INVITE ONLY
OBSERVATORY

01 Publications

Read the protocol in the open.

Every security claim on this site resolves to a publication — versioned, dated, and cited to the source that ships it.

Take the index in order.

Each row carries its version, the date it was last revised, and the primitives it is responsible for. Open one and the paper states the same four values in its own header — the ledger and the document read from a single registry, so they cannot disagree.

12 PAPERS
14 REVISIONS
12 PRIMITIVES
12 SOURCE ARTIFACTS
2026-06-01 LAST REVISION

Start here

  1. §01 white-paper v0.1 revised Entanglement-Anchored Key Agreement Q-Entangle-Witness: folding Bell-certified public randomness — from a loophole-free Bell-test beacon or an operator-run CHSH device-behaviour witness — into session-key input material as an additive public co-factor strictly under a hybrid X25519 + ML-KEM-1024 secret. Auditable freshness that can never weaken the post-quantum floor, with the honest limits stated in full. X25519ML-KEM-1024ML-DSA-87HKDF-SHA-512
  2. §09 protocol-spec v1.0 revised Q-Ratchet: Four Parallel Ratchets The per-message key ratchet behind every QERYX session: a classical X25519 ratchet every message, an ML-KEM-1024 ratchet every epoch, a symmetric HKDF chain every message, and QRNG entropy injection every few messages. Forward secrecy and post-compromise security arguments, header AAD binding, and skipped-key bounds. X25519ML-KEM-1024HKDF-SHA-512ChaCha20-Poly1305
  3. §11 protocol-spec v1.0 revised The QERYX Protocol: Overview and Design Goals The tier-1 summary of the QERYX cryptographic protocol specification (Entangled v1): what ships, the one-paragraph threat model, seven design goals, and the map of per-chapter publications. Every load-bearing claim in the specification cites a path and line in the shipping source. ML-KEM-1024ML-DSA-87X25519ChaCha20-Poly1305
  4. §12 security-analysis v1.0 revised The QERYX Threat Model The adversary QERYX is built against: full active network capability, a coercible server operator, and a cryptographically-relevant quantum computer. Twenty-one attack classes with their mitigations and residual risks, the defense-in-depth table, and — stated plainly — what QERYX cannot promise. ML-KEM-1024ML-DSA-87X25519

Read the whole record.

Every publication, newest revision first

  1. §01 white-paper v0.1 published revised Entanglement-Anchored Key Agreement Q-Entangle-Witness: folding Bell-certified public randomness — from a loophole-free Bell-test beacon or an operator-run CHSH device-behaviour witness — into session-key input material as an additive public co-factor strictly under a hybrid X25519 + ML-KEM-1024 secret. Auditable freshness that can never weaken the post-quantum floor, with the honest limits stated in full. X25519ML-KEM-1024ML-DSA-87HKDF-SHA-512
  2. §02 conformance v1.2 published revised CNSA 2.0 and FIPS Conformance Posture Every QERYX primitive mapped to its CNSA 2.0 line item and FIPS standard, with honest per-line markers — COMPLIANT, PARTIAL, DEVIATES — and the justification for each deviation. Includes the FIPS 140-3 module lifecycle, the self-test KAT set, and the two-build model for NSS-targeted deployments. ML-KEM-1024ML-DSA-87AES-256-GCMSHA-512
  3. §03 protocol-spec v1.0 published revised Cryptographic Primitives and Parameter Sets The master table of every primitive QERYX instantiates — parameter sets, byte sizes, backend pinning, and the source citation for each. Covers the FIPS 204 §5.2 context-framing discipline, the labeled-HKDF catalog, Argon2id at m=512 MiB, and what is deliberately absent from the build. ML-KEM-1024ML-DSA-87X25519ChaCha20-Poly1305
  4. §04 protocol-spec v1.0 published revised FSOR: Cryptographic Erasure of Server-Held Ciphertext Forward-Secrecy Output Reset wraps every server-stored ciphertext in a per-conversation envelope whose key lives only in process memory. On destroy, the epoch advances and the old key is zeroized — bytes left in any backup, WAL, or replica become envelope-locked under a key that no longer exists. With the honest limits stated. HKDF-SHA-512ChaCha20-Poly1305ML-DSA-87SHA-512
  5. §05 protocol-spec v1.0 published revised Group Messaging: Sender Keys with Post-Quantum Rotation One sender key per member, ratcheted forward every message, re-encapsulated to the current member set via ML-KEM-1024 every 100 messages and on every membership change. Every group message individually signed under ML-DSA-87. Removed members cannot decrypt what comes next; new joiners cannot decrypt what came before. ML-KEM-1024ML-DSA-87ChaCha20-Poly1305HKDF-SHA-512
  6. §06 protocol-spec v1.0 published revised Identity and Key Transparency: Serpent ID, Profile ID, and the KTS Log The two-layer identity model — a device-only 256-bit Serpent ID and a public BLAKE3-derived Profile ID — plus the Key Transparency System: an append-only Merkle log with ML-DSA-87 Signed Tree Heads, consistency proofs, TOFU operator pinning, and out-of-band gossip that makes operator equivocation detectable. BLAKE3ML-DSA-87SHA-512HMAC-SHA-256
  7. §07 security-analysis v1.0 published revised Known Limitations and Open Work The honesty layer of the specification: every gap between the spec and the shipping snapshot, enumerated — audit items not yet in code, items that require user action, cadence trade-offs, optional features off by default, open production symptoms, and the v1.1 roadmap. Where spec and code diverge, code is canonical. ML-DSA-87Argon2idHKDF-SHA-512
  8. §08 protocol-spec v1.0 published revised Message AEAD, Frame Header v2, and the Padding Ladder The on-the-wire shape of one encrypted message: plaintext snapped to one of nine fixed buckets with crypto-random fill, ChaCha20-Poly1305 with the full Q-Ratchet header bound as AAD, and the Frame Header v2 outer envelope that makes peer re-registration detectable before decryption fails. ChaCha20-Poly1305HKDF-SHA-512
  9. §09 protocol-spec v1.0 published revised Q-Ratchet: Four Parallel Ratchets The per-message key ratchet behind every QERYX session: a classical X25519 ratchet every message, an ML-KEM-1024 ratchet every epoch, a symmetric HKDF chain every message, and QRNG entropy injection every few messages. Forward secrecy and post-compromise security arguments, header AAD binding, and skipped-key bounds. X25519ML-KEM-1024HKDF-SHA-512ChaCha20-Poly1305
  10. §10 protocol-spec v1.0 published revised The Hybrid Handshake: SP 800-227 Combiner and Entangled Session v1 Two interlocking handshake layers: a NIST SP 800-227 hybrid KEM combiner over X25519 + ML-KEM-1024, and Entangled Session v1 — the mutual-authentication handshake that mixes both peers’ QRNG contributions, signs each leg under a distinct FIPS 204 context, and echoes nonces in constant time. X25519ML-KEM-1024ML-DSA-87HKDF-SHA-512
  11. §11 protocol-spec v1.0 published revised The QERYX Protocol: Overview and Design Goals The tier-1 summary of the QERYX cryptographic protocol specification (Entangled v1): what ships, the one-paragraph threat model, seven design goals, and the map of per-chapter publications. Every load-bearing claim in the specification cites a path and line in the shipping source. ML-KEM-1024ML-DSA-87X25519ChaCha20-Poly1305
  12. §12 security-analysis v1.0 published revised The QERYX Threat Model The adversary QERYX is built against: full active network capability, a coercible server operator, and a cryptographically-relevant quantum computer. Twenty-one attack classes with their mitigations and residual risks, the defense-in-depth table, and — stated plainly — what QERYX cannot promise. ML-KEM-1024ML-DSA-87X25519

A paper on this ledger is a distillation of an in-repo specification chapter, not a substitute for it. Where the shipped code has moved past the snapshot the paper was cut from, the paper says so in its own body rather than in a footnote here.