Everyone knows that the weak link is the specification. But this is a spurious argument, since, by definition, if you guarantee the implementation the only thing that's left exposed is the spec itself. At least you're reducing the attack surface
And you can put the specification in the manual of the software so the user knows what they're dealing with.
And you can put the specification in the manual of the software so the user knows what they're dealing with.