QNSI

NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) finalized August 2024. QNSI runs 87 PQC algorithms across 13 families. Migration window open. Read the migration brief →

Industry PQC migration target in878d 13h 50m 02s(Cloudflare and Google target 2029 · NIST transition deadline 2035 · CRQC date unknown)
FIPS 203 · ML-KEMFIPS 204 · ML-DSAFIPS 205 · SLH-DSACSA STAR Level 1

Quantum-nativesecurity infrastructure.

A full-stack post-quantum cryptography infrastructure platform for sensitive data, critical systems, and AI workloads. Globally available.

Operate keys, secrets, storage, audit, posture, governed PQC migration, and AI security from one enterprise infrastructure layer.

Post-quantum KMS
Encrypted vault
PQC-native storage
Vector search
Tamper-evident audit chain
Access control
Identity federation
Hardware enclaves
AI workload security
Security operations
Multi-cloud crypto-posture + transition planning
Compliance evidence

Operated as one infrastructure layer.

NIST FIPS-finalisedCloudVPCOn-premisesAir-gappedSovereign

Sized to your organisation's regulatory posture.

Built for governments, defence, financial institutions, critical infrastructure, enterprises, AI companies, sensitive-data platforms, and production trust teams.

Start with the decision you own

Concrete questions for accountable operators.

QNSI's use-case library connects a named operational decision to a product contribution, decision artifact, validation boundary, and primary-source context.

Platform architecture - Cloud-default flow

Your stack stays. QNSI becomes your trust layer.

QNSI sits between your applications, HSMs, and multi-cloud estate as a dedicated security infrastructure layer. Customer systems stay where they are; QNSI provides post-quantum key operations, vaulting, storage protection, policy enforcement, posture telemetry, and tamper-evident evidence across them. The diagram below renders the Cloud-default topology - one of five deployment models supported. Compare all five deployment topologies →

Your organisation

Apps · AI workloads

Whatever stack you operate today. TypeScript · Python · Go · Rust · JVM/Android · REST · CLI · MCP.

Customer HSMs

Capability-gated BYOHSM connectors: six PKCS#11 implementations and two REST backends. Each named device or service must pass live qualification before use.

Your multi-cloud estate

11 connector families: AWS · Azure · GCP · IBM · Oracle · Alibaba · Akamai · Cloudflare · Fastly · DigitalOcean · HashiCorp Vault.

↓ TLS boundary · JWT · PQC evidence required↕ PKCS#11 (private)↑ Read-only posture telemetry

QNSI Edge Gateway

Single ingress · transport-policy boundary · multi-tenant routing · authentication · entitlement enforcement · capability gates · rate limits.

Identity & Decision

Authentication · access control · policy decisions

Control

Tenancy · entitlements · platform APIs

Data

KMS · vault · storage · search

Evidence

Audit chain · evidence packs

Operations

Crypto inventory · AI orchestration · security monitoring · observability

Tamper-Evident Audit Ledger

Merkle-tree chain · ML-DSA-signed checkpoints · 90-day → 7-year retention tiers · WebSocket streaming for SIEM.

Compliance Evidence

Evidence packs mapped to SOC 2, HIPAA, GDPR, PCI DSS v4, ISO 27001, PDPA, and MAS TRM. Signed and exportable on demand.

Crypto-posture insights

Continuous discovery, NIST PQC readiness scoring, CycloneDX CBOM export across your multi-cloud estate.

Deployment topologies:

Cloud (default)VPCOn-premisesAir-gappedSovereign

Note:

Architecture is illustrative and current as of Q2 2026. Public SDKs and integration examples are independently verifiable at github.com/heossihq/qnsi-public.
Detailed implementation documentation is available under mutual NDA.

Third-party product names, logos, and trademarks are the property of their respective owners and are referenced solely for compatibility and integration documentation.
Their inclusion does not imply endorsement, partnership, or affiliation unless explicitly stated.

Security & assurance

Built for high-assurance environments.

NIST-finalised cryptographic standards, publicly verifiable CSA STAR assurance artifacts, and deployment topologies sized to regulated procurement frameworks.

FIPS 203 · ML-KEMFIPS 204 · ML-DSAFIPS 205 · SLH-DSACSA STAR Level 1PQC TLSTamper-evident audit evidenceSovereign · VPC · On-premises · Air-gapped

CSA STAR Level 1 - Publicly Verified

HEOSSI is listed in the CSA STAR Registry. Download the CAIQ self-assessment directly for your vendor-risk programme.

STAR L1CSA registry tier
CCMv4Control framework
CAIQ 4.1Self-assessment
PublicArtifact visibility
GAPlatform status

CAIQ Self-Assessment v4.1.0

Comprehensive documentation of security controls mapped across IaaS, PaaS, and SaaS layers - downloadable from the CSA STAR Registry for vendor due diligence.

Cloud Controls Matrix (CCMv4)

All control domains mapped to CSA CCM - the industry-accepted framework for cloud security assurance, audit, and third-party risk assessment.

Publicly Verifiable Artifacts

Assurance artifacts are publicly accessible for customer due diligence, regulatory submissions, and procurement review. No NDA required for Level 1 evidence.

QNSI Platform Coverage Scope

Transport compatibility, HSM-integrated KMS, secrets vault, encrypted storage (SSE-X), audit evidence, and CBOM export. Current execution status is shown separately.

Verify externallyHEOSSI Organization Profile →QNSI Service Listing + CAIQ →

Scope: QNSI cloud service as listed in CSA STAR. Controls vary by deployment model. STAR Level 1 = self-attestation; independent audit support available under enterprise agreement.

Operated by HEOSSI (PTE.) LTD., Singapore.

Public assurance sandbox · no signup · no API key

Run live post-quantum operations before onboarding.

Execute fresh FIPS 203, FIPS 204, and FIPS 205 post-quantum operations from a public verification surface. Inspect generated key material, ciphertexts, signatures, verification status, timing data, and integrity checks before creating an account.

The sandbox uses the same pinned implementation family as QNSI's public SDKs and produces new outputs per request. Results are not precomputed, replayed, or served as canned examples.

Operations covered

  • ML-KEM - key generation, encapsulation, decapsulation
  • ML-DSA - key generation, signing, verification
  • SLH-DSA - key generation, signing, verification

Evidence available

Live output · implementation version · algorithm identifiers · timing data · integrity status · conformance vectors · public SDK and integration source mirror · API route access.

Every request produces fresh verification output. Sandbox key material is generated for assurance testing only and must not be used in production systems. Conformance vectors verify deterministic implementation behavior against pinned library versions.

$ curl -s https://qnsi.heossi.com/api/sandbox/pqc-runtime | jq .

QNSI transition

From existing trust stack to QNSI-operated trust.

Already operating across cloud KMS, HSMs, Vault, certificates, secrets, storage, or legacy PKI? QNSI can assess your current trust stack, identify exposure, prioritise critical workloads, and guide transition into QNSI-operated security infrastructure. Every phase below maps to a real cloud-portal surface and a real backend service route.

Your existing trust stack

Cloud KMS (AWS · Azure · GCP · IBM · Oracle · Alibaba)HSMs (Thales Luna · Entrust nShield · CloudHSM · Azure HSM)HashiCorp Vault · Akamai · Cloudflare · Fastly · DigitalOceanExisting PKI · TLS endpoints · code-signing chainsSecret stores · encrypted storage · audit logs
  1. 01Discover

    Connect cloud accounts through 11 vendor connector families and deploy QNSI discovery agents into private networks. Inventory keys, secrets, certificates, TLS endpoints, hardware modules, and storage across 36 normalized source types.

  2. 02Map

    Score quantum exposure per asset, generate a CycloneDX CBOM, identify deprecated algorithms still in use, and map controls against the regulatory frameworks that apply to your organisation.

  3. 03Prioritise

    Define transition rules per workload class, draft compliance policies, and produce migration plans that sequence assets by data-lifetime risk, blast radius, and audit obligation.

  4. 04Transition

    Source defines dry-run and cutover modes plus BYOK and qualified BYOH coexistence. Complete migration effects and audit-chain coverage remain NOT VERIFIED and must be proven from returned reconciliation evidence.

  5. 05Operate

    Continuous drift-control validation, automated key-compromise response, attack-path analysis, and on-demand evidence packs for SOC 2 / HIPAA / GDPR / PCI / ISO / PDPA / MAS TRM audits.

QNSI-operated security infrastructure

Post-quantum KMS · encrypted vault · PQC-native storage · vector search · tamper-evident audit chain · access control · identity federation · hardware enclaves · AI workload security · multi-cloud crypto-posture · compliance evidence - operated across cloud, VPC, on-premises, air-gapped, and sovereign deployment models.

Read the migration journey →See the platform →

Every portal path above resolves in the QNSI cloud portal at cloud.qnsi.heossi.com. Backend services that implement the transition flow: crypto-inventory-service (23 routes), kms-service (BYOK · BYOH · rotation), and security-monitoring-service (continuous ops). Public SDKs and integration examples are independently verifiable at the public SDK and integration source mirror at github.com/heossihq/qnsi-public.

Technical integration

Integrate through standard runtimes and APIs.

QNSI is consumed through package managers and runtimes technical teams already use. One package per language, one shared OpenAPI surface, one activation call. Start on Free Forever, then carry the same integration path into cloud, VPC, sovereign, on-premises, or air-gapped deployment.

TypeScript / Node.js

pnpm add @heossihq/qnsi

Python

pip install qnsi

Go

go get github.com/heossihq/qnsi-public/sdks/go/qnsi

Rust

cargo add qnsi

JVM / Android (Kotlin + Java)

implementation("com.heossi:qnsi:0.4.0")

Same wire contracts

All runtimes call the same OpenAPI surface with identical request/response shapes, error codes, and algorithm identifiers.

One activation path

Self-service activation registers against the Free Forever production tier. Enterprise deployments use the same integration model.

No proprietary build pipeline

Standard package managers, registries, versioning, and CI/CD workflows. No bespoke compiler, vendored toolchain, or custom build system required.

Standards-based evaluation

REST · OpenAPI · JWT · API keys · public registries · SBOM-friendly releases · public source mirror

Full SDK reference →Public SDK source →

Self-service activation is free and instant. No credit card required. Same integration path carries into enterprise deployment.

Sectors served

Designed for high-consequence sectors.

QNSI supports organisations where cryptographic failure, exposed secrets, weak audit trails, or long-life data compromise can create operational, financial, regulatory, or national-security risk.

Government & sovereign systems

Protect citizen data, sovereign cloud workloads, inter-agency systems, classified-adjacent records, and long-life archives with post-quantum key management, encrypted storage, policy controls, and audit evidence.

Protects

  • ·citizen records
  • ·digital identity systems
  • ·inter-agency data sharing
  • ·long-retention public-sector archives
  • ·regulated procurement evidence

Deployment: sovereign · VPC · on-prem · air-gapped

Explore use cases →

Defence & military

Secure mission systems, operational data, command workflows, signing operations, and sensitive communications where confidentiality, integrity, and long-term cryptographic resilience are non-negotiable.

Protects

  • ·mission data protection
  • ·defence supply-chain trust
  • ·secure signing workflows
  • ·operational audit trails
  • ·long-life classified-adjacent data

Deployment: air-gapped · sovereign · on-prem

Explore use cases →

Banks & financial institutions

Protect payment systems, customer records, transaction evidence, signing workflows, vault secrets, and long-life regulated data with quantum-native security infrastructure.

Protects

  • ·payment infrastructure
  • ·customer PII
  • ·transaction signing
  • ·audit evidence
  • ·secrets and key governance
  • ·long-retention compliance data
Explore use cases →

Critical infrastructure

Protect energy, telecom, transport, water, healthcare, and industrial systems where cryptographic failure can create physical-world disruption, operational downtime, or national resilience risk.

Protects

  • ·OT/IT trust boundaries
  • ·infrastructure control-plane secrets
  • ·telemetry protection
  • ·vendor access controls
  • ·incident evidence

Deployment: sovereign · VPC · on-prem · air-gapped

Explore use cases →

Enterprises

Consolidate keys, secrets, storage protection, audit evidence, access control, and crypto-posture across business units, cloud estates, applications, and regulated data environments.

Protects

  • ·multi-cloud key governance
  • ·secrets sprawl
  • ·application encryption
  • ·access policy what-if analysis
  • ·internal audit evidence
  • ·vendor-risk response
Explore use cases →

AI companies

Protect model pipelines, embeddings, training data, inference workloads, prompt surfaces, model registries, and AI audit trails with trust controls built for high-value AI systems.

Protects

  • ·model registry protection
  • ·prompt-injection monitoring
  • ·training-data protection
  • ·vector search security
  • ·inference audit trails
  • ·confidential AI workloads
Explore use cases →

Sensitive-data platforms

Secure SaaS platforms, data rooms, healthcare systems, legal workflows, research platforms, and regulated applications that store, process, or exchange high-value sensitive data.

Protects

  • ·encrypted customer data
  • ·tenant isolation
  • ·regulated file storage
  • ·signed audit trails
  • ·API security
  • ·customer evidence packs
Explore use cases →

Healthcare & life sciences

Protect patient records, clinical workflows, research data, genomic datasets, regulated file exchange, and long-retention medical archives.

Protects

  • ·patient records
  • ·clinical systems
  • ·research data
  • ·regulated exchange
Explore use cases →

Telecom, cloud & digital infrastructure

Protect network trust, platform control planes, customer data, service credentials, edge workloads, and infrastructure audit evidence.

Protects

  • ·control-plane secrets
  • ·edge workloads
  • ·service credentials
  • ·customer data
Explore use cases →
Explore all 100 use cases →Read industry solution briefs

Organized for executives, security leaders, architects, engineers, risk teams, and procurement.

Live platform

Live infrastructure. Public service health.

QNSI Cloud exposes live production service health for its public AWS-hosted control plane. Private, sovereign, VPC, on-premises, and air-gapped deployments are monitored through deployment-specific status and observability endpoints.

ProductionEnvironment
ap-southeast-1AWS Singapore region
14 public endpointsHealth surface
Deployment-specificPrivate monitoring

Control plane

Authentication, tenancy, billing, entitlement checks, policy enforcement, and access-control services are monitored through the public status surface.

Data plane

KMS, vault, storage, search, audit, and AI orchestration services publish health independently so operational issues are visible by capability.

Dedicated deployments

VPC, sovereign, on-premises, and air-gapped deployments use dedicated status and observability endpoints separate from QNSI Cloud.

Public health endpoints show externally exposed QNSI Cloud service checks. Internal production services and dedicated deployments are monitored through private observability and deployment-specific status endpoints.

AWS and AWS region names are referenced for deployment-location clarity only and do not imply endorsement or affiliation.

QNSI Cloud Public Health Surface

Edge Gateway
online
Auth Service
online
Vault Service
online
Storage Service
online
Search Service
online
AI Orchestrator
online
Tenant Service
online
Billing Service
online
KMS Service
online
Observability Service
online
Audit Service
online
Access Control Service
online
Security Monitoring Service
online
Crypto Inventory Service
online

Ready to evaluate quantum-native security infrastructure?

Start with Free Forever, review public assurance evidence, or speak with an architect about sovereign, VPC, on-premises, and air-gapped deployments.

Talk to an architect →Start Free Forever →View live status →

Free Forever · developer plans from $149/month · enterprise + sovereign deployments custom-priced · see all plans →