Skip to main content

Compliance & Standards

Qpher implements NIST FIPS 203, 204 and 205. Our cryptographic module has not been validated by NIST's CMVP, and no SOC 2 audit has been completed.

This page covers the standards Qpher implements, SOC 2, GDPR, what deleting an account removes, where data is stored and what the audit log records. The Trust Center states the same facts.

NIST Post-Quantum Cryptography Standards​

AlgorithmStandardNIST security categoryUse in Qpher
ML-KEM-768 (Kyber768)FIPS 2033Key encapsulation (the API default)
ML-KEM-1024FIPS 2035Key encapsulation
ML-DSA-65 (Dilithium3)FIPS 2043Digital signatures (the API default)
ML-DSA-87FIPS 2045Digital signatures
SLH-DSAFIPS 2051, 3 or 5, by parameter setHash-based signatures

ML-KEM-1024 and ML-DSA-87 are the parameter sets named in the NSA CNSA 2.0 suite. Qpher's hybrid modes combine these algorithms with classical ones in constructions based on IETF drafts: X-Wing (X25519 + ML-KEM-768) and a composite ECDSA P-256 + ML-DSA-65 signature. Qpher's post-quantum operations run on liboqs, the Open Quantum Safe project's open-source C library. Our cryptographic module has not been validated by NIST's CMVP.

NIST security categories

NIST defines each category by the effort of an exhaustive key search on AES: category 1 on AES-128, category 3 on AES-192 and category 5 on AES-256. The API's default algorithms, ML-KEM-768 and ML-DSA-65, are category 3.

SOC 2​

No SOC 2 audit has been completed. We will update the Trust Center when one is under way; the reports will be shared with customers under NDA once they exist.

How Qpher protects keys and requests is described in Security Architecture and on the Trust Center's Security page. For a procurement or security review, write to security@qpher.ai.

GDPR​

Qpher's Privacy Policy describes the personal data we process, our role under the EU General Data Protection Regulation (GDPR) and how to exercise your rights; our Data Processing Agreement is public for every customer. The API's server-side mode receives plaintext over TLS, processes it in memory and does not store it.

What deleting an account removes​

You can delete a Qpher Portal account in Settings → Account and a Qpher Vault account in the app (Settings → Delete account); an organization owner can delete the organization in Qpher Portal. A deleted account stops working at once and can be restored for 30 days. After that, a Qpher Vault account and its documents are permanently deleted, unless the account has an armed Legacy policy; Qpher Portal accounts and organizations stay disabled but are not yet permanently deleted. Deleting an account does not yet destroy its PQC private keys; they stay encrypted in the key service. Archiving a key in Qpher Portal deletes its private key file; encrypted copies of that file can remain in our backups.

Audit logs are retained for the life of your account and for 24 months after the account is deleted; accounts with an armed Legacy policy are exempt from deletion while the policy is armed.

Step-by-step guides: Deleting Your Account and Deleting Your Organization.

Data Residency​

All customer data is stored in the United States; there is no EU or other regional data-residency option today.

Audit Logging​

Qpher writes an audit log entry for the events below. Cryptographic operations are logged when they succeed. Deleting or restoring a Qpher Portal account or an organization is not recorded in this log today.

What Is Logged​

Event TypeExamples
AuthenticationSign-in and sign-out, token refresh, failed authentication, MFA enrollment and verification, step-up
Cryptographic operationsEncrypt, decrypt, encapsulate, decapsulate, key wrap and unwrap, sign, verify, sign-hash, verify-hash
Key managementKey generated, key rotated, key retired, key archived
AdministrativeAPI key created, rotated or revoked; plan changed; team member invited or removed; MFA requirement turned on or off
Security eventsPolicy denial

Log Properties​

PropertyValue
RetentionAudit logs are retained for the life of your account and for 24 months after the account is deleted; accounts with an armed Legacy policy are exempt from deletion while the policy is armed.
FormatStructured JSON
Fieldsid, event_type, result, service_name, endpoint, request_id, actor_id, details, created_at
Tamper evidenceEach organization's entries form a SHA-256 hash chain; since August 2026 a daily job signs a checkpoint of each chain
AccessQpher Portal (Audit Logs) and the audit log API, on every paid Qpher Portal plan
Redaction

Fields whose names mark them as sensitive — private keys, plaintext, ciphertext, shared secrets, API keys, tokens, passwords and other secrets — are replaced with [REDACTED] before an entry is written.

Security Contact​

If you have questions about Qpher's compliance posture, need documentation for a procurement review, or want to report a security concern: