Trust Center
Check every claim on this page.
Posture in the present tense: what is true today, what is pending, and what unlocks each absent artifact.
Read the verdict unvarnished
QERYX maintains a consolidated evaluator dossier: a Security Target skeleton, a Protection-Profile conformance matrix, a tiered assurance-gap ledger, and an honest-claim ledger. Its verdict is quoted here exactly — including the part that says no.
The composite TOE is ready to enter formal evaluation and is not signable today. A reviewer’s signature can rest on this dossier once the code-closed cluster lands and the accredited lab attests — and not one moment before the lab attests.
That separation — what we close ourselves, what only a lab can issue — is the discipline of this whole page. The dossier text publishes at /trust/dossier after its publication ceremony; the load-bearing tables from it ship below, verbatim.
Check the posture, program by program
One wording per program. It ships unedited, everywhere.
CNSA 2.0 — asymmetric core conformant (ML-KEM-1024 + ML-DSA-87 at Category V; SHA-512 at or above the hash floor). Production AEAD today is ChaCha20-Poly1305 (RFC 8439), a documented deviation; the AES-256-GCM NSS suite is implemented and reserved as suite 0x0002, staged for rollout. Pre-evaluation checklist: 0 non-conformant findings, 3 documented deviations (NIAP ETR, 2026-05).
| Program | Status today | What is pending |
|---|---|---|
| NIAP / Common Criteria | READY WITH DEVIATIONS — not a completed EAL 4+ certification. Deviations are enumerated; formal evaluation in progress. | Formal evaluation at an accredited facility. |
| FIPS 140-3 | Algorithm-conformant; implemented via a library lineage holding FIPS 140-3 cert #4631; QERYX's own module is not yet CMVP-certified. | CMVP validation of the QERYX module boundary. |
| FIPS 203 / 204 | Algorithm-conformant constructions; known-answer tests pinned and run at every boot. | CAVP / ACVP validation for the shipping build. |
| Formal verification | Symbolic protocol models pass 5 of 5, with non-vacuous negative controls that fail when the model is sabotaged. | Model coverage grows with each protocol revision. |
| Entropy (SP 800-90B) | Multi-source entropy pool feeding the platform DRBG. | SP 800-90B health-test assessment on the primary path. |
The three documented deviations behind the CNSA count, on the record:
Deviation — ChaCha20-Poly1305 as production AEAD
The production AEAD is ChaCha20-Poly1305 (RFC 8439), verify-before-release and key-committing. The AES-256-GCM NSS suite is implemented and reserved as suite 0x0002; its rollout is staged as a new versioned, dual-accept format — no interop break.
Deviation — SLH-DSA fail-closed scaffolding
SLH-DSA support exists as fail-closed scaffolding: present in the tree, inert in production, documented for the Security Target rather than silently shipped.
Deviation — SHA-1 in TURN / TOTP legacy interop
SHA-1 survives only where legacy interop protocols require it — TURN message integrity and TOTP. It is never part of the message plane, the key schedule, or any QERYX-designed construction.
Before a Security Target signature — the code-closed cluster
The dossier enumerates what we close ourselves before entering formal evaluation: the metadata-layer remediation (sealed-sender wire-v2, rolling out), the AES-256-GCM lane and its strict byte-framing flip, claim-versus-code corrections, fail-open backend defaults, and a zeroization sweep. Every item ships as a versioned format — zero interop-breaking changes.
What only a lab can issue — never self-claimed
CMVP module validation, CAVP/ACVP algorithm certificates, the SP 800-90B entropy assessment, on-silicon leakage testing, and AVA_VAN-class penetration testing are issued by accredited facilities. Our review readies them; it cannot issue them, and this site never claims otherwise.
Hold us to the maximal claim
The strongest sentence each primitive has earned. Nothing rounds up.
| Primitive | The claim we make today |
|---|---|
| ML-KEM-1024 | FIPS 203-conformant construction — sizes pinned, implicit rejection — delegated to a FIPS-lineage backend (cert #4631); CAVP validation pending. |
| ML-DSA-87 | FIPS 204-conformant parameters, hedged signing, unique domain-separated contexts; strict byte-framing lands with a staged, versioned flip; ACVP pending. |
| Hybrid KEX | X25519 + ML-KEM-1024 through an SP 800-56C-shaped combiner, ML-KEM-first keying material, contributory check on the default path. Secure if either component holds. |
| ChaCha20-Poly1305 | RFC 8439 AEAD, verify-before-release, key-committing — a partitioning-oracle defense on by default. |
| AES-256-GCM | No production claim yet. Implemented and reserved as suite 0x0002; claimable after the staged rollout and CAVP — not before. |
| HKDF-SHA-512 | RFC 5869 / SP 800-56C Rev 2 extract-then-expand under frozen QERYX- domain separation; anchored by boot known-answer tests. |
| QSEED / QRNG | Multi-source entropy pool feeding the platform DRBG, with attested fallback — no silent substitution. SP 800-90B assessment on the primary path pending. |
| Q-Entangle-Bell | Every session key is bound to a CHSH-verified, Tsirelson-window-validated Bell-game transcript both peers seed and any auditor can verify — folded into the KDF above the X25519 + ML-KEM-1024 floor, never below it. Operator-signed transcripts from real quantum processors are the v2 lane, activating per deployment. |
| Key transparency (KTS) | 2-of-3 multi-witness quorum (verify-only today — operator equivocation is detected, not prevented) plus three external Ed25519 auditor slots that ship dormant, holding placeholder keys until auditors are onboarded; registry expansion release-gated by design. |
| Zero-knowledge relay | The relay is content-blind: message, channel, vault, and mail payloads are ciphertext-only bytes it never decrypts. Metadata claims stay qualified — see the storage row below. |
| Sealed sender | Sender-blinding and mailbox derivation are cryptographically confirmed; the metadata layer’s operator-reversibility is under active remediation (wire-v2, rolling out). We do not market operator-blindness until it lands. |
| Server storage | Group names, subjects, avatars, and all content are end-to-end encrypted; the relay holds only opaque routing identifiers; sender identifiers are stripped from the stored message row (sealed-sender v2), though the relay still authenticates the sender at send time. Undelivered messages queue with routing metadata under a published retention ladder. |
| Onion routing (QLEAP) | QLEAP is not in the v1 build; this row scopes the construction, never a shipped feature. As built: unlinkable against network observers and a compromised hop subset; operator-unlinkability arrives with multi-operator federation, and is not claimed before it. |
| Software updates | No update-authenticity claim. The build-attestation manifest format (ML-DSA-87, ctx QERYX-attest-v1) ships in the tree; the public trust-root registry is not yet claimed. |
| Deniable constructions | No deniability claim. The construction is present in the tree, not claimed. |
| Blind-signature payments | Unforgeability is classical (one-more-RSA-4096); unlinkability is information-theoretic and therefore survives any future quantum computer. Stated precisely — never rounded up to quantum-secure payments. |
Read the canary, and know how to read it
A canary only works if silence is loud. So here is the silence.
The last canary statement is dated 2026-04-18. The monthly reissue it promises has not followed. By the published semantics below, a canary not renewed by the 15th of the following month is a revocation signal — so until a fresh dual-signed statement publishes, read this canary as revoked and weigh the architecture on its own terms. The canary badge returns when the reissue ceremony completes and the monthly cadence resumes — then, and only then.
- Last statement
- 2026-04-18
- Promised cadence
- Monthly, renewed by the 15th of each following month.
- Signing scheme
- Dual signatures — an offline-held classical key plus a parallel ML-DSA-87 key; either failing to verify is itself a revocation.
- Clauses affirmed
- Five, independently revocable: no national-security letters; no FISA 702 directives; no gagged production or preservation orders; no compelled key disclosure, backdoor, weakened algorithm, or targeted build; no compelled silent companion-device link.
| Observation | Meaning |
|---|---|
| Fresh statement monthly | All five clauses present, both signatures verify — all clear. |
| No update by the 15th | Revocation signal. Assume compelled silence. This is the current state. |
| A clause disappears | Targeted revocation — a process in that category has been received. |
| Signature fails | Key compromise or impersonation. Do not trust the statement. |
| Log entry unresolvable | The statement may be presented off the append-only transparency log. Do not trust it. |
| Freshness proof stale | The embedded news fingerprint is older than 7 days — possible replay. Do not trust it. |
The canary is additional to the architecture, never a substitute for it. Even with every clause dropped, the relay could not produce plaintext — it never held any. What it does hold is on the record in the storage row above and the retention ladder on /messenger/privacy.
Take the artifact, or read the gate holding it
An artifact appears here signed and dated, or it appears as the gate that is holding it. Never as a dead link.
-
01 PUBLICATION PENDING
Evaluator dossier
The consolidated pre-evaluation dossier: Security Target skeleton, Protection-Profile conformance matrix, assurance-gap ledger, per-requirement verdicts, honest-claim ledger.
Unlocks: the publication-mode ruling (full text + digest, or summarized). Its verdict and load-bearing tables already ship on this page. The dossier page states its own absence.
-
02 V2.0 REISSUE PENDING
Procurement kit
Nine documents for a buyer’s cryptographer — conformance maps with file-and-line citations, threat model, attack surface, benchmarks, audit history, FAQ.
v1.0 (2026-05-01) is archived: it predates the dossier and carries one wording its own audit later corrected. Unlocks: the v2.0 reissue pinned to the current tree. Intake at /procurement.
-
03 REGENERATION PENDING
SBOM
A reproducible software bill of materials generated by a script in the tree, covering the Rust and client dependency graphs with license review.
The last generated SBOM (2026-04-30) is pinned to an older commit and unsigned — stated, not hidden. Unlocks: regeneration against the release tree plus a release-key signature.
-
04 TRUST ROOT NOT YET CLAIMED
Build attestation
The attestation manifest format ships in the tree (ML-DSA-87, ctx QERYX-attest-v1) and signs build outputs.
Unlocks: the public update-authenticity trust-root registry. Until it ships, no verified-update-chain claim appears anywhere on this site.
-
05 SUMMARIZED ABOVE
Pre-evaluation ETR
The 2026-05 evaluation technical report behind the CNSA wording: 0 non-conformant findings, 3 documented deviations — always cited together, never split.
The full report ships inside the procurement kit reissue.
-
06 DISCLOSURE RULING PENDING
Subprocessor register
A register that hides its entries is not a register. This site names no outside vendors anywhere — the register will be the one place that does.
Unlocks: the naming-exception ruling. It then lists every subprocessor, its role, and its jurisdiction — complete or not at all.
Name the twelve adversaries
The threat model is a published register: capability, mitigation, and the residual risk we did not delete.
A1 — State-actor cryptanalyst
Assumes full source access, a decades-long harvest, and a cryptanalytic budget. Mitigation: hybrid X25519 + ML-KEM-1024 with ML-DSA-87 identity signatures — a break of either key-agreement leg alone does not expose payloads.
A2 — Supply-chain implant
Pinned dependency set, a reproducible SBOM script, weekly dependency audit, and a build-attestation manifest format in the tree. Residual: a fresh dependency vulnerability can land between regenerations, and the update-authenticity trust root is not yet claimed — both stated in the artifact ledger above.
A3 — Radio-frequency denial
Spectrum-wide denial of cellular service. The transport layer fails over across six bearers; sustained denial degrades to text-only throughput. That degradation is documented behavior, not a hidden edge.
A4 — Interception at the network boundary
Every payload byte crossing the wire is end-to-end ciphertext, and the relay itself holds none of the keys. Onion routing is available per session. Residual: traffic shape — mitigated by the fixed padding-bucket ladder, and never claimed solved.
A5 — First-exchange man-in-the-middle
Out-of-band safety-number verification, a key-transparency Merkle log under the 2-of-3 verify-only witness quorum, and a pinned operator-key anchor close the first-contact window.
A6 — Malicious operator
An insider with full backend root reads ciphertext-only stores: no message bodies, no group names or membership plaintext, no session keys. Residual: timing and routing-identifier correlation at the metadata layer — under active remediation, and not marketed away.
A7 — Coerced operator
Forward secrecy plus signed destruction roots mean the relay cannot retroactively decrypt rotated sessions — there is nothing current to hand over. Residual: one escrow-shaped surface exists in the tree; it is disabled by build flag in customer builds and disclosed in the audit history.
A8 — Stolen device, stolen session
The ratchet heals at the next epoch — at most 100 messages1 — and long-term keys sit behind hardware-backed wrapping. Residual: an adversary with sustained device control reads until that next step; we say so.
A9 — Harvest now, decrypt later
Every long-lived ciphertext class — messages, pre-key bundles, group keys, vault items — is wrapped with ML-KEM-1024 today, ahead of the standards deadline it answers to.
A10 — Side channels
Constant-time equality on every secret comparison and a constant-time backend for the post-quantum suite. Residual: on-silicon leakage assessment is an accredited-lab step — our posture today is structural, and labeled structural.
A11 — Coerced user
A duress passphrase opens a decoy vault under a separate KDF salt. Residual, documented in source: a captor who knows the mechanism exists can demand both passphrases. No duress scheme deletes that fact; ours declines to pretend.
A12 — Physical tamper
The power-up known-answer battery refuses to operate from an error state, device attestation folds into the root key, and volatile zeroization forecloses cold-boot residue on freed key memory.
Trace every number to its method
Every stat shipped on this site resolves here: how it is computed, where it comes from, and what it does not cover.
- Measured
- Benchmarked on named hardware with the harness in the tree. Raw-run tables publish only when they can publish true.
- Counted from source
- Computed from the pinned tree while the page builds. A missing tree fails the build — a stale count cannot ship.
- Enforced constant
- A protocol or wire constant the code pins. The number is the constant, checkable at the named module.
- Observed behavior
- What the running system answers. Verifiable with any client, no trust in this page required.
- Negative capability
- A zero that states what the system cannot do — verified by reading the path that would have to exist.
- Design target
- A stated KPI for a product still in development. Explicitly not a measurement, and labeled on its page.
- Record
- A dated fact about our own artifacts — fleet counts, review scores, document counts — cited to the artifact.
- External figure
- Published third-party research, quoted approximately and at category level, for context only.
Homepage — the deadline algorithms
ships the deadline algorithms today Counted from source
ML-KEM-1024 and ML-DSA-87 run under pinned known-answer tests at
every boot (crypto-core/src/fips_module.rs); the
deadline is the published CNSA 2.0 transition timeline.
Scoped by the canonical wording in section 02: asymmetric core, with the AEAD deviation documented.
/messenger — heal window, padding ladder, erasure status
≤100 messages Enforced constant
The Q-Ratchet epoch length: a fresh ML-KEM-1024 encapsulation
heals the chain at most every 100 messages
(crypto-core/src/quadruple_ratchet.rs).
A worst-case window — rotation can land earlier on other triggers.
9 buckets · 256 B – 64 KiB Enforced constant
The nine-step text padding ladder TEXT_BUCKETS in
crypto-core/src/q_pad_ladder.rs. Real and decoy
envelopes share it.
Hides length within the ladder, not the existence of traffic.
HTTP 410 Observed behavior
The relay’s erased-message handler answers 410 Gone
(backend/src/handlers.rs) — it can no longer produce
the ciphertext.
410 speaks for the relay; device copies are erased by the client deletion path.
/messenger/calls — frame keys, re-key cadence, candidate paths
20 ms Enforced constant
One ChaCha20-Poly1305 key per 20 ms voice frame, derived in the
EVS ratchet (crypto-core/src/evs.rs).
~60 s Enforced constant
The mid-call ML-KEM-1024 re-key cadence in the call key schedule.
The tilde marks scheduler jitter, not uncertainty about the constant.
0 public-IP candidate paths Negative capability
Call media routes relay-only by construction; the path that would expose a peer address is not offered.
/messenger/groups — rotation, epoch, fan-out floor
1 ciphertext per member Enforced constant
Every Q-GroupCipher rotation issues one fresh ML-KEM-1024 ciphertext per member — no shared shortcut.
100 messages per epoch Enforced constant
The group post-quantum rotation epoch — the same law as the 1:1 ratchet window above.
8 members minimum fan-out Enforced constant
The padded fan-out floor in the group send path — the relay is never shown a smaller recipient set.
A floor the relay sees, not a member cap.
/messenger/privacy — purge grace, queue horizon, destruction roots
10 min Enforced constant
The delivered-row hard-purge grace default in the relay’s purge job.
During the grace, ciphertext still exists. The page says so in the same sentence as the number.
7 days Enforced constant
The offline-queue horizon for undelivered ciphertext, an environment-tunable relay setting; the stated value is the default.
ML-DSA-87 destruction roots Counted from source
Erasure roots are signed with FIPS 204 signatures you can verify against the published context string.
/qvault — Argon2id work factors
m = 512 MiB · t = 2 · p = 4 Enforced constant
Argon2Params::new(512 * 1024, 2, 4) in
crypto-core/src/argon2_password.rs — memory expressed
in KiB, so 512 MiB at 2 passes, 4 lanes (RFC 9106).
27× the floor Record
512 MiB against the 19 MiB Argon2id memory floor in the OWASP password-storage guidance, rounded down.
The guidance floor can move; the comparison is dated to this build.
1024 MiB-passes · 0 plaintext entries Negative capability
Net work is m × t = 512 MiB × 2. Vault items reach the relay sealed; storage is ciphertext-only bytes.
/qleap — circuit timings, overhead, fleet
3 ms · ~600 ns Measured
Full three-hop post-quantum circuit handshake and per-packet
three-layer onion wrap, measured on an A18-class device with the
crypto-core bench harness over the QLEAP modules
(crypto-core/src/qleap_pq.rs,
qleap_hybrid.rs), over repeated runs.
Device-scoped. Raw-run tables publish here when they can publish true; until then the method is stated and the number stays scoped to its hardware.
84 B per packet Enforced constant
The fixed layered framing — three onion layers of AEAD tag plus nonce material — computed from the wire format, not measured.
4 relays · 2 circuits Record
The fleet as listed in the ML-DSA-87-signed relay directory on the build date.
A deployment count, not a capability claim. Live status and latency stay absent until they can publish true.
/qmail · /qwallet — portal and threshold facts
one read · 4 states · 0 content keys Observed behavior
The burn-after-read portal consumes its key at first unlock; its state machine enumerates locked, decrypting, decrypted, invalid; the mail plane holds no content keys — the decryption happens on your device.
t-of-n · 1 signature · 0 custodial Negative capability
Threshold signing: no single device holds a spendable key, the verifier sees one aggregate signature, and QERYX holds no accounts, balances, or keys.
/wadjet — design targets, labeled as such
0 lines of C/C++ · ≤2 bits Design target
Wadjet is in development. The trust-boundary language target and the fingerprint-entropy KPI are stated design constraints, and the page labels them design targets in the same breath.
Nothing on the Wadjet page is a shipped measurement.
~70% of memory-safety CVEs External figure
Published analyses of memory-safety bug shares across major browser and systems codebases; quoted approximately, at category level, for context.
Not a QERYX measurement and not a claim about any named product.
/hydrasim — the self-capped score
94 / 100 Enforced constant
The app audits its own cellular privacy and refuses itself the
last six points while the server reports
rotationReal: false. The cap is the honesty
mechanism, in shipping code.
6 bearers · 0 invented coverage figures Counted from source
The shipped HYDRA transport registry
(crypto-core/src/hydra.rs); coverage numbers appear
only when a real coverage source exists — none do, so none appear.
/qaduceus · Underground — preview and surface facts
100% listed = shipped · 0 third-party AI services Record
Research-preview framing: the capability list on the page is the contract — everything listed ships in the preview build, and the preview’s network surface reaches no outside AI service.
1 auth layer · 0 bytes persisted · 9 buckets Enforced constant
QSEAL’s compartment gate is a single authentication layer;
the Shadow ID surface keeps no on-device persistence; Ghost
Serpent decoys share the same nine-bucket ladder as real traffic
(crypto-core/src/q_pad_ladder.rs).
Sovereign Stack — build-computed counts and ledger constants
crypto-core label / test / KAT counts Counted from source
The /stack/crypto-core page
recomputes its three headline counts from the tree on every build
— registered QERYX- domain separators in
labels.rs, test functions across the library, and the
boot known-answer battery. A missing tree fails the build.
The numbers move with the tree by design; they are correct for the build you are reading.
0 plaintext columns · 10 min · 5 min Enforced constant
The ledger’s write path is ciphertext-only by schema; hard-purge grace and timestamp coarsening are ledger constants — five minutes is the finest time the ledger will persist.
24 h · 5 min sweep · 6 AAD fields · 256 KB · 0 keys Enforced constant
Cache TTL classes and sweep cadence are configuration constants;
the storage layer binds six fields into every blob’s AAD,
chunks at 256 KiB (MEDIA_CHUNK_BYTES,
crypto-core/src/q_pad_ladder.rs), and never holds a
key.
/design + this page — bench and review records
626 µs · 3 hops · 32 B Measured
Bell-binding adds 626 µs once per epoch on the bench harness; hop count and the 32-byte HKDF-SHA-512 session key are protocol constants.
94/100 · 11 of 13 closed Record
The internal adversarial review of 2026-04-30: a scored checklist with findings tracked to closure in the audit history.
An internal review run to an external-reviewer standard — not an independent lab result. Independent evaluation is the pending step, stated in section 01.
0 non-conformant · 3 deviations Record
The pre-evaluation checklist counts from the named 2026-05 report — always shipped together with the deviation list, never split.
A number you cannot trace here is a defect. Report it through /contact and it is corrected or removed.
08The evaluator's questions — asked of this page itself
Interrogate this page.
Where is the full dossier?
Written, versioned, and pending its publication ceremony — the ruling on whether it ships as full text with a digest or as a summary. Its verdict and both load-bearing tables already ship on this page, verbatim. /trust/dossier states its own absence rather than pretending.
Why show a canary that reads as revoked?
Because the mechanism only works if silence is loud. A canary section that quietly disappeared when stale would train you to ignore exactly the signal it exists to send. The honest state is printed, with the semantics that make it legible.
Who has audited this?
Internal adversarial reviews on a scored checklist, symbolic protocol verification with negative controls, and a boot-time known-answer battery in shipping code. Independent, accredited evaluation is the pending step — that separation is stated in section 01 and never blurred.
What exactly does the relay hold?
Group names, subjects, avatars, and all content are end-to-end encrypted; the relay holds only opaque routing identifiers; sender identifiers are stripped from the stored message row (sealed-sender v2), though the relay still authenticates the sender at send time. Undelivered messages queue with routing metadata under the retention ladder published on /messenger/privacy.
Can we verify without trusting this page?
Yes — that is the point. Every claim in the procurement kit cites file and line in a pinned tree, the reproduction commands ship with it, and the boot battery re-proves the primitives on your own hardware. Start at /procurement.