QUANTUMSAFE PRODUCTS

A complete product ecosystem with evidence-backed maturity.

The portfolio connects cryptographic visibility, protected keys, application providers, trust services, data protection, verification and continuous operation. Product status is explicit so that architecture, sales and procurement teams do not confuse validation, availability, pilot and roadmap.

PRODUCT READINESS

Every Pilot and Research product now has a readiness passport, API contract, test corpus and evaluation pack.

The website is information-complete without overstating commercial maturity.

FLAGSHIP PRODUCT SUITE

Flagship products with demos, manuals and bounded maturity.

The portfolio now mirrors the complete customer journeys expected from specialist quantum-cybersecurity products while retaining Mobile-ID naming, evidence and trust-service strengths.

Pilot product

QuantumSafe Discovery Studio

Discover cryptographic exposure from packet captures, certificates, software dependencies and declared CBOM data—then turn findings into an owned migration backlog.

Controlled pilot

QuantumSafe Evidence Shield

Augment existing PDF, CMS, XML and software artifacts with versioned quantum-safe evidence while preserving the original business object and verification history.

Research / partner pilot

QuantumSafe QKD Bridge

Present QKD-derived keys through governed enterprise interfaces, synchronize approved key material with HSM/KMS controls and support PPK-based protected tunnels.

Research preview

QuantumSafe Circuit Studio

Build and execute small quantum circuits in the browser, inspect amplitudes and probabilities, and connect quantum-computing concepts to PQC migration decisions.

Controlled pilot

QuantumSafe Data Shield

Protect selected fields, files, messages and API payloads before they cross shared infrastructure, using versioned hybrid/PQC envelope profiles and protected backend key services.

Solution preview

QuantumSafe Asset Assurance

Support auditors in validating wallet formats, challenge signatures, activity evidence, counterparty exposure and proof-of-control records across approved blockchain connectors.

Research lab

QuantumSafe Web3 Migration Lab

Model the impact of post-quantum signatures on wallets, transactions, smart contracts, consensus interfaces and verification costs before committing to a chain migration design.

Pilot platform

QuantumSafe Certificate Fabric

Design, issue, validate and migrate classical, hybrid and PQC certificate profiles across CA, RA, VA, TSA, HSM and relying-party ecosystems.

Controlled pilot

Trusted SIC – QuantumSafe Remote Signing Gateway

Passkey-native multi-CA signing with signature activation, protected HSM/QSCD execution and an integrated ASiC Signer & Evidence Packager module.

PORTFOLIO CLASSIFICATION

Products, platform suites, services and research are separated.

Flagship product profiles provide commercial and technical entry points. ASiC signing and evidence packaging is governed as an integrated Trusted SIC module, not a separate top-level product.

1Validated product boundary
4Platform suites / controlled pilots
3Available professional services
1Research and partner track

Filter by maturity

01

PRODUCT PILLAR

Discover & Govern

Build cryptographic visibility, prioritize quantum risk and govern migration with evidence.

DISCAvailable

QuantumSafe Crypto Discovery

Locate vulnerable public-key cryptography across certificates, traffic, code, devices and trust services.

Key outcomes

  • Cryptographic asset inventory
  • Network and certificate discovery
  • Owner and dependency mapping

Integration boundary

Network captures, certificate stores, source/dependency scans and structured interviews.

Required evidence

Discovery report, asset register and scoped findings with traceable source evidence.

View detailed profile
CBOMAvailable

QuantumSafe CBOM & Inventory

Maintain a versioned cryptographic bill of materials for systems, applications and suppliers.

Key outcomes

  • Algorithm and key inventory
  • Certificate/profile registry
  • Supplier and product dependency view

Integration boundary

CSV/JSON import, assessment workflow and project-specific connectors.

Required evidence

Versioned CBOM, ownership records, review history and exportable audit package.

View detailed profile
RISKAvailable

Quantum Risk Prioritization

Rank migration work by data lifetime, signature lifetime, business value, exposure and dependency complexity.

Key outcomes

  • Quantum-risk heatmap
  • Migration wave proposal
  • Executive decision record

Integration boundary

Assessment workshops, data-classification input and dependency data from the inventory.

Required evidence

Scoring criteria, assumptions, approvals and a traceable prioritized backlog.

View detailed profile
CTRLSolution architecture

QuantumSafe Control Plane

Govern algorithm policy, migration waves, product versions, exceptions and evidence from one operating model.

Key outcomes

  • Algorithm policy control
  • Migration and exception workflow
  • Lifecycle and evidence dashboard

Integration boundary

PKI, HSM/KMS, application inventory, change management and observability systems.

Required evidence

Policy versions, approvals, exception records, control status and exportable evidence.

View detailed profile
02

PRODUCT PILLAR

Key & Hardware Trust

Protect keys in validated hardware and governed enterprise key-management architectures.

TKTValidated

Trusted Key Token

Portable hardware cryptographic module recorded by NIST CMVP Certificate #5331 at FIPS 140-3 Overall Level 3.

Key outcomes

  • Hardware-protected private keys
  • Strong identity and signing workflows
  • Familiar trust anchor for controlled migration

Integration boundary

Middleware-based integration; supported combinations are confirmed by model, firmware, OS and application version.

Required evidence

NIST CMVP #5331, public Security Policy and project-specific interoperability evidence.

View detailed profile
HSMAvailable

Trusted PQC HSM / QSCD Integration

Design and integrate protected key custody for CA, TSA, remote signing, code signing and enterprise services.

Key outcomes

  • High-assurance key custody
  • Quorum and ceremony controls
  • HA/DR and lifecycle architecture

Integration boundary

HSM, QSCD, SAM, PKCS#11, remote-signing services and approved operational procedures.

Required evidence

Architecture, ceremony records, configuration baseline, recovery tests and operational runbooks.

View detailed profile
KMSSolution architecture

QuantumSafe Key Management

Coordinate key generation, wrapping, rotation, versioning, tenant isolation and policy enforcement.

Key outcomes

  • Centralized key policy
  • Rotation and version control
  • HSM-backed API integration

Integration boundary

On-premises or private-cloud KMS, HSM, applications and approval workflows.

Required evidence

Key policy, access model, lifecycle logs, recovery tests and tenant-isolation validation.

View detailed profile
QKDResearch / partner track

QKD / QRNG Integration Track

Assess partner-based integration of quantum key distribution or quantum random sources where the use case justifies it.

Key outcomes

  • PQC-versus-QKD decision
  • Connector and trust-boundary design
  • Partner interoperability plan

Integration boundary

QKD networks, QRNG devices, HSM/KMS and standards-aligned connectors when available.

Required evidence

Research note, partner scope, threat model and pilot acceptance criteria.

View detailed profile
03

PRODUCT PILLAR

Providers, Middleware & SDK

Expose controlled cryptographic capabilities to Windows, Java, native, web and mobile applications.

CNGPilot

Trusted PQC Windows CNG/KSP Provider

Integrate classical, hybrid and approved project-specific PQC profiles into Windows applications through CNG/KSP.

Key outcomes

  • Native Windows key-provider integration
  • Hybrid signing experiments
  • Enterprise application pilot

Integration boundary

Windows 11 and supported Windows Server profiles, subject to release-specific validation.

Required evidence

Build/version matrix, signed test corpus, application compatibility and performance report.

View detailed profile
P11Pilot

Trusted PQC PKCS#11 Provider

Provide governed slot, object, key-generation and signature operations for native and enterprise middleware.

Key outcomes

  • Standardized middleware surface
  • HSM/token abstraction
  • Controlled mechanism exposure

Integration boundary

PKCS#11 applications, HSM/token adapters and OpenSSL or server-side integrations.

Required evidence

Mechanism matrix, threading/session tests, sample applications and compatibility report.

View detailed profile
JCAPilot

Trusted PQC Java JCA/JCE Provider

Support Java 21 application integration for keys, signatures, CMS and trust-service workflows.

Key outcomes

  • JCA/JCE integration
  • CMS and signing samples
  • Jakarta EE deployment profile

Integration boundary

Java 17/21, WildFly/Jakarta EE and approved library combinations.

Required evidence

Provider tests, JDK matrix, sample code, signed artifacts and known-limitations register.

View detailed profile
NETPilot

Trusted PQC .NET SDK

Enable C# applications to create, verify and exchange classical, hybrid or project-approved PQC artifacts.

Key outcomes

  • C# integration package
  • CMS/CAdES examples
  • Backend and desktop pilots

Integration boundary

.NET applications through approved native/provider bridges and project APIs.

Required evidence

NuGet/internal package record, test vectors, application matrix and exception log.

View detailed profile
SSLRoadmap

Trusted PQC OpenSSL 3 Provider

Planned provider surface for Linux, CLI, CMS and controlled TLS interoperability testing.

Key outcomes

  • OpenSSL 3 provider model
  • Containerized test profile
  • TLS/CMS pilot path

Integration boundary

Linux distributions, OpenSSL 3 applications and controlled test environments.

Required evidence

Roadmap approval, implementation tests and release-specific compatibility evidence before public support.

View detailed profile
MOBRoadmap

macOS CryptoTokenKit & Mobile SDK Track

Plan native Apple and mobile integration without overstating platform or release readiness.

Key outcomes

  • Target extension architecture
  • Keychain/mobile security model
  • Roadmap dependency register

Integration boundary

CryptoTokenKit, platform keystores, remote signing and biometric transaction confirmation where approved.

Required evidence

Architecture note, platform dependency review, prototype results and approved release gate.

View detailed profile
04

PRODUCT PILLAR

PKI & Digital Trust Services

Transform CA, RA, VA, TSA, signing and evidence services as one governed trust lifecycle.

PKIPilot

Trusted PQC PKI

Design and pilot classical, hybrid and target-state certificate services across Root CA, Issuing CA, RA and validation.

Key outcomes

  • Algorithm and certificate policy
  • Profile and OID strategy
  • Controlled issuance and path validation

Integration boundary

CA/RA, HSM, enrollment, OCSP/CRL, relying parties and project governance.

Required evidence

CP/CPS impact record, certificate samples, issuance/path-validation tests and cutover plan.

View detailed profile
TSAPilot

Trusted PQC TSA & Long-Term Evidence

Preserve trusted time, validation material and renewal evidence across algorithm and certificate lifecycles.

Key outcomes

  • Timestamp profile design
  • PAdES/CAdES/XAdES LT/LTA
  • Archive renewal policy

Integration boundary

TSA, OCSP/CRL, evidence stores, signing services and long-term verification.

Required evidence

Timestamp samples, validation reports, renewal tests and trusted-time control records.

View detailed profile
CODEPilot

QuantumSafe Code & Firmware Signing

Protect software, container and device release chains with governed signing and long-lived verification.

Key outcomes

  • Release approval workflow
  • Offline or protected signing keys
  • Firmware/secure-boot migration path

Integration boundary

CI/CD, artifact repositories, HSM, SBOM systems, device update and verification paths.

Required evidence

Signed release corpus, approval logs, key-rotation tests and verifier compatibility report.

View detailed profile
SICControlled Pilot

Trusted SIC – QuantumSafe Remote Signing Gateway

Passkey-native multi-CA signing, signature activation, protected HSM/QSCD execution and correlated evidence.

Key outcomes

  • One signing UX across CAs
  • WebAuthn-bound transaction approval
  • PQC transition and ASiC evidence

Integration boundary

RP, OIDC, WebAuthn, multi-CA connectors, HSM/QSCD/SAM, ASiC packaging, TSA, VA and evidence services.

View detailed profile
05

PRODUCT PILLAR

Data, Document & Channel Protection

Protect authenticity, integrity and long-lived confidentiality across documents, APIs, networks and archives.

DOCPilot

QuantumSafe Document Protection

Create and verify governed classical, hybrid and project-approved PQC document evidence.

Key outcomes

  • PDF/CMS/XML signing
  • Hybrid evidence container
  • Existing-record preservation plan

Integration boundary

GoPaperless, DMS/ERP, signing services, TSA/VA and verification components.

Required evidence

Signed test corpus, format profile, verifier matrix, LTV report and limitation record.

View detailed profile
NETSolution architecture

QuantumSafe TLS/mTLS & VPN

Design controlled hybrid key-establishment pilots for APIs, service meshes and protected network links.

Key outcomes

  • Hybrid handshake architecture
  • Fallback and downgrade policy
  • Network-performance model

Integration boundary

API gateways, reverse proxies, Java/.NET/OpenSSL clients, VPN gateways and service meshes.

Required evidence

Packet traces, cipher/profile matrix, latency/size benchmark and rollback criteria.

View detailed profile
WEBSolution architecture

QuantumSafe Browser & API Protection

Protect selected sensitive payloads from browser or client to an approved backend cryptographic boundary.

Key outcomes

  • Field/payload protection
  • Session and transaction binding
  • Developer integration pattern

Integration boundary

Web SDK, API gateway, KMS/HSM, identity and business-service endpoints.

Required evidence

Threat model, protocol profile, replay tests, sample integration and privacy review.

View detailed profile
DATARoadmap

QuantumSafe Email & Data-at-Rest

Plan long-lived confidentiality for email, files, databases, object storage, backups and archives.

Key outcomes

  • Data-class migration plan
  • Envelope/key-wrapping model
  • Rekey and recovery strategy

Integration boundary

Enterprise mail, object storage, backup, databases, KMS/HSM and data-governance systems.

Required evidence

Data-flow map, key hierarchy, recovery tests and approved retention/re-encryption plan.

View detailed profile
06

PRODUCT PILLAR

Verification, Assurance & Operations

Prove what works, for which version, under which scope—and keep that evidence current.

VERIFYSolution architecture

QuantumSafe Verification Portal

Inspect certificates, signatures, timestamps, chains, status evidence and algorithm identifiers.

Key outcomes

  • Human-readable verification
  • Machine-verifiable report
  • Interoperability diagnostics

Integration boundary

Certificates, PDF/CMS/XML, OCSP/CRL, timestamps and approved validation engines.

Required evidence

Signed verification report, engine/version record, policy result and limitation disclosure.

View detailed profile
LABAvailable

QuantumSafe Interoperability Lab

Test exact product, firmware, OS, middleware, application and relying-party combinations before rollout.

Key outcomes

  • Supported-version matrix
  • Signed sample corpus
  • Known-issue and exception register

Integration boundary

Customer applications, tokens/HSMs, providers, verifiers and test automation.

Required evidence

Reproducible test plan, pass/fail evidence, environment manifest and remediation decisions.

View detailed profile
PERFAvailable

QuantumSafe Benchmark Center

Measure latency, throughput, object size, memory and network impact for classical, hybrid and PQC profiles.

Key outcomes

  • P50/P95/P99 metrics
  • Size and capacity model
  • Deployment sizing recommendation

Integration boundary

Token, HSM, server, client, network and document test environments.

Required evidence

Test methodology, environment manifest, raw results, charts and decision summary.

View detailed profile
EVIDSolution architecture

QuantumSafe Evidence Repository

Preserve approved test artifacts, claims, versions, reports and control evidence for audit and procurement.

Key outcomes

  • Evidence catalogue
  • Claim-to-source traceability
  • Release and procurement package

Integration boundary

Control plane, CI/CD, PKI, validation labs, ticketing and document repositories.

Required evidence

Immutable or controlled evidence records with ownership, approval, version and review dates.

View detailed profile
OPSAvailable

Managed Crypto-Agility

Operate standards watch, lifecycle reviews, exception handling, evidence refresh and migration backlog governance.

Key outcomes

  • Periodic posture review
  • Algorithm/product lifecycle watch
  • Owned improvement backlog

Integration boundary

Customer governance, inventory, PKI, product lifecycle and security operations.

Required evidence

Review minutes, updated matrices, exceptions, action ownership and management reporting.

View detailed profile
07

PRODUCT PILLAR

Academy, Research & Ecosystem

Equip executives, architects and developers with the knowledge and test assets required for responsible adoption.

EDUAvailable

QuantumSafe Academy

Role-based learning for executive decisions, architecture, implementation and operational governance.

Key outcomes

  • Executive briefing
  • Architect deep dive
  • Developer and operator workshops

Integration boundary

Training portal, live workshops, labs and organization-specific curriculum.

Required evidence

Course version, learning objectives, lab assets and participant completion record.

View detailed profile
R&DAvailable

QuantumSafe Research & Publications

Publish responsible technical work on hybrid signatures, providers, PKI profiles, evidence preservation and hardware trust.

Key outcomes

  • Whitepapers and benchmarks
  • Reference profiles
  • Conference and webinar material

Integration boundary

Product engineering, customer pilots, standards monitoring and academic/industry collaboration.

Required evidence

Named authors, versioned publications, source references and reproducible technical appendices.

View detailed profile
PARTSolution architecture

Technology & Validation Ecosystem

Classify every relationship as validation, tested compatibility, integration, research or commercial collaboration.

Key outcomes

  • Clear partner role
  • Tested integration scope
  • No ambiguous logo claims

Integration boundary

Labs, HSM/QSCD vendors, CA/TSPs, cloud/platform providers, integrators and research institutions.

Required evidence

Approved partner statement, scope, date, product/version and permission to publish.

View detailed profile

STATUS GOVERNANCE

A maturity model procurement can understand.

Status describes commercial and technical readiness; it is not a substitute for algorithm or module validation. Exact product, firmware, provider, operating-system and application combinations remain subject to an approved release or project matrix.

VALI

Validated

Validated by an identified external program within a precise scope.

AVAI

Available

Commercial or professional service capability available under an approved scope.

PILO

Pilot

Controlled project use requiring version, evidence and acceptance gates.

ARCH

Solution architecture

Defined solution architecture; productization and release evidence are not yet complete.

ROAD

Roadmap

Approved or proposed development direction; no production commitment is implied.

RESE

Research / partner track

Exploratory or partner-dependent capability, not a standard commercial product.