Trust & Transparency

Trust Center

Transparency, compliance, and security posture at a glance. Review our encryption standards, compliance frameworks, federal mandate alignment, and platform architecture.

Security Overview

QCrypton is built with a zero-dependency cryptographic design, PQC-first architecture, and defense-in-depth security model. All cryptographic primitives are implemented natively with no external crypto dependencies. Post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) are the default for all key exchange and digital signature operations. Multiple layers of protection — including HSM-backed key management, runtime threat scanning, noise collapse for false positive suppression, and autonomous remediation — provide comprehensive defense across the entire application lifecycle.

38
Native Modules
13
Threat Scanners
44
Compliance Controls
200+
API Endpoints

Compliance Frameworks

QCrypton maintains alignment with industry-leading compliance frameworks and security standards.

SOC 2 Type II

Security, availability, and confidentiality trust service criteria. Continuous monitoring with automated evidence collection.

Implemented

ISO 27001

Information security management system with risk-based controls, asset management, and access control policies.

Implemented

PCI-DSS

Payment card data protection with encryption at rest and in transit, key management, and access logging.

Implemented

HIPAA

Protected health information safeguards including encryption, access controls, audit logging, and breach notification.

Implemented

Federal Mandates

QCrypton aligns with key federal directives governing post-quantum cryptography migration and national cybersecurity posture.

  • NSA CNSA 2.0 — Commercial National Security Algorithm Suite 2.0. Phased PQC migration: deprecate classical by 2030, disallow by 2035.
  • OMB OMB M-23-02 — Memorandum on migrating to post-quantum cryptography. Federal agencies must inventory and prioritize cryptographic systems for migration.
  • NSC NSM-10 — National Security Memorandum on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems.
  • WH EO 14028 — Executive Order on Improving the Nation's Cybersecurity. Mandates zero-trust architecture, software supply chain security, and enhanced detection capabilities.
  • NIST NIST IR 8547 — Transition to Post-Quantum Cryptography Standards. Provides guidance on deprecation timelines and algorithm selection for federal systems.

Encryption Standards

All cryptographic operations in QCrypton use NIST-standardized or peer-reviewed algorithms with no external dependencies.

Standard Algorithm Purpose
FIPS 203 ML-KEM (Kyber) Key Exchange
FIPS 204 ML-DSA (Dilithium) Digital Signatures
FIPS 205 SLH-DSA (SPHINCS+) Stateless Signatures
FIPS 197 AES-256-GCM Symmetric Encryption
FIPS 202 SHA3-256 Hashing
RFC 9180 HPKE End-to-End Encryption

Architecture

Enterprise-grade infrastructure designed for security, scalability, and multi-tenant isolation.

Deployment
Kubernetes
Database
PostgreSQL Aurora
Multi-Tenant
Yes
Zero Dependencies
Yes
RBAC Roles
4

Platform Stats

Key operational metrics for the QCrypton platform.

--
Total Scans Processed
--
Total Assets Monitored
--
Remediation Rate
--
Algorithms Covered
--
Scanner Types
--
Languages Supported