INVITE ONLY
OBSERVATORY

9.0 QSeal

Post-quantum authentication for the deepest work.

QSEAL SHADOW TIER

Sealed communication above the messenger floor: post-quantum authentication, stream sealing, and verification built for work that cannot surface. Unlocked with Shadow.

Press seal. Watch the data stop moving.

Vault open. The cipher rain falls.

Every falling glyph is real ciphertext — an authored demo vault sealed with ChaCha20-Poly1305 (RFC 8439) when this page was built. The demo key ships beside the ciphertext on purpose: open it and check.

A vault at rest. The rain is real ciphertext from an authored demo vault — press [ SEAL ] and every glyph freezes into its outline. It shows the state change, not your data.

Read the seal, layer by layer.

9.0 / A

The authentication layer

Q-SEAL — Quantum-Secure Entangled Authentication Layer: a post-quantum authentication compartment for the Shadow tier. You authenticate, you enter, and you work in a space the rest of the app cannot see.

Gate
Biometric, on-device — the key never leaves your phone to answer
Primitives
ML-KEM-1024 + ML-DSA-87 — the same crypto-core beneath every tier
Adds
Compartmentalization, not new math

“Quantum” in the name is the post-quantum floor — ML-KEM-1024 (FIPS 203) and ML-DSA-87 (FIPS 204). QSeal builds a compartment above that floor; it does not change the ciphers you already have.

9.0 / B

The sealed compartment

Behind the layer sits a completely separate encrypted space, reachable only after Q-SEAL authentication — invisible to the regular app.

Entry
Q-SEAL authentication, every time — verification before entry
Visibility
No trace in the standard surfaces
Separation
Storage, messaging, and media sealed apart from the rest of the app

11

authentication layer stands between the app and the compartment

9.0 / C

Stream sealing

Media crosses into the compartment as QSEAL-Stream: a chunked post-quantum envelope with per-chunk integrity and one signed manifest covering the whole stream.

Envelope
Chunked — ChaCha20-Poly1305 per chunk
Manifest
One ML-DSA-87 (FIPS 204) signature over the whole stream
Verify
Tamper is rejected before a single chunk opens

The compartment is a capability, not a stronger cipher. Every tier already has maximum crypto.

The Connection Floor

Set it against a folder and a PIN.

Category columns only — never named products
QERYX QSeal Standard app compartments No compartment
Real workloads
Casual device inspection Compartment invisible without QSeal authentication Folders visible Everything visible
Compartment entry Post-quantum authentication + biometric gate PIN reuse Not included
Media in the compartment QSEAL-Stream sealed, signed manifests App-level encryption Camera roll
Server view Sealed blobs, indistinguishable Sealed blobs, indistinguishable Plaintext backups common

Read the access terms once, plainly.

QSeal is part of Shadow, alongside Shadow ID and Ghost Serpent. This build carries no purchase surface and no price: the Underground compartment opens after v1, and the tier ladder is set out on pricing.

Every existing feature runs at maximum capability for everyone. Higher tiers unlock new capabilities — apps, tools, modes — and never upgrade a primitive you already had.

Request an invite

Ask what the compartment does not do.

What is QSeal in one sentence?

A post-quantum authentication layer that opens a sealed compartment above the standard messenger floor.

Work that cannot surface: its storage, messaging, and media are sealed separately from the rest of the app.

The compartment is a capability, not a stronger cipher — every tier already has maximum crypto. Shadow unlocks the tool.

The same as everywhere: sealed blobs. The compartment adds separation on your device, not a new server surface.

Nothing. This build carries no purchase surface and no price. QSeal is part of Shadow, and the tier ladder is set out on pricing.

Request an invite Read the spec