Encryption at Rest
Qpher encrypts every PQC private key before storing it. In production, each private key is encrypted by a key held in Google Cloud KMS.
How a private key is stored (production)
The Cloud KMS key never leaves Cloud KMS. To store a private key, the KMS-Orchestrator sends it to Cloud KMS over TLS and writes the ciphertext it gets back; to use the key, it sends the envelope to Cloud KMS, which returns the private key.
| Property | Value |
|---|---|
| KMS provider | Google Cloud KMS |
| Algorithm | Cloud KMS symmetric encryption (AES-256-GCM) |
| Key location | projects/qpher-production/locations/us-east1/keyRings/pqc-keys/cryptoKeys/private-key-kek |
| Stored file | {tenant}/{algorithm}/{version}.key.envelope in the KMS-Orchestrator's key store |
| Protection level | SOFTWARE (a Cloud KMS software key) |
AES-256-GCM is widely considered quantum-resistant for symmetric encryption. While Grover's algorithm could theoretically reduce the effective key strength to 128 bits, 128-bit security remains far beyond practical attack capabilities.
How a private key is used
When an operation needs a private key (decrypting a ciphertext or signing a message), the KMS-Orchestrator:
- Reads the key's record and checks its status: decrypting needs
activeorretired, signing needsactive;archivedkeys are refused. - Reads
{tenant}/{algorithm}/{version}.key.envelopefrom the key store. - Calls Cloud KMS Decrypt on the envelope.
- Performs the operation (decapsulate or sign) with the private key in memory.
- Returns only the result (a plaintext, shared secret, unwrapped key or signature).
Tamper detection
Cloud KMS encryption is authenticated: a modified envelope fails to decrypt, and the KMS-Orchestrator refuses the operation with an error.
Backups
Qpher maintains automated database backups with point-in-time recovery, giving a Recovery Point Objective (RPO) of well under one hour for database data. Cryptographic private-key material is replicated daily to a separate geographic region (US-WEST1), and object versioning provides a 30-day recovery window against accidental deletion. All backups are encrypted at rest (AES-256). Disaster recovery procedures are documented; periodic restoration rehearsals are planned as we onboard customers and have not yet been conducted. Backup copies made before this scheme was introduced in May 2026 are encrypted with AES-256-GCM under a key kept in Google Secret Manager.
Level 1 (development)
Local development uses Level 1: private keys are encrypted with AES-256-GCM under a key-encryption key read from the QPHER_KEY_ENCRYPTION_KEY environment variable, and stored as {version}.key files (a 12-byte IV followed by the ciphertext). Production used Level 1 until May 2026.