Skip to main content

Introduction to Qpher

Qpher keeps documents under your rules after they leave your hands. These docs cover the engine — Qpher API — plus guides for Qpher Vault and Legacy.

Quickstart · Why Qpher?

Your private keys are generated and used only inside Qpher's isolated key service (KMS-Orchestrator) and are never exported.


One engine behind Vault, Legacy and the API​

Vault, Legacy and the API share one isolated key service.

  • Keys that stay in one place — Private keys are generated and used only inside Qpher's isolated key service. No API can export them.
  • Hand-offs across organizations — Sharing outside your organization re-wraps the document's key for the recipient; the document itself is not re-encrypted.
  • A portable, signed copy — A portable, tamper-evident encrypted copy; to open it again, come back to Qpher with the same email.

Qpher API exposes the key service: encrypt, wrap keys, sign and verify. Cross-organization re-wrap and the .qpher copy are app features, not API endpoints.

Three ways to use Qpher​

Send documents outside your organization, set aside what your family should receive later, or build on the same engine.

  • Qpher Vault — Encrypted on your iPhone, signed in your name, shared with any email address (the recipient opens it in Qpher Vault). Web version coming soon.
  • Qpher Legacy — You encrypt what matters on your device today, choose who should receive it, and arm your policy.
  • Qpher API — The engine behind Qpher Vault, over REST, with SDKs for Python, Node.js and Go. Start with a free API key.

What Qpher API does​

Encrypt and Decrypt Data​

Use Kyber768 (ML-KEM-768) to encapsulate a shared secret and encrypt arbitrary data. Qpher uses a hybrid KEM-DEM scheme internally: Kyber768 for key encapsulation, HKDF-SHA256 for key derivation, and AES-256-GCM for symmetric encryption. You get a single ciphertext blob back -- no need to manage the underlying cryptographic pipeline.

Sign and Verify Documents​

Use Dilithium3 (ML-DSA-65) to create quantum-resistant digital signatures. Sign invoices, audit logs, API responses, contracts, or any data whose signature you want to verify later.

Manage PQC Keys​

Generate, rotate and retire keys through the API; archive them, irreversibly, in Qpher Portal only. Private keys are used only inside the isolated key service.

Encrypt and sign may omit key_version: Qpher uses the active key and returns its version. Decrypt, verify, encapsulate and key wrap always need it.

Rotate Keys Without Downtime​

Qpher supports seamless key rotation: a new key version is created and becomes active, while the previous version transitions to retired status. Retired keys can still decrypt and verify, so there is no disruption to in-flight data.


Algorithms​

ML-KEM-768/1024 (FIPS 203), ML-DSA-65/87 (FIPS 204), SLH-DSA (FIPS 205), hybrid X-Wing and composite ECDSA P-256 + ML-DSA-65. Some need a paid plan.

The API's defaults, used when you omit algorithm:

PropertyKyber768Dilithium3
NIST NameML-KEM-768ML-DSA-65
NIST StandardFIPS 203FIPS 204
OperationKey Encapsulation (Encrypt/Decrypt)Digital Signatures (Sign/Verify)
Security LevelNIST Level 3 (~AES-192)NIST Level 3 (~AES-192)
Public Key Size1,184 bytes1,952 bytes
Private Key Size2,400 bytes4,032 bytes
Ciphertext Size1,088 bytes3,309 bytes
Shared Secret Size32 bytesN/A
Latency Target< 15ms crypto op (p95)< 30ms crypto op (p95)
Why Level 3 by default?

NIST Security Level 3 provides protection roughly equivalent to AES-192. It offers a strong security margin against both classical and quantum attacks while keeping performance practical for real-time API use cases.

Hybrid PQC + classical mode

Qpher also supports hybrid PQC + classical mode — X-Wing (ML-KEM-768 + X25519) for encryption and Composite ML-DSA (ECDSA P-256 + ML-DSA-65) for signatures. See Hybrid Cryptography.


Why post-quantum​

Encrypted data recorded today can be kept until a quantum computer can break the public-key step that protected it — the RSA or elliptic-curve key exchange. This is harvest now, decrypt later (HNDL). The symmetric layer is not the weak point: AES-256 is already quantum-safe.

In August 2024 NIST published the first post-quantum standards: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).


Architecture at a glance​

API requests pass through the API Gateway, which authenticates your API key, applies rate limits and routes KEM, signature and key-management calls to the KMS-Orchestrator, Qpher's isolated key service. API requests pass a policy engine that fails closed. Qpher Vault and Qpher Legacy reach the same key service through their own backend, not through the API Gateway.


Next Steps​

Ready to start? Head to the Quickstart Guide to make your first quantum-safe API call in under 5 minutes.

Want to understand the concepts first? Read about Core Concepts to learn about tenants, key versioning, and the hybrid encryption scheme.