Security Overview
QCrypton is built with a zero-dependency cryptographic design, PQC-first architecture, and defense-in-depth security model. All cryptographic primitives are implemented natively with no external crypto dependencies. Post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) are the default for all key exchange and digital signature operations. Multiple layers of protection — including HSM-backed key management, runtime threat scanning, noise collapse for false positive suppression, and autonomous remediation — provide comprehensive defense across the entire application lifecycle.
Compliance Frameworks
QCrypton maintains alignment with industry-leading compliance frameworks and security standards.
SOC 2 Type II
Security, availability, and confidentiality trust service criteria. Continuous monitoring with automated evidence collection.
ISO 27001
Information security management system with risk-based controls, asset management, and access control policies.
PCI-DSS
Payment card data protection with encryption at rest and in transit, key management, and access logging.
HIPAA
Protected health information safeguards including encryption, access controls, audit logging, and breach notification.
Federal Mandates
QCrypton aligns with key federal directives governing post-quantum cryptography migration and national cybersecurity posture.
- NSA CNSA 2.0 — Commercial National Security Algorithm Suite 2.0. Phased PQC migration: deprecate classical by 2030, disallow by 2035.
- OMB OMB M-23-02 — Memorandum on migrating to post-quantum cryptography. Federal agencies must inventory and prioritize cryptographic systems for migration.
- NSC NSM-10 — National Security Memorandum on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems.
- WH EO 14028 — Executive Order on Improving the Nation's Cybersecurity. Mandates zero-trust architecture, software supply chain security, and enhanced detection capabilities.
- NIST NIST IR 8547 — Transition to Post-Quantum Cryptography Standards. Provides guidance on deprecation timelines and algorithm selection for federal systems.
Encryption Standards
All cryptographic operations in QCrypton use NIST-standardized or peer-reviewed algorithms with no external dependencies.
| Standard | Algorithm | Purpose |
|---|---|---|
| FIPS 203 | ML-KEM (Kyber) | Key Exchange |
| FIPS 204 | ML-DSA (Dilithium) | Digital Signatures |
| FIPS 205 | SLH-DSA (SPHINCS+) | Stateless Signatures |
| FIPS 197 | AES-256-GCM | Symmetric Encryption |
| FIPS 202 | SHA3-256 | Hashing |
| RFC 9180 | HPKE | End-to-End Encryption |
Architecture
Enterprise-grade infrastructure designed for security, scalability, and multi-tenant isolation.
Platform Stats
Key operational metrics for the QCrypton platform.