Compliance Roadmap

We publish the real status of every standard we are building against — not aspirational badges. Items marked “Roadmap” are not yet certified.

Last updated: 2026-04-18

Honest disclosure

QuantumSecure is currently a private / internal PKI. Certificates we issue are nottrusted by browsers or operating systems out of the box. Public-trust root inclusion is on the roadmap and requires a successful WebTrust for CAs audit. We do not currently hold SOC 2, ISO 27001, FIPS 140-2/3, Common Criteria, or WebTrust certifications.

Standards & Frameworks

NIST FIPS 204 (ML-DSA / Dilithium)

Implemented

Module-Lattice Digital Signature Algorithm. The default signature suite for QuantumSecure-issued certificates.

Signing is performed by liboqs (Open Quantum Safe). FIPS 140-3 module validation of the underlying cryptographic boundary is on the roadmap.

NIST FIPS 205 (SLH-DSA / SPHINCS+)

Implemented

Stateless hash-based signatures, available as an alternative algorithm for high-assurance use cases.

Available via the API and ACME finalize flow.

RFC 8555 (ACME)

Implemented

Automated Certificate Management Environment. Compatible with certbot and similar clients.

JWS verification and one-shot replay-nonce protection are enforced. Order/account state is persisted in PostgreSQL.

SOC 2 Type II

Roadmap

Independent attestation of security, availability, and confidentiality controls.

Not yet engaged with an auditor. We are not SOC 2 certified and will not claim to be until we hold a current report from an accredited firm.

ISO 27001

Roadmap

International information-security management system (ISMS) standard.

ISMS scoping in progress. We will publish the certificate and accreditation body once issued.

FIPS 140-2 / 140-3 (Cryptographic Module)

Roadmap

Validation of the cryptographic boundary that performs PQC signing and key storage.

Requires either a validated HSM partner or independent CMVP submission. Current builds use software liboqs.

WebTrust for CAs

Not Pursued

Audit framework required for inclusion in browser/OS public-trust root stores.

QuantumSecure issues certificates for private/internal PKI today. Public-trust root inclusion is not in scope until further notice.

Current Data & Security Practices

  • Personal data is processed under a documented privacy notice (see /privacy).
  • API authentication uses bcrypt-hashed passwords and short-lived JWTs.
  • Issued private keys are encrypted at rest with Fernet (AES-128-CBC + HMAC-SHA256).
  • Audit logs are retained for security and incident-response purposes.

Compliance Inquiries

For questions about our compliance posture, planned audits, or private-PKI deployment models:

Compliance Team: compliance@quantumsecure.app

Security Disclosures: security@quantumsecure.app