interoperability, SFTP, certificates, PAM, GSSAPI, Kerberos, X11, or ControlMaster.
  • You depend on cloud/forge support or third-party SSH clients.
  • You need decades of deployment history and broad independent scrutiny.
  • You cannot accept an externally unaudited single implementation.
  • You require mature security parity on Windows, macOS, or BSD today.
Audit status: Evelin is self-released and has not completed a paid third-party cryptographic audit. Memory safety, small scope, formal models, tests, and reproducible artifacts reduce risk; they do not erase it.
Architecture

Three authenticated flights, then a ratcheted record layer and multiplexed channels.

The algorithm suite is fixed. Protocol v2 negotiates operational capabilities inside the signed transcript; it does not negotiate ciphers.

1 · IdentityLong-term ML-DSA-87 identities. SHA-256 fingerprints. Explicit server pin or known_hosts.
2 · HelloClientFresh ephemeral ML-KEM-1024 encapsulation key, client identity, nonce, optional v2 offer.
3 · HelloServerML-KEM ciphertext, server identity, nonce, transcript-bound ML-DSA-87 signature.
4 · FinishClient ML-DSA-87 signature over the complete, domain-separated transcript.
5 · KeysHKDF-SHA-512 derives independent 32-byte ChaCha20-Poly1305 keys per direction.
6 · ChannelsAEAD records carry exec, PTY shell, file copy, forwarding, SOCKS, jump, and agent traffic.

Record layer

Each record is a big-endian length plus authenticated ciphertext. Per-direction counters construct nonces. Authentication failure closes the connection instead of attempting recovery.

Always-on symmetric ratchet

After 1 GiB per direction by default, HKDF advances that direction’s traffic key, zeroizes the old key, and resets its counter. This is not a full asymmetric ML-KEM rekey.

Policy before convenience

Unknown TOML keys fail closed. Exec uses an allow-list, file copy uses rooted paths and per-direction enable flags, and server identities must be pinned before connection.

Protocol v2: opt-in capability negotiation

shipping

Both peers set max_protocol_version = 2. Capability offers live inside the signed transcript. MAX_FRAME_LOG2 negotiates the lower frame ceiling from 16 KiB to 1 MiB. Tampering changes the transcript and breaks authentication.

Reserved and dormant machinery

not live

The v2 REKEY flag is reserved for future asymmetric ML-KEM rekeying. Session-ticket code exists and is tested, but its older extension path was never wired into the live handshake; treat resumption as dormant, not a current wire feature.

Actual toolchain

The current binaries and the workflows they expose.

The previous page listed several names that are not current standalone binaries. The public entry point is evelin-client; copy, forwarding, trust, and shell are its subcommands.

BinaryClosest OpenSSH roleCurrent purpose
evelin-serversshdServer daemon, policy enforcement, rate limits, audit logging, Linux Landlock/seccomp integration.
evelin-clientssh + scpexec, shell, cp, Linux fixed-export, pipe, local/reverse forwarding, SOCKS, jump hosts, proxy-command, and trust management.
evelin-keygenssh-keygenGenerate ML-DSA-87 identity files, optionally wrapped with Argon2id.
evelin-agentssh-agentHold unlocked identities in memory over a Unix socket and support agent forwarding.
evelin-keyscanssh-keyscanDiscover the fingerprint a server presents. Discovery is not trust; verify it out of band.
evelin-multisig-verify—Verify multi-signer release manifests.
evelin-sandbox-probe—Check Landlock capability on the host.
evelin-seccomp-probe—Check seccomp behavior on the host.
evelin-fixed-export-*—Linux PostgreSQL/Forgejo backend helpers and an extraction-free archive validator.
Security posture

Strong building blocks, explicit boundaries, incomplete external assurance.

The most important security property of this page is that “implemented,” “tested,” “proven,” and “planned” remain different labels.

Memory-safety boundary

Rust

Protocol codecs use safe Rust. Explicit unsafe boundaries remain in the C ABI and low-level operating-system/helper code; review their documented invariants rather than assuming the whole workspace is unsafe-free.

Fixed cryptographic suite

category 5

ML-KEM-1024, ML-DSA-87, ChaCha20-Poly1305, HKDF-SHA-512, Argon2id for optional key wrapping, and zeroization for secrets.

Explicit trust

no automatic TOFU

Client identities must appear in authorized_keys. Server fingerprints are SHA-256 and must be pinned in configuration or added explicitly to known_hosts.

Linux sandbox

Landlock + seccomp

Fixed-export instances require Landlock before runtime startup and keep legacy seccomp off. Ordinary shell instances skip Landlock; ordinary post-runtime seccomp does not filter all existing workers. Platform support must be assessed per mode.

Supply-chain gates

release evidence

The release tracks Cargo.lock and pins Rust 1.93.0. Formatting, Clippy, workspace tests and dependency gates accompany SHA-256 artifact manifests; consult the release notes for the actual results.

Known assurance gap

no external audit

Formal models and internal review are project-authored. A paid third-party cryptographic audit is still a roadmap item.

Formal status—exactly stated

  • Primary Tamarin model: 5 PROVEN, 3 STATED.
  • Primary ProVerif model: 8 PROVEN, 2 STATED.
  • Protocol-v2 negotiation: 4 Tamarin lemmas + 3 ProVerif queries are STATED, not PROVEN.
  • A STATED model expresses intended design; it is not a verified property of the implementation.

Threats outside the guarantee

  • Traffic length and timing analysis; there is no padding or cover traffic.
  • Compromised endpoints or a resident root attacker.
  • Determined denial of service despite connection and frame limits.
  • Physical/hardware side channels and implementation-level leakage not covered by an external audit.
  • Pure PQ has no classical X25519 backstop if ML-KEM is catastrophically broken.
Measured evidence

Numbers include their method; missing comparisons stay missing.

OpenSSH was not measured on the same Evelin test host, so this website makes no claim that Evelin is faster or slower end to end.

17,662 bytes

Derived v1 handshake wire cost: 4,200-byte HelloClient, 8,827-byte HelloServer, 4,635-byte Finish; three messages, 1.5 RTT.

11.7 ms median

Full connect + ML-KEM/ML-DSA handshake + exec + teardown, five loopback runs on one core. This is a CPU floor, not WAN latency.

1.13 GiB/s seal

Isolated ChaCha20-Poly1305 ceiling on 1 MiB blocks, single core with AVX2; open measured 924 MiB/s.

~50–75 MiB/s

Single-core bulk file-copy range with substantial cross-session variance. A real two-host, multi-core number remains pending.

v4.1.1 live validation remains the current published end-to-end baseline: 1 MiB upload at 21.6 MB/s and download at 45.8 MB/s through deliberately negotiated 64 KiB frames, with a byte-identical round trip.
Comparison checked · September 6, 2026

Evelin 4.4.0 vs OpenSSH 10.5.

OpenSSH 10.5 was released August 11, 2026 with security and other fixes. Experimental composite ML-DSA44+Ed25519 signatures, introduced in 10.4, remain an explicit opt-in. Official OpenSSH release notes.

CriterionEvelin 4.4.0OpenSSH 10.5Operational reading
Key exchangePure ML-KEM-1024, fixed, NIST category 5.Hybrid ML-KEM-768 + X25519 is the default.Evelin uses the higher PQ category; OpenSSH retains a classical backstop.
AuthenticationML-DSA-87 mutual authentication is the fixed default.10.4 adds experimental ML-DSA44+Ed25519 composite signatures, not enabled by default; mature classical methods remain.Evelin makes PQ authentication mandatory; OpenSSH offers an opt-in experimental hybrid path.
Implementation languageRust; documented unsafe boundary only in C FFI.C, with decades of hardening, privilege separation, and current sandbox work.Memory safety favors Evelin’s language choice; track record favors OpenSSH.
Wire ecosystemOwn protocol; one implementation; no SSH compatibility.Universal SSH-2 ecosystem with many implementations and services.OpenSSH wins decisively for interoperability.
FeaturesExec, PTY, copy, forwarding, SOCKS, jump, agent, metrics.All of those plus SFTP, certificates, PAM/GSSAPI/Kerberos, X11, ControlMaster, extensive config ecosystem.Use OpenSSH when established SSH integration matters.
SandboxingMode-specific Linux confinement; fixed exports require pre-runtime Landlock.Mature privilege separation and platform-specific sandboxing; Linux seccomp failures are fatal in 10.4.Both take sandboxing seriously; OpenSSH has broader operational maturity.
Handshake size17,662 bytes, derived from protocol constants.Smaller; the project’s older 3–4 KB estimate was for 10.2 object sizes and is not a packet capture.On constrained/high-latency links, OpenSSH has the wire-cost advantage.
External assuranceNo completed third-party cryptographic audit.Decades of public deployment, independent review, and a documented CVE history.OpenSSH is the lower-maturity-risk choice.
LicenseAGPL-3.0-or-later or commercial.BSD-style.License fit depends on distribution and proprietary integration needs.

No same-host comparative throughput benchmark exists. The table intentionally does not name a universal winner.

Release artifacts

Artifacts exist for multiple platforms; production security parity does not.

Use the v4.4.0 asset list and validation notes for the exact build and runtime coverage. A cross-compiled binary does not establish equivalent sandbox enforcement.

Linux x86_64

primary Linux target

Static-musl tarball plus Debian and RPM packages. The musl binaries avoid glibc dependencies and support per-user installation on GNU Guix. Fixed exports need a compatible Linux kernel and dedicated policy.

Linux/Android aarch64

cross-build targets

Use the architecture-specific Linux and Android assets listed in the release. Android builds target the Android runtime; Linux musl and Android binaries are not interchangeable. Runtime coverage is recorded separately.

Windows x86_64

do not expose server

Four PE32+ core executables are published without a C API DLL. They were not runtime-tested on Windows, and the Windows sandbox backend remains an unimplemented skeleton.

macOS x86_64 / arm64

no Developer ID

Mach-O archives lack Apple Developer ID signing and notarization. The arm64 library carries its linker-generated ad hoc signature; this is not Apple distribution approval. Runtime validation on macOS is separate.

FreeBSD 14 amd64

not runtime-tested

A valid package and FreeBSD-ABI ELF were produced, but not run on FreeBSD, and equivalent sandbox enforcement is not implemented.

Checksums

required

Verify downloaded files against SHA256SUMS-v4.4.0 before installation. Artifact names and their exact hashes are recorded in the release manifest.

Secure quickstart

From new keys to the first authenticated command.

Use absolute paths, mode 0600 for identity and trust files, an exact authorized_keys header, and an out-of-band server-fingerprint check. There is no automatic trust-on-first-use.

1 · Server identity and minimal configuration
# Generate the server identity
sudo install -d -m 0700 /etc/evelin
sudo evelin-keygen --out /etc/evelin/server.key
sudo chmod 0600 /etc/evelin/server.key

# /etc/evelin/authorized_keys
# evelin-authorized-keys v1
<64-hex-client-SHA256-fingerprint>  alice@laptop

# /etc/evelin/server.toml
bind = "0.0.0.0:2200"
identity_key = "/etc/evelin/server.key"
authorized_keys = "/etc/evelin/authorized_keys"
log_format = "json"
log_level = "info"
max_protocol_version = 2
max_frame_kib = 1024

[exec]
allow = ["uptime", "uname"]

[shell]
enable = true
command = "/bin/sh"

[filecopy]
roots = ["/srv/uploads", "/srv/data"]
allow_upload = true
allow_download = true
2 · Validate and start the server
# Parse policy and keys without binding TCP
sudo evelin-server \
  --config /etc/evelin/server.toml --check

# Start through the packaged service
sudo systemctl enable --now evelin-server
sudo systemctl status evelin-server

# Discover what the server presents
evelin-keyscan server.example.com:2200
# Verify that SHA-256 fingerprint out of band.
3 · Client identity and pin
mkdir -p ~/.config/evelin
evelin-keygen --out ~/.config/evelin/id.evelin
chmod 0600 ~/.config/evelin/id.evelin

# ~/.config/evelin/client.toml
server_addr = "server.example.com:2200"
identity_key = "/home/alice/.config/evelin/id.evelin"
server_fingerprint = "<64-hex-server-SHA256-fingerprint>"
log_format = "text"
log_level = "info"
max_protocol_version = 2
4 · Connect, shell, and copy
# Clean stdout by default
evelin-client --config ~/.config/evelin/client.toml exec uptime

# Interactive PTY
evelin-client --config ~/.config/evelin/client.toml shell

# Upload / download
evelin-client --config ~/.config/evelin/client.toml \
  cp ./local.txt remote:/srv/uploads/local.txt
evelin-client --config ~/.config/evelin/client.toml \
  cp remote:/srv/data/report.pdf ./report.pdf
Before exposing the port: retain OpenSSH as a recovery path, test an unauthorized client, test a wrong server pin, constrain every allow-list/root, verify Landlock and seccomp on the real host, and archive the exact release checksums.
libevelin and SDKs

A stable C ABI foundation with bindings of different maturity.

evelin-capi exposes ABI major 1, minor 0 and promises additive changes within v1; breaking changes require ABI v2 and an SONAME bump.

C ABI contract

Documented evln_* symbols, stable status codes, caller-owned buffers, library-owned handles, idempotent process initialization, and a documented threading model.

12 language directories

C, Rust, Python, Go, Node.js, Ruby, Java, Swift, .NET, Elixir, OCaml, and Guile. Rust is native; the others bind through the C surface.

Maturity is not uniform

Evaluate each binding’s README and tests. The current Swift directory is a packaging/module shim with no Swift source and should be treated as a skeleton, not a complete SDK.

Documentation and roadmap

Read the source of truth, not inherited marketing text.

The English documents are canonical when translations diverge. The roadmap has no dates or version promises and separates current code from future work.

Recent history

The v4 release history.

2026-06-09 · v4.0.0

Protocol v2 reaches GA

Opt-in transcript-bound capability negotiation, negotiated record-frame limits, downgrade tests, and STATED v2 formal models.

2026-06-10 · v4.1.0 / v4.1.1

Errata, strict parsing, and live validation

Four defects were published and fixed; the full binaries passed T1–T7, including v1 fallback, negative auth, 64 KiB frames, and byte-identical file copy.

2026-07-20 · v4.2.0

EN + pt-BR docs and hot-path cleanup

Governance/user guides, in-place receive decryption, reduced copy/allocation work, advisory updates, and 439 tests without a throughput claim.

2026-07-24 · v4.3.0

Quiet client and scp-shaped copy

Clean stdout, stderr-only logs, familiar verbosity, explicit progress percentage, 440 tests, and no wire/server change.

2026-09-06 · v4.4.0

Fixed exports and session lifecycle

Dedicated Linux PostgreSQL/Forgejo exports, durable validated publication, connection cleanup, locked release inputs and updated EN/pt-BR guides.

FAQ

Questions the deployment page should answer directly.

Is Evelin a drop-in replacement for SSH?

No. The workflows are intentionally familiar, but the wire protocol, identities, trust files, and ecosystem are different. Both endpoints must run Evelin.

Can I use it in production?

The project is self-deployed and Linux x86_64 release artifacts are production-validated by the maintainer. It still has no completed third-party cryptographic audit. Use it where you control both endpoints, can keep OpenSSH as recovery, and can evaluate the threat model yourself.

How are fingerprints computed?

SHA-256 of the encoded ML-DSA-87 public key, rendered as 64 lowercase hexadecimal characters. The v4.4.0 README and user guides use this same definition.

Does it support session resumption or 0-RTT?

Not as a live negotiated wire feature. Ticket machinery exists and is tested, but the extension path it depended on was never connected to the live handshake. True 0-RTT application data was explicitly rejected.

Why pure PQ instead of hybrid cryptography?

The fixed pure-PQ design reduces negotiation and uses category-5 parameters, but removes the classical X25519 fallback that protects OpenSSH’s hybrid KEX if ML-KEM fails. This is an explicit trade-off, not an unconditional advantage.

How do I report a vulnerability?

Email sac@securityops.co. Plaintext is acceptable for initial contact; the policy states a temporary PGP key will be supplied for exploit details. The default disclosure window is 90 days after acknowledgment.

What is the license?

AGPL-3.0-or-later or a commercial license. Review NOTICE for the project’s interpretation and contact SecurityOps for proprietary integration that cannot comply with AGPL obligations.