Qpher

Standards we implement, audits we have not done

Qpher implements NIST FIPS 203, 204 and 205. Our cryptographic module has not been validated by NIST's CMVP, and no SOC 2 audit has been completed.

NIST PQC Standards Alignment

Qpher's post-quantum algorithms are the NIST-standardized ones: ML-KEM-768 (FIPS 203) for key encapsulation and ML-DSA-65 (FIPS 204) for signatures at NIST security category 3; ML-KEM-1024 and ML-DSA-87 at category 5, the parameter sets named in the NSA CNSA 2.0 suite; and SLH-DSA (FIPS 205) for hash-based signatures. They run on liboqs, the Open Quantum Safe library. Qpher's hybrid modes combine them with classical algorithms in constructions based on IETF drafts: X-Wing (X25519 + ML-KEM-768) and a composite ECDSA P-256 + ML-DSA-65 signature. Our cryptographic module has not been validated by NIST's CMVP.

SOC 2 audit

No SOC 2 audit has been completed. We will update this page when one is under way; the reports will be shared with customers under NDA once they exist.

GDPR

Qpher's Privacy Policy (/legal/privacy) describes the personal data we process, our role under the EU General Data Protection Regulation (GDPR) and how to exercise your rights; our Data Processing Agreement (/legal/dpa) is public for every customer. What deleting an account removes today is described on Data handling. The API's server-side mode receives plaintext over TLS, processes it in memory and does not store it.

CCPA

How California residents exercise their rights under the California Consumer Privacy Act (CCPA) is described in our Privacy Policy (/legal/privacy). Qpher does not sell personal information.

Ask Qpher AI