Compliance & Standards
Qpher implements NIST FIPS 203, 204 and 205. Our cryptographic module has not been validated by NIST's CMVP, and no SOC 2 audit has been completed.
This page covers the standards Qpher implements, SOC 2, GDPR, what deleting an account removes, where data is stored and what the audit log records. The Trust Center states the same facts.
NIST Post-Quantum Cryptography Standards
| Algorithm | Standard | NIST security category | Use in Qpher |
|---|---|---|---|
| ML-KEM-768 (Kyber768) | FIPS 203 | 3 | Key encapsulation (the API default) |
| ML-KEM-1024 | FIPS 203 | 5 | Key encapsulation |
| ML-DSA-65 (Dilithium3) | FIPS 204 | 3 | Digital signatures (the API default) |
| ML-DSA-87 | FIPS 204 | 5 | Digital signatures |
| SLH-DSA | FIPS 205 | 1, 3 or 5, by parameter set | Hash-based signatures |
ML-KEM-1024 and ML-DSA-87 are the parameter sets named in the NSA CNSA 2.0 suite. Qpher's hybrid modes combine these algorithms with classical ones in constructions based on IETF drafts: X-Wing (X25519 + ML-KEM-768) and a composite ECDSA P-256 + ML-DSA-65 signature. Qpher's post-quantum operations run on liboqs, the Open Quantum Safe project's open-source C library. Our cryptographic module has not been validated by NIST's CMVP.
NIST defines each category by the effort of an exhaustive key search on AES: category 1 on AES-128, category 3 on AES-192 and category 5 on AES-256. The API's default algorithms, ML-KEM-768 and ML-DSA-65, are category 3.
SOC 2
No SOC 2 audit has been completed. We will update the Trust Center when one is under way; the reports will be shared with customers under NDA once they exist.
How Qpher protects keys and requests is described in Security Architecture and on the Trust Center's Security page. For a procurement or security review, write to security@qpher.ai.
GDPR
Qpher's Privacy Policy describes the personal data we process, our role under the EU General Data Protection Regulation (GDPR) and how to exercise your rights; our Data Processing Agreement is public for every customer. The API's server-side mode receives plaintext over TLS, processes it in memory and does not store it.
What deleting an account removes
You can delete a Qpher Portal account in Settings → Account and a Qpher Vault account in the app (Settings → Delete account); an organization owner can delete the organization in Qpher Portal. A deleted account stops working at once and can be restored for 30 days. After that, a Qpher Vault account and its documents are permanently deleted, unless the account has an armed Legacy policy; Qpher Portal accounts and organizations stay disabled but are not yet permanently deleted. Deleting an account does not yet destroy its PQC private keys; they stay encrypted in the key service. Archiving a key in Qpher Portal deletes its private key file; encrypted copies of that file can remain in our backups.
Audit logs are retained for the life of your account and for 24 months after the account is deleted; accounts with an armed Legacy policy are exempt from deletion while the policy is armed.
Step-by-step guides: Deleting Your Account and Deleting Your Organization.
Data Residency
All customer data is stored in the United States; there is no EU or other regional data-residency option today.
Audit Logging
Qpher writes an audit log entry for the events below. Cryptographic operations are logged when they succeed. Deleting or restoring a Qpher Portal account or an organization is not recorded in this log today.
What Is Logged
| Event Type | Examples |
|---|---|
| Authentication | Sign-in and sign-out, token refresh, failed authentication, MFA enrollment and verification, step-up |
| Cryptographic operations | Encrypt, decrypt, encapsulate, decapsulate, key wrap and unwrap, sign, verify, sign-hash, verify-hash |
| Key management | Key generated, key rotated, key retired, key archived |
| Administrative | API key created, rotated or revoked; plan changed; team member invited or removed; MFA requirement turned on or off |
| Security events | Policy denial |
Log Properties
| Property | Value |
|---|---|
| Retention | Audit logs are retained for the life of your account and for 24 months after the account is deleted; accounts with an armed Legacy policy are exempt from deletion while the policy is armed. |
| Format | Structured JSON |
| Fields | id, event_type, result, service_name, endpoint, request_id, actor_id, details, created_at |
| Tamper evidence | Each organization's entries form a SHA-256 hash chain; since August 2026 a daily job signs a checkpoint of each chain |
| Access | Qpher Portal (Audit Logs) and the audit log API, on every paid Qpher Portal plan |
Fields whose names mark them as sensitive — private keys, plaintext, ciphertext, shared secrets, API keys, tokens,
passwords and other secrets — are replaced with [REDACTED] before an entry is written.
Security Contact
If you have questions about Qpher's compliance posture, need documentation for a procurement review, or want to report a security concern:
- Security team: security@qpher.ai
- Legal team: legal@qpher.ai
- Trust center: qpher.ai/trust