QNSI

HEOSSI · Singapore

About QNSI

QNSI is the flagship post-quantum cryptography platform from HEOSSI - verifiable PQC infrastructure for AI, data, and mission-critical systems.

QNSI is built and operated by HEOSSI. For the company behind QNSI - corporate, legal, and registration details - see heossi.com.

90PQC algorithms · 14 families
2independent providers, cross-verified
100%NIST ACVP (noble 435/435 · liboqs 240/240)
Freeto start - full 5-language SDK family

Why QNSI exists

Standards on paper aren't the same as verifiable deployment

"Harvest now, decrypt later" is no longer a thought experiment. Adversaries are already collecting encrypted traffic they intend to break with cryptanalytically relevant quantum computers later this decade. Every long-lived secret encrypted with RSA, ECDH, or ECDSA today is on a clock - and the regulated industries that hold the most sensitive long-lived data (finance, defense, healthcare, government) have the least appetite for migration improvisation.

NIST finalised the first post-quantum standards in August 2024 - FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) - with FIPS 206 (FN-DSA) and HQC still in draft. The U.S. CNSA 2.0 suite sets a federal migration window (new National Security Systems from 2027, full transition 2030-2033); U.S. Executive Order 14412 (June 2026) adds 2030/2031 PQC deadlines for federal High-Value Assets, and the EU's post-quantum roadmap targets high-risk financial systems by 2030. The work is no longer "discover PQC"; it is "deploy PQC verifiably, with evidence regulators and auditors can check."

That gap - between standards on paper and verifiable deployment - is QNSI.

One platform, four surfaces

What QNSI is

A full managed post-quantum platform - not a single library or a point tool.

KMS · Vault · Storage

Quantum-safe KMS, vault, and SSE-X storage

ML-KEM, ML-DSA, Falcon, and SLH-DSA across 14 algorithm families, with dual-provider cross-verification (liboqs + noble) and enforceable per-tenant crypto-policy tiers.

Hardware-backed keys

HSM, BYOH, and confidential compute

8 capability-gated HSM connector implementations, customer-controlled custody workflows, and confidential-compute connectors for AI workload isolation. Named hardware requires live qualification.

Audit · Compliance

Tamper-evident audit + compliance evidence

A PQC-signed Merkle-tree audit trail and evidence aligned to ISO/IEC 27001:2022, ISO/IEC 42001:2023, and ISO/IEC 19790:2025.

Public verifiability

Conformance you can re-run yourself

NIST ACVP conformance vectors (noble 435/435, liboqs 240/240 on the addressable ML-KEM surface) and reproducible benchmarks - open to inspection in the public mirror.

How we build it

Production infrastructure, not a research project

QNSI publishes evidence for material claims such as algorithm coverage, conformance, and qualified hardware paths. Each artifact carries a scope boundary: source presence, test-vector conformance, service telemetry, deployment qualification, and independent assurance are not treated as interchangeable.

The platform is built in TypeScript and Rust, runs on AWS in Singapore (ap-southeast-1), and is operated under regulated-buyer-grade engineering discipline: signed audit trails, immutable production change records, deterministic deploys, and no shortcuts on cryptographic correctness.

Verify it yourself: NIST ACVP conformance at /verify/conformance, reproducible benchmarks at /benchmarks, and the crypto path open for inspection in the public mirror at heossihq/qnsi-public.

Who it's for

Built for regulated buyers

QNSI is built for financial institutions, defense contractors, healthcare systems, sovereign AI programmes, and critical-infrastructure operators across Asia, Europe, and North America - organisations whose data has to stay confidential long past the arrival of a quantum computer.

HEOSSI is headquartered in Singapore deliberately: it is one of the few jurisdictions with a coherent national posture on AI, cryptography, and financial infrastructure, and the MAS TRM Guidelines and PDPA give QNSI a regulatory baseline that maps cleanly onto the obligations its international customers face.

Singapore-HQAWS ap-southeast-1MAS TRM-alignedPDPA-native

Get in touch

Contact

For more channels - compliance, billing, support, incident escalation - see the Contact page.

See the Contact page for all channels, or heossi.com for HEOSSI company, legal, and registration details.

QNSI privacy choices

Necessary storage keeps the site secure. With your permission, privacy-bounded analytics help HEOSSI understand pages, journeys, and campaign outcomes. No advertising profiles are created.

Cookie policy