xml-sec / measured, not assumed

Benchmark
Observatory.

Same documents. Four CLI configurations. Explicit measurement boundaries.

Read the boundary first

Comparisons include fresh process launch, key loading, filesystem I/O and the operation. Caches are warm; processes are not. They are not library-only algorithm timings. Security defaults differ; this corpus uses named caller-supplied keys, locally checked reference digests, RSA-2048/SHA-256 and AES-256-GCM.

RSS covers the complete process lifetime. Valgrind allocation and heap measurements are separate from latency, include native libraries, and exclude stacks and non-malloc memory mappings. Shared GitHub runners are noisy. Small sample counts do not establish reliable tail latency or superiority.

Loading validated measurements…

Latency summary: median of three repetition percentiles. CPU: median individual sample. RSS: maximum individual sample. Profiling measurements: one separate process per case. Counts and raw samples are downloadable, not inferred.

Environment, versions & provenance

Download raw comparison JSON · Builds and full measurement artifacts · Measurement contract

Not comparable in this chart

Standalone parse/C14N, retained-DOM operations, semantic projection, operation graph and policy phases remain xml-sec-only measurements. The CLIs do not expose equivalent boundaries. Multi-signature, nested-Manifest and external-reference workloads remain internal benchmarks until equivalent selection, resolver and trust semantics are demonstrated. No unsupported operation is timed as a successful one.