Introduction to Qpher
Qpher keeps documents under your rules after they leave your hands. These docs cover the engine — Qpher API — plus guides for Qpher Vault and Legacy.
Your private keys are generated and used only inside Qpher's isolated key service (KMS-Orchestrator) and are never exported.
One engine behind Vault, Legacy and the API
Vault, Legacy and the API share one isolated key service.
- Keys that stay in one place — Private keys are generated and used only inside Qpher's isolated key service. No API can export them.
- Hand-offs across organizations — Sharing outside your organization re-wraps the document's key for the recipient; the document itself is not re-encrypted.
- A portable, signed copy — A portable, tamper-evident encrypted copy; to open it again, come back to Qpher with the same email.
Qpher API exposes the key service: encrypt, wrap keys, sign and verify. Cross-organization re-wrap and the .qpher copy are app features, not API endpoints.
Three ways to use Qpher
Send documents outside your organization, set aside what your family should receive later, or build on the same engine.
- Qpher Vault — Encrypted on your iPhone, signed in your name, shared with any email address (the recipient opens it in Qpher Vault). Web version coming soon.
- Qpher Legacy — You encrypt what matters on your device today, choose who should receive it, and arm your policy.
- Qpher API — The engine behind Qpher Vault, over REST, with SDKs for Python, Node.js and Go. Start with a free API key.
What Qpher API does
Encrypt and Decrypt Data
Use Kyber768 (ML-KEM-768) to encapsulate a shared secret and encrypt arbitrary data. Qpher uses a hybrid KEM-DEM scheme internally: Kyber768 for key encapsulation, HKDF-SHA256 for key derivation, and AES-256-GCM for symmetric encryption. You get a single ciphertext blob back -- no need to manage the underlying cryptographic pipeline.
Sign and Verify Documents
Use Dilithium3 (ML-DSA-65) to create quantum-resistant digital signatures. Sign invoices, audit logs, API responses, contracts, or any data whose signature you want to verify later.
Manage PQC Keys
Generate, rotate and retire keys through the API; archive them, irreversibly, in Qpher Portal only. Private keys are used only inside the isolated key service.
Encrypt and sign may omit key_version: Qpher uses the active key and returns its version. Decrypt, verify, encapsulate and key wrap always need it.
Rotate Keys Without Downtime
Qpher supports seamless key rotation: a new key version is created and becomes active, while the previous version transitions to retired status. Retired keys can still decrypt and verify, so there is no disruption to in-flight data.
Algorithms
ML-KEM-768/1024 (FIPS 203), ML-DSA-65/87 (FIPS 204), SLH-DSA (FIPS 205), hybrid X-Wing and composite ECDSA P-256 + ML-DSA-65. Some need a paid plan.
The API's defaults, used when you omit algorithm:
| Property | Kyber768 | Dilithium3 |
|---|---|---|
| NIST Name | ML-KEM-768 | ML-DSA-65 |
| NIST Standard | FIPS 203 | FIPS 204 |
| Operation | Key Encapsulation (Encrypt/Decrypt) | Digital Signatures (Sign/Verify) |
| Security Level | NIST Level 3 (~AES-192) | NIST Level 3 (~AES-192) |
| Public Key Size | 1,184 bytes | 1,952 bytes |
| Private Key Size | 2,400 bytes | 4,032 bytes |
| Ciphertext Size | 1,088 bytes | 3,309 bytes |
| Shared Secret Size | 32 bytes | N/A |
| Latency Target | < 15ms crypto op (p95) | < 30ms crypto op (p95) |
NIST Security Level 3 provides protection roughly equivalent to AES-192. It offers a strong security margin against both classical and quantum attacks while keeping performance practical for real-time API use cases.
Qpher also supports hybrid PQC + classical mode — X-Wing (ML-KEM-768 + X25519) for encryption and Composite ML-DSA (ECDSA P-256 + ML-DSA-65) for signatures. See Hybrid Cryptography.
Why post-quantum
Encrypted data recorded today can be kept until a quantum computer can break the public-key step that protected it — the RSA or elliptic-curve key exchange. This is harvest now, decrypt later (HNDL). The symmetric layer is not the weak point: AES-256 is already quantum-safe.
In August 2024 NIST published the first post-quantum standards: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).
Architecture at a glance
API requests pass through the API Gateway, which authenticates your API key, applies rate limits and routes KEM, signature and key-management calls to the KMS-Orchestrator, Qpher's isolated key service. API requests pass a policy engine that fails closed. Qpher Vault and Qpher Legacy reach the same key service through their own backend, not through the API Gateway.
Next Steps
Ready to start? Head to the Quickstart Guide to make your first quantum-safe API call in under 5 minutes.
Want to understand the concepts first? Read about Core Concepts to learn about tenants, key versioning, and the hybrid encryption scheme.