QNSI

HEOSSI · Singapore

About QNSI

QNSI is the flagship post-quantum cryptography platform from HEOSSI - verifiable PQC infrastructure for AI, data, and mission-critical systems.

QNSI is built and operated by HEOSSI. For the company behind QNSI - corporate, legal, and registration details - see heossi.com.

87PQC algorithms · 13 families
2independent providers, cross-verified
100%NIST ACVP (noble 435/435 · liboqs 240/240)
Freeto start - full 5-language SDK family

Why QNSI exists

Standards on paper aren't the same as verifiable deployment

"Harvest now, decrypt later" is no longer a thought experiment. Adversaries are already collecting encrypted traffic they intend to break with cryptanalytically relevant quantum computers later this decade. Every long-lived secret encrypted with RSA, ECDH, or ECDSA today is on a clock - and the regulated industries that hold the most sensitive long-lived data (finance, defense, healthcare, government) have the least appetite for migration improvisation.

NIST finalised the first post-quantum standards in August 2024 - FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) - with FIPS 206 (FN-DSA) and HQC still in draft. The U.S. CNSA 2.0 suite sets a federal migration window (new National Security Systems from 2027, full transition 2030-2033); U.S. Executive Order 14412 (June 2026) adds 2030/2031 PQC deadlines for federal High-Value Assets, and the EU's post-quantum roadmap targets high-risk financial systems by 2030. The work is no longer "discover PQC"; it is "deploy PQC verifiably, with evidence regulators and auditors can check."

That gap - between standards on paper and verifiable deployment - is QNSI.

One platform, four surfaces

What QNSI is

A full managed post-quantum platform - not a single library or a point tool.

KMS · Vault · Storage

Quantum-safe KMS, vault, and SSE-X storage

ML-KEM, ML-DSA, Falcon, and SLH-DSA across 13 algorithm families, with dual-provider cross-verification (liboqs + noble) and enforceable per-tenant crypto-policy tiers.

Hardware-backed keys

HSM, BYOH, and confidential compute

8 capability-gated HSM connector implementations, customer-controlled custody workflows, and confidential-compute connectors for AI workload isolation. Named hardware requires live qualification.

Audit · Compliance

Tamper-evident audit + compliance evidence

A PQC-signed Merkle-tree audit trail and on-demand evidence packs for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, PDPA, and MAS TRM.

Public verifiability

Conformance you can re-run yourself

NIST ACVP conformance vectors (noble 435/435, liboqs 240/240 on the addressable ML-KEM surface) and reproducible benchmarks - open to inspection in the public mirror.

How we build it

Production infrastructure, not a research project

QNSI publishes evidence for material claims such as algorithm coverage, conformance, and qualified hardware paths. Each artifact carries a scope boundary: source presence, test-vector conformance, service telemetry, deployment qualification, and independent assurance are not treated as interchangeable.

The platform is built in TypeScript and Rust, runs on AWS in Singapore (ap-southeast-1), and is operated under regulated-buyer-grade engineering discipline: signed audit trails, immutable production change records, deterministic deploys, and no shortcuts on cryptographic correctness.

Verify it yourself: NIST ACVP conformance at /verify/conformance, reproducible benchmarks at /benchmarks, and the crypto path open for inspection in the public mirror at heossihq/qnsi-public.

Who it's for

Built for regulated buyers

QNSI is built for financial institutions, defense contractors, healthcare systems, sovereign AI programmes, and critical-infrastructure operators across Asia, Europe, and North America - organisations whose data has to stay confidential long past the arrival of a quantum computer.

HEOSSI is headquartered in Singapore deliberately: it is one of the few jurisdictions with a coherent national posture on AI, cryptography, and financial infrastructure, and the MAS TRM Guidelines and PDPA give QNSI a regulatory baseline that maps cleanly onto the obligations its international customers face.

Singapore-HQAWS ap-southeast-1MAS TRM-alignedPDPA-native

Get in touch

Contact

For more channels - compliance, billing, support, incident escalation - see the Contact page.

See the Contact page for all channels, or heossi.com for HEOSSI company, legal, and registration details.