{
  "schemaVersion": "3.3.0",
  "product": "QNSI",
  "productLong": "Quantum-Native Security Infrastructure",
  "vendor": "HEOSSI (PTE.) LTD",
  "canonicalUrl": "https://qnsi.heossi.com",
  "validFrom": "2026-07-21",
  "locale": "en",
  "pqc": {
    "families": 13,
    "kems": 24,
    "signatures": 63,
    "total": 87,
    "policyTiers": 4
  },
  "acvp": {
    "noble": "435/435",
    "liboqs": "240/240",
    "liboqsDeferred": 195,
    "evidenceUrl": "https://qnsi.heossi.com/verify/conformance"
  },
  "pricing": {
    "freePrice": "$0",
    "entryPrice": "$149",
    "free": {
      "storage": "10 GB",
      "apiCalls": "50,000",
      "kmsKeys": 20,
      "vaultSecrets": 25
    },
    "url": "https://qnsi.heossi.com/pricing"
  },
  "compliance": {
    "frameworks": 7,
    "controls": 48
  },
  "affordances": {
    "api": "https://api.qnsi.heossi.com",
    "mcp": "@heossihq/qnsi-mcp",
    "signup": "https://cloud.qnsi.heossi.com/auth?mode=signup",
    "docs": "https://docs.qnsi.heossi.com",
    "conformance": "https://qnsi.heossi.com/verify/conformance"
  },
  "sdks": [
    {
      "language": "TypeScript/Node",
      "pkg": "@heossihq/qnsi",
      "registry": "npm",
      "version": "0.6.0",
      "install": "pnpm add @heossihq/qnsi"
    },
    {
      "language": "Python",
      "pkg": "qnsi",
      "registry": "PyPI",
      "version": "0.4.2",
      "install": "pip install qnsi"
    },
    {
      "language": "Rust",
      "pkg": "qnsi",
      "registry": "crates.io",
      "version": "0.3.0",
      "install": "cargo add qnsi"
    },
    {
      "language": "JVM/Android",
      "pkg": "com.heossi:qnsi",
      "registry": "Maven Central",
      "version": "0.4.0",
      "install": "implementation(\"com.heossi:qnsi:0.4.0\")"
    },
    {
      "language": "Go",
      "pkg": "github.com/heossihq/qnsi-public/sdks/go/qnsi",
      "registry": "go",
      "version": null,
      "install": "go get github.com/heossihq/qnsi-public/sdks/go/qnsi@latest"
    },
    {
      "language": "MCP",
      "pkg": "@heossihq/qnsi-mcp",
      "registry": "npm",
      "version": "0.2.0",
      "install": "pnpm add @heossihq/qnsi-mcp"
    }
  ],
  "blog": [
    {
      "title": "IBM Defined Application-Level Crypto-Agility. QNSI Takes It Into Enterprise Execution",
      "slug": "ibm-crypto-agility-framework-qnsi-enterprise-execution",
      "datePublished": "2026-07-21",
      "url": "https://qnsi.heossi.com/blog/ibm-crypto-agility-framework-qnsi-enterprise-execution"
    },
    {
      "title": "Native PQC HSMs Are Here: How QNSI Solves the Real Migration Problem",
      "slug": "native-pqc-hsms-qnsi-migration-bridge",
      "datePublished": "2026-07-20",
      "url": "https://qnsi.heossi.com/blog/native-pqc-hsms-qnsi-migration-bridge"
    },
    {
      "title": "Post-Quantum Claims Should Be Verifiable: How QNSI Proves Them",
      "slug": "verifiable-post-quantum-claims-qnsi",
      "datePublished": "2026-07-20",
      "url": "https://qnsi.heossi.com/blog/verifiable-post-quantum-claims-qnsi"
    },
    {
      "title": "Migrating a Bank's Cryptography to Quantum-Safe via QNSI: A 2026 Field Guide",
      "slug": "quantum-safe-cryptography-migration-for-banks",
      "datePublished": "2026-07-01",
      "url": "https://qnsi.heossi.com/blog/quantum-safe-cryptography-migration-for-banks"
    },
    {
      "title": "Is AES Quantum-Safe? What to Keep, What to Replace, and QNSI's Required Design",
      "slug": "is-aes-quantum-safe",
      "datePublished": "2026-06-01",
      "url": "https://qnsi.heossi.com/blog/is-aes-quantum-safe"
    },
    {
      "title": "ML-DSA on QNSI: Signature Contracts and Evidence Boundaries",
      "slug": "ml-dsa-explained",
      "datePublished": "2026-06-01",
      "url": "https://qnsi.heossi.com/blog/ml-dsa-explained"
    },
    {
      "title": "Crypto-Agility Is an Operating Capability: How QNSI Connects Policy, Inventory, and Migration",
      "slug": "what-is-crypto-agility",
      "datePublished": "2026-06-01",
      "url": "https://qnsi.heossi.com/blog/what-is-crypto-agility"
    },
    {
      "title": "Choosing a PQC Platform in 2026: The Tests We Invite You to Run on QNSI",
      "slug": "how-to-choose-pqc-platform-2026",
      "datePublished": "2026-06-01",
      "url": "https://qnsi.heossi.com/blog/how-to-choose-pqc-platform-2026"
    },
    {
      "title": "SLH-DSA on QNSI: Hash-Based Signatures for Your Most Conservative Signing Paths",
      "slug": "slh-dsa-explained",
      "datePublished": "2026-06-01",
      "url": "https://qnsi.heossi.com/blog/slh-dsa-explained"
    },
    {
      "title": "The Quantum Timeline Doesn't Matter — Your Data's Lifetime Does. Start on QNSI Today",
      "slug": "when-will-quantum-break-encryption",
      "datePublished": "2026-06-01",
      "url": "https://qnsi.heossi.com/blog/when-will-quantum-break-encryption"
    },
    {
      "title": "Composite Interoperability Without Guesswork: X25519 + ML-KEM on QNSI",
      "slug": "hybrid-pqc-explained",
      "datePublished": "2026-06-01",
      "url": "https://qnsi.heossi.com/blog/hybrid-pqc-explained"
    },
    {
      "title": "CNSA 2.0 Compliance on QNSI: ML-KEM-1024 and ML-DSA-87 as a Policy Setting",
      "slug": "cnsa-2-0-explained",
      "datePublished": "2026-06-01",
      "url": "https://qnsi.heossi.com/blog/cnsa-2-0-explained"
    },
    {
      "title": "Beyond AWS KMS: Migrating to Post-Quantum Key Management with QNSI",
      "slug": "migrating-aws-kms-to-pqc",
      "datePublished": "2026-06-01",
      "url": "https://qnsi.heossi.com/blog/migrating-aws-kms-to-pqc"
    },
    {
      "title": "Five PQC Vendor Evaluation Questions — and QNSI's Evidence Boundaries",
      "slug": "five-pqc-vendor-red-flags",
      "datePublished": "2026-05-14",
      "url": "https://qnsi.heossi.com/blog/five-pqc-vendor-red-flags"
    },
    {
      "title": "'Harvest Now, Decrypt Later' Is on a 2027 Clock — Here's How to Beat It with QNSI",
      "slug": "harvest-now-decrypt-later-2027-clock",
      "datePublished": "2026-05-14",
      "url": "https://qnsi.heossi.com/blog/harvest-now-decrypt-later-2027-clock"
    },
    {
      "title": "MAS TRM and PQC: How Singapore Financial Institutions Comply with QNSI",
      "slug": "mas-trm-pqc-compliance-singapore",
      "datePublished": "2026-05-14",
      "url": "https://qnsi.heossi.com/blog/mas-trm-pqc-compliance-singapore"
    },
    {
      "title": "What ML-KEM Does — and How QNSI Runs It for You Today",
      "slug": "what-ml-kem-actually-does",
      "datePublished": "2026-05-14",
      "url": "https://qnsi.heossi.com/blog/what-ml-kem-actually-does"
    },
    {
      "title": "Continuous Compliance vs. Snapshot Reports: QNSI Source Contracts and Evidence Boundaries",
      "slug": "live-compliance-vs-snapshot-reports",
      "datePublished": "2026-05-14",
      "url": "https://qnsi.heossi.com/blog/live-compliance-vs-snapshot-reports"
    }
  ],
  "changelog": [
    {
      "date": "2026-07-20",
      "category": "release",
      "title": "Native-PQC HSM positioning and migration guidance",
      "detail": "Published an evidence-backed guide to native-PQC provider adoption and QNSI's HSPK compatibility path. Public claims now distinguish native provider operations, module-certificate ownership, deployment qualification, and QNSI's current ML-DSA-44/65/87 software signing boundary under qualified PKCS#11 custody."
    },
    {
      "date": "2026-07-20",
      "category": "release",
      "title": "Durable and resumable host discovery",
      "detail": "Host scans now checkpoint their deterministic filesystem cursor, resume after interruption, spool signed reports durably, and export bounded signed evidence bundles for controlled transfer from disconnected estates. Import verifies tenant and agent identity, payload integrity, signature validity, revocation state, and bundle reuse before inventory processing."
    },
    {
      "date": "2026-07-20",
      "category": "release",
      "title": "Durable AI event intelligence and governed remediation",
      "detail": "Security operations can now retain and correlate AI and platform events, detect anomalies across services, build root-cause context, and prepare remediation behind tenant authorization and approval gates. The workflow preserves operator accountability instead of turning an AI recommendation into an unaudited production change."
    },
    {
      "date": "2026-07-20",
      "category": "release",
      "title": "Source-code cryptography discovery is live",
      "detail": "The QNSI CLI can scan a repository locally for classical, PQC, and hybrid cryptography usage, emit JSON or a local CBOM, and upload signed findings through a scoped scanner identity. Uploaded findings enter Crypto Inventory as code_repo/code_usage assets and flow into discovery runs, posture, CBOM, and audit evidence. Source code stays in the customer's environment; only normalized findings are uploaded."
    },
    {
      "date": "2026-07-20",
      "category": "release",
      "title": "Governed migration execution and recovery",
      "detail": "PQC migrations now support hash-bound dry runs, four-eyes approval, durable execution waves, pause/resume/cancel controls, per-asset cutover confirmation, lease-based crash recovery, and evidence-backed reconciliation when a provider outcome is ambiguous. Execution history remains readable even when new execution is feature-gated."
    },
    {
      "date": "2026-07-20",
      "category": "release",
      "title": "QNSI SDK 0.6.0 and MCP 0.2.0",
      "detail": "Published @heossihq/qnsi 0.6.0 with the source-code scanner and HSPK client methods, plus @heossihq/qnsi-mcp 0.2.0 with HSPK seal/sign tools. The current HSPK API binds ML-DSA-44/65/87 private-key custody at rest to a qualified PKCS#11 HSM while ML-DSA operations remain in QNSI software."
    },
    {
      "date": "2026-07-07",
      "category": "release",
      "title": "SDK @heossihq/qnsi 0.5.2",
      "detail": "PQC provider bumped to @noble/post-quantum 0.6.1 (the SDK's pure-JS cross-verification engine). NIST ACVP conformance unchanged (noble 435/435). Latest published npm release."
    },
    {
      "date": "2026-06-16",
      "category": "release",
      "title": "QNSI SDKs live on every registry",
      "detail": "One SDK per language, published and installable: @heossihq/qnsi (npm), qnsi (PyPI), qnsi (crates.io), com.heossi:qnsi (Maven Central), the Go module, plus the @heossihq/qnsi-mcp server."
    },
    {
      "date": "2025-12-01",
      "category": "security",
      "title": "Edge gateway and auth hardening",
      "detail": "Hardened public route handling and proxy behavior for signup, login, and tenant-lookup flows; reduced sensitive auth logging; removed committed signing material."
    },
    {
      "date": "2025-11-01",
      "category": "release",
      "title": "QNSI monorepo bootstrapped",
      "detail": "Consolidated the platform into the current monorepo; established the @heossihq/qnsi-* namespace and Changesets-based semantic versioning."
    }
  ],
  "legal": {
    "trustCenter": "https://qnsi.heossi.com/legal",
    "entity": {
      "legalName": "HEOSSI (PTE.) LTD",
      "uen": "202532790K",
      "jurisdiction": "Singapore",
      "incorporatedOn": "2025-07-28",
      "dpo": {
        "name": "Christopher M. Frost",
        "title": "Founder & CTO",
        "email": "qnsi-legal@heossi.com"
      }
    },
    "core": [
      {
        "slug": "terms",
        "title": "Terms of Service",
        "url": "https://qnsi.heossi.com/terms",
        "lastUpdated": "2026-06-01",
        "effective": "2026-06-01"
      },
      {
        "slug": "privacy",
        "title": "Privacy Policy",
        "url": "https://qnsi.heossi.com/privacy",
        "lastUpdated": "2026-06-01",
        "effective": "2026-06-01"
      },
      {
        "slug": "dpa",
        "title": "Data Processing Addendum",
        "url": "https://qnsi.heossi.com/dpa",
        "lastUpdated": "2026-06-01",
        "effective": "2026-06-01"
      },
      {
        "slug": "cookies",
        "title": "Cookie Policy",
        "url": "https://qnsi.heossi.com/cookies",
        "lastUpdated": "2026-06-01",
        "effective": "2026-06-01"
      }
    ],
    "policies": [
      {
        "slug": "data-protection-officer",
        "title": "Controller Identity and Data Protection Officer",
        "category": "legal",
        "review": "operational",
        "url": "https://qnsi.heossi.com/legal/data-protection-officer",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "sub-processors",
        "title": "Sub-processors",
        "category": "legal",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/sub-processors",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "export-control",
        "title": "Export Control and Sanctions",
        "category": "compliance",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/export-control",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "governing-law",
        "title": "Governing Law and Dispute Resolution",
        "category": "legal",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/governing-law",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "acceptable-use",
        "title": "Acceptable Use Policy",
        "category": "legal",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/acceptable-use",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "vulnerability-disclosure",
        "title": "Vulnerability Disclosure Policy",
        "category": "security",
        "review": "operational",
        "url": "https://qnsi.heossi.com/legal/vulnerability-disclosure",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "ai-and-customer-data",
        "title": "AI and Customer Data",
        "category": "security",
        "review": "operational",
        "url": "https://qnsi.heossi.com/legal/ai-and-customer-data",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "data-retention",
        "title": "Data Retention and Deletion",
        "category": "legal",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/data-retention",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "incident-response",
        "title": "Incident Response and Breach Notification",
        "category": "security",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/incident-response",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "business-continuity",
        "title": "Business Continuity and Disaster Recovery",
        "category": "operational",
        "review": "operational",
        "url": "https://qnsi.heossi.com/legal/business-continuity",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "accessibility",
        "title": "Accessibility Statement",
        "category": "operational",
        "review": "operational",
        "url": "https://qnsi.heossi.com/legal/accessibility",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "billing-cancellation",
        "title": "Billing, Renewal, Cancellation, and Refund Policy",
        "category": "legal",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/billing-cancellation",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "customer-security-responsibilities",
        "title": "Customer Security Responsibilities",
        "category": "security",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/customer-security-responsibilities",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "support-and-maintenance",
        "title": "Support and Maintenance Policy",
        "category": "operational",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/support-and-maintenance",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "service-level-agreement",
        "title": "Service Level Agreement",
        "category": "operational",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/service-level-agreement",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "government-and-law-enforcement-requests",
        "title": "Government and Law-Enforcement Request Policy",
        "category": "legal",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/government-and-law-enforcement-requests",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "intellectual-property-complaints",
        "title": "Intellectual Property Complaint Policy",
        "category": "legal",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/intellectual-property-complaints",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "marketing-communications",
        "title": "Marketing Communications Policy",
        "category": "compliance",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/marketing-communications",
        "lastUpdated": "2026-07-13"
      },
      {
        "slug": "business-conduct",
        "title": "Anti-Bribery, Anti-Corruption and Modern Slavery",
        "category": "compliance",
        "review": "pending-counsel",
        "url": "https://qnsi.heossi.com/legal/business-conduct",
        "lastUpdated": "2026-07-13"
      }
    ],
    "subProcessors": [
      {
        "name": "Amazon Web Services (AWS)",
        "purpose": "Primary cloud infrastructure for QNSI Cloud — compute (ECS, Lambda), storage (S3, RDS), networking (CloudFront, ELB), key management (KMS, Secrets Manager).",
        "region": "Singapore (ap-southeast-1)",
        "transfers": "EU SCCs + UK IDTA in place for EU/UK customer data routed through AWS edges.",
        "processesCustomerData": true
      },
      {
        "name": "Stripe",
        "purpose": "Subscription billing, payment processing, tax calculation, and invoicing for self-serve plans.",
        "region": "Global (controller-to-processor)",
        "transfers": "Stripe's published SCCs; cardholder data is tokenised and never touches QNSI infrastructure.",
        "processesCustomerData": true
      },
      {
        "name": "Namecheap (PrivateEmail)",
        "purpose": "Transactional email delivery for account verification, invoices, support correspondence, and incident notifications.",
        "region": "United States",
        "transfers": "EU SCCs in place for EU/UK recipient addresses.",
        "processesCustomerData": true
      },
      {
        "name": "Cloudflare",
        "purpose": "DNS authoritative resolution and DDoS protection for heossi.com and qnsi.heossi.com zones.",
        "region": "Global edge network",
        "transfers": "Cloudflare's data processing addendum + EU SCCs.",
        "processesCustomerData": false
      },
      {
        "name": "GitHub (Microsoft)",
        "purpose": "Source-code hosting and CI/CD orchestration for QNSI build pipelines. Customer Data is never stored in GitHub.",
        "region": "United States",
        "transfers": "Microsoft EU Data Boundary commitments + SCCs.",
        "processesCustomerData": false
      },
      {
        "name": "npm, Inc. (GitHub Packages)",
        "purpose": "Public SDK distribution. No Customer Data is processed; only published artifact metadata.",
        "region": "United States",
        "transfers": "Not applicable — public package registry.",
        "processesCustomerData": false
      }
    ]
  },
  "segments": [
    {
      "slug": "regulated-finance",
      "name": "Regulated Finance & Banking",
      "tagline": "PQC for retail/wholesale banking, broker-dealers, and payment processors under PCI DSS, MAS TRM, DORA, and FedRAMP equivalents.",
      "url": "https://qnsi.heossi.com/solutions/regulated-finance",
      "buyerPersona": [
        "CISO",
        "Head of Compliance",
        "Head of Crypto/PKI",
        "Chief Data Officer"
      ],
      "threatModel": [
        {
          "title": "Harvest-now, decrypt-later on long-life records",
          "description": "Transaction records, KYC files, and customer correspondence are retained for 7–30+ years. Anything captured in transit today is a CRQC target the moment a cryptographically relevant quantum computer arrives — historically estimated by NIST and major banks at ~2030–2035."
        },
        {
          "title": "Cross-border data movement under conflicting regimes",
          "description": "A Singapore bank operating in the EU and US faces MAS TRM + GDPR + DORA + PCI DSS simultaneously. Snapshot-style annual audits leave gaps; regulators increasingly demand continuous evidence."
        },
        {
          "title": "Vendor-key concentration risk",
          "description": "When one cloud KMS holds keys for KYC, settlement, and SWIFT messaging, a single compromise blast-radiuses every downstream regulator filing. Per-tenant cryptographic isolation contains the blast radius."
        }
      ],
      "complianceDrivers": [
        "PCI DSS v4.0.1",
        "MAS TRM (Singapore)",
        "DORA (EU financial)",
        "ISO/IEC 27001:2022",
        "SOC 2 Type II"
      ],
      "outcomes": [
        "Strict crypto-policy tier — every signing operation uses ML-DSA-65 or stronger, every KEM uses ML-KEM-768 or stronger",
        "Tamper-evident audit chain that survives regulator review without bespoke evidence assembly",
        "Per-tenant isolation across business lines (retail / commercial / wealth) — single compromise does not cascade",
        "Continuous compliance evidence (PCI DSS, SOC 2, ISO 27001, MAS TRM) — not annual snapshots"
      ],
      "keywords": [
        "PQC finance",
        "post-quantum banking",
        "PCI DSS PQC",
        "MAS TRM compliance",
        "DORA quantum-safe",
        "broker-dealer PQC",
        "payment processor PQC",
        "KYC encryption PQC"
      ],
      "minTier": "business-advanced",
      "cryptoPolicyTier": "strict"
    },
    {
      "slug": "defense-national-security",
      "name": "Defense & National Security",
      "tagline": "Air-gapped, CNSA 2.0-aligned PQC for defense contractors, intelligence agencies, and classified workloads.",
      "url": "https://qnsi.heossi.com/solutions/defense-national-security",
      "buyerPersona": [
        "CISO",
        "Authorizing Official",
        "PKI Lead",
        "Security Officer"
      ],
      "threatModel": [
        {
          "title": "Classified data with multi-decade confidentiality",
          "description": "NSS data retained under TOP SECRET for 50+ years is a primary harvest-now-decrypt-later target. Capture in 2025, decrypt circa 2035 — operationally relevant for an entire human generation."
        },
        {
          "title": "Hostile cryptanalytic adversary with sustained budget",
          "description": "Threat model assumes a nation-state-scale adversary running coordinated capture programmes against allied infrastructure. Algorithm agility and rapid rotation are not optional."
        },
        {
          "title": "Supply-chain attack on the root of trust",
          "description": "If keys never leave a customer-controlled HSM (Thales Luna, Entrust nShield — FIPS 140-3 validated), a compromised vendor cannot weaponise downstream signatures."
        },
        {
          "title": "Air-gap operational necessity",
          "description": "Classified, special-access, and sensitive-compartmented environments cannot depend on internet-reachable services. Offline signing, distributed edge routing, and tamper-evident audit replay are baseline requirements."
        }
      ],
      "complianceDrivers": [
        "CNSA 2.0",
        "FIPS 140-3",
        "NIST SP 800-208",
        "DoD IL5-class"
      ],
      "outcomes": [
        "Government crypto-policy tier — ML-KEM-1024 + ML-DSA-87 + SLH-DSA-256f, FIPS-finalized only",
        "Customer-managed HSM custody after live device qualification",
        "Air-gapped operation — no internet dependency, distributed edge routing",
        "Tamper-evident audit chain verifiable offline for IG and OIG review"
      ],
      "keywords": [
        "defense PQC",
        "CNSA 2.0 PQC",
        "air-gapped PQC",
        "IL5-class PQC",
        "NSS PQC",
        "intelligence PQC",
        "federal PQC"
      ],
      "minTier": "specialized",
      "cryptoPolicyTier": "government"
    },
    {
      "slug": "healthcare-life-sciences",
      "name": "Healthcare & Life Sciences",
      "tagline": "HIPAA + GDPR + PDPA-aligned PQC for hospitals, pharma research, clinical trials, and PHI exchanges.",
      "url": "https://qnsi.heossi.com/solutions/healthcare-life-sciences",
      "buyerPersona": [
        "CISO",
        "HIPAA Security Officer",
        "Clinical Data Lead",
        "DPO"
      ],
      "threatModel": [
        {
          "title": "PHI with lifetime confidentiality requirement",
          "description": "Genomic, psychiatric, reproductive-health, and HIV records retain confidentiality value across a patient's lifetime — and often their children's. Multi-decade HNDL exposure is real."
        },
        {
          "title": "Cross-institution research data exchange",
          "description": "Clinical trials and rare-disease consortia move de-identified PHI across borders and institutions. PQC signatures on every exchange let receivers verify authenticity without trusting the transport."
        },
        {
          "title": "Insider-attack on bulk PHI",
          "description": "Tenant isolation + per-record encryption + per-access audit means an exfiltrated database dump is plaintext-empty; the attacker must also breach the per-key access boundary."
        }
      ],
      "complianceDrivers": [
        "HIPAA Security Rule",
        "GDPR",
        "PDPA (Singapore)",
        "ISO/IEC 27001:2022",
        "21 CFR Part 11 (FDA)"
      ],
      "outcomes": [
        "HIPAA Security Rule addressable safeguards met without bespoke encryption infrastructure",
        "Per-record encryption — bulk database exfiltration is plaintext-empty",
        "PQC-signed cross-institution exchanges with verifiable provenance",
        "Continuous compliance evidence for HIPAA, GDPR, PDPA — not annual snapshots"
      ],
      "keywords": [
        "healthcare PQC",
        "HIPAA PQC",
        "PHI quantum-safe",
        "clinical trial encryption",
        "pharma R&D PQC",
        "genomic data PQC",
        "21 CFR Part 11 PQC"
      ],
      "minTier": "business-advanced",
      "cryptoPolicyTier": "strict"
    },
    {
      "slug": "government-sovereign-cloud",
      "name": "Government & Sovereign Cloud",
      "tagline": "FedRAMP, NIS2, and sovereign-residency PQC for federal, state, municipal, and supranational deployments.",
      "url": "https://qnsi.heossi.com/solutions/government-sovereign-cloud",
      "buyerPersona": [
        "CISO",
        "Authorizing Official",
        "Privacy Officer",
        "Records Officer"
      ],
      "threatModel": [
        {
          "title": "Data-residency under sovereign jurisdiction",
          "description": "Citizen records, tax data, and inter-agency correspondence must remain under the originating jurisdiction's legal control. VPC-pinned QNSI deployments enforce residency at the infrastructure layer."
        },
        {
          "title": "Long-cycle public records",
          "description": "Title deeds, court records, and benefits-history span 30–80+ years. HNDL exposure is asymptotically certain on this timeframe without PQC."
        },
        {
          "title": "Adversarial-state harvest of inter-agency traffic",
          "description": "Diplomatic cables and inter-agency briefings captured in transit today have ongoing value as historical intelligence. PQC-TLS today removes that asymptotic exposure."
        }
      ],
      "complianceDrivers": [
        "FedRAMP (Moderate / High)",
        "NIS2 (EU)",
        "FIPS 140-3",
        "ISO/IEC 27001:2022",
        "CJIS Security Policy"
      ],
      "outcomes": [
        "Maximum crypto-policy tier — strongest FIPS-finalized parameter sets across KEM and signature",
        "Sovereign data residency controls with a qualified customer-HSM custody option",
        "Audit chain verifiable by IG / GAO / equivalent independent reviewer",
        "Architecturally aligned to FedRAMP, NIS2, CJIS, ISO 27001 — continuous evidence"
      ],
      "keywords": [
        "government PQC",
        "FedRAMP PQC",
        "sovereign cloud PQC",
        "NIS2 PQC",
        "public sector PQC",
        "CJIS PQC",
        "municipal PQC"
      ],
      "minTier": "enterprise-pro",
      "cryptoPolicyTier": "maximum"
    },
    {
      "slug": "sovereign-ai-labs",
      "name": "Sovereign AI Labs",
      "tagline": "Encrypted model training, GPU-enclave orchestration, and PQC-signed inference for sovereign AI labs and model marketplaces.",
      "url": "https://qnsi.heossi.com/solutions/sovereign-ai-labs",
      "buyerPersona": [
        "CTO",
        "ML Platform Lead",
        "AI Safety Officer",
        "Head of Research"
      ],
      "threatModel": [
        {
          "title": "Training-data extraction from the model",
          "description": "Membership-inference and gradient-leakage attacks recover training samples from served weights. End-to-end encryption from data lake to enclave neutralises the bulk-exposure risk."
        },
        {
          "title": "Model exfiltration from the inference path",
          "description": "Served models are themselves IP. Enclave-bound inference + ML-DSA-signed responses make black-box weight extraction provably tamper-evident."
        },
        {
          "title": "Cross-tenant leakage on shared GPUs",
          "description": "GPU enclaves (SGX, SEV-SNP, Nitro) plus QNSI tenant isolation give each customer cryptographic separation even on shared hardware."
        },
        {
          "title": "Supply-chain attack on training data",
          "description": "PQC-signed dataset attestations — every input training file carries an ML-DSA signature that traces to its source."
        }
      ],
      "complianceDrivers": [
        "ISO/IEC 27001:2022",
        "SOC 2 Type II",
        "EU AI Act",
        "NIST AI RMF"
      ],
      "outcomes": [
        "Maximum crypto-policy tier — strongest parameter sets across training and inference",
        "GPU-enclave attestation — training and inference run on verified hardware",
        "PQC-signed inference responses — verifiable provenance from served model to consumer",
        "Per-tenant isolation on shared GPU infrastructure"
      ],
      "keywords": [
        "sovereign AI PQC",
        "confidential AI inference",
        "PQC AI training",
        "GPU enclave PQC",
        "AI model marketplace PQC",
        "SGX AI",
        "SEV-SNP AI",
        "Nitro Enclaves AI"
      ],
      "minTier": "enterprise-pro",
      "cryptoPolicyTier": "maximum"
    },
    {
      "slug": "critical-infrastructure",
      "name": "Critical Infrastructure",
      "tagline": "PQC for utilities, energy grids, telecommunications, and transport systems under NIS2 and NERC CIP.",
      "url": "https://qnsi.heossi.com/solutions/critical-infrastructure",
      "buyerPersona": [
        "CISO",
        "OT Security Lead",
        "Regulatory Affairs",
        "Operations Director"
      ],
      "threatModel": [
        {
          "title": "OT equipment with multi-decade service life",
          "description": "SCADA controllers, smart-meters, and grid telemetry endpoints deployed today run for 15–25 years. They will face CRQC during their service life — algorithm agility is mandatory."
        },
        {
          "title": "Nation-state grid-disruption objective",
          "description": "Energy and telecom are top-priority adversary targets. Captured-now command-and-control traffic decrypted on a future quantum platform yields operational blueprints."
        },
        {
          "title": "IT/OT boundary as the soft target",
          "description": "IT-side compromise → OT command injection is the documented attack chain. QNSI audit chains across the boundary make lateral movement tamper-evident."
        }
      ],
      "complianceDrivers": [
        "NIS2 (EU)",
        "NERC CIP-005-7 / CIP-007-6",
        "ISO/IEC 27001:2022",
        "MAS TRM (Singapore)"
      ],
      "outcomes": [
        "Inventory and govern IT/OT transport boundaries; end-to-end PQC-native execution requires boundary-specific production evidence",
        "Continuous CBOM inventory across both IT and legacy OT systems",
        "Tamper-evident incident-evidence packs for NIS2 24-hour reporting",
        "Qualified sovereign HSM custody path for nationally significant infrastructure"
      ],
      "keywords": [
        "critical infrastructure PQC",
        "NIS2 PQC",
        "NERC CIP PQC",
        "utility PQC",
        "telecom PQC",
        "energy grid PQC",
        "SCADA PQC",
        "OT PQC"
      ],
      "minTier": "enterprise-standard",
      "cryptoPolicyTier": "maximum"
    },
    {
      "slug": "insurance-asset-management",
      "name": "Insurance & Asset Management",
      "tagline": "PQC for insurers, reinsurers, asset managers, and pension funds with multi-decade data-retention obligations.",
      "url": "https://qnsi.heossi.com/solutions/insurance-asset-management",
      "buyerPersona": [
        "CISO",
        "Head of Compliance",
        "Data Retention Lead",
        "Risk Officer"
      ],
      "threatModel": [
        {
          "title": "Multi-decade policy retention",
          "description": "Life insurance, annuities, and pension records are routinely retained 30–80 years. Any record in transit today that an adversary captures is decryptable on the buyer's likely CRQC arrival horizon."
        },
        {
          "title": "Claim-record integrity over a lifetime",
          "description": "A 1995-issued policy must still be cryptographically authenticatable in 2055. PQC signatures applied today survive that timeline; RSA-2048 does not."
        },
        {
          "title": "Reinsurance and broker exchange",
          "description": "Sensitive actuarial data moves across reinsurers, brokers, and underwriters. PQC-signed exchange and per-counterparty key isolation contain breach scope."
        }
      ],
      "complianceDrivers": [
        "SOX",
        "MAS TRM (Singapore)",
        "DORA (EU financial)",
        "ISO/IEC 27001:2022",
        "SOC 2 Type II"
      ],
      "outcomes": [
        "PQC signatures applied today remain cryptographically authenticatable across the policy life",
        "Long-retention audit chain for regulator review (SOX, MAS, DORA)",
        "Per-counterparty key isolation in reinsurance and broker exchanges",
        "Continuous CBOM inventory to plan legacy RSA/ECDSA retirement"
      ],
      "keywords": [
        "insurance PQC",
        "asset management PQC",
        "pension fund PQC",
        "HNDL insurance",
        "long-term data retention PQC",
        "actuarial data PQC",
        "reinsurance PQC"
      ],
      "minTier": "business-advanced",
      "cryptoPolicyTier": "strict"
    },
    {
      "slug": "multi-tenant-saas",
      "name": "Multi-Tenant SaaS Platforms",
      "tagline": "PQC primitives, tenant isolation, and usage metering for SaaS platforms serving regulated buyers.",
      "url": "https://qnsi.heossi.com/solutions/multi-tenant-saas",
      "buyerPersona": [
        "CTO",
        "VP Engineering",
        "Head of Security",
        "Head of Compliance"
      ],
      "threatModel": [
        {
          "title": "Single regulated customer breaches your platform",
          "description": "One enterprise breach drags every other tenant into the regulator response. Per-tenant cryptographic isolation contains the blast radius to a single tenant's data."
        },
        {
          "title": "Bring-your-own-customer-compliance burden",
          "description": "Customers in finance/healthcare push their compliance requirements onto you. QNSI per-tenant crypto-policy gives you the lever to satisfy strict-tier customers without forcing the cost onto everyone."
        },
        {
          "title": "Privileged-access bulk exfiltration",
          "description": "A compromised internal account that can read every tenant's data is a regulator-level event. QNSI per-tenant keys, RBAC, and audit-service make bulk reads observable and rate-limitable."
        }
      ],
      "complianceDrivers": [
        "SOC 2 Type II",
        "ISO/IEC 27001:2022",
        "GDPR",
        "HIPAA (if PHI customers)",
        "PCI DSS (if cardholder data)"
      ],
      "outcomes": [
        "Per-tenant crypto-policy lets you serve regulated and unregulated tenants on one codebase",
        "Tenant isolation contains breach blast radius to a single tenant",
        "Audit chain produces SOC 2 / ISO 27001 / GDPR evidence continuously",
        "Browser SDK gives end-to-end PQC to customer-facing web apps"
      ],
      "keywords": [
        "multi-tenant SaaS PQC",
        "B2B SaaS encryption",
        "tenant isolation PQC",
        "SaaS compliance PQC",
        "per-tenant crypto policy"
      ],
      "minTier": "business-team",
      "cryptoPolicyTier": "strict"
    },
    {
      "slug": "education-research",
      "name": "Education & Research",
      "tagline": "FERPA + PDPA-aligned PQC for universities, K-12, EdTech platforms, and research consortia.",
      "url": "https://qnsi.heossi.com/solutions/education-research",
      "buyerPersona": [
        "CISO",
        "Registrar",
        "Research IT Lead",
        "DPO"
      ],
      "threatModel": [
        {
          "title": "Lifetime-retention student records",
          "description": "Transcripts, degrees, and disciplinary records are retained indefinitely. They identify the individual across their entire career — HNDL exposure is multi-decade."
        },
        {
          "title": "Cross-institution research data movement",
          "description": "Genomics, social-science, and clinical-research datasets move across institutions and borders. PQC signatures + tenant isolation contain bleed between consortium members."
        },
        {
          "title": "Mass-stalking risk from student-record leaks",
          "description": "Student PII at scale is a frequently abused dataset for stalking, doxxing, and identity theft. Per-record encryption defeats bulk exfiltration."
        }
      ],
      "complianceDrivers": [
        "FERPA",
        "PDPA (Singapore)",
        "GDPR",
        "SOC 2 Type II"
      ],
      "outcomes": [
        "FERPA-aligned per-student encryption and audited access",
        "PDPA + GDPR coverage for cross-border students and researchers",
        "Cross-institution research exchanges with PQC-signed provenance",
        "Per-record encryption defeats bulk student-data exfiltration"
      ],
      "keywords": [
        "EdTech PQC",
        "FERPA PQC",
        "university PQC",
        "research data PQC",
        "student records encryption",
        "K-12 PQC"
      ],
      "minTier": "business-team",
      "cryptoPolicyTier": "strict"
    },
    {
      "slug": "manufacturing-ip-protection",
      "name": "Manufacturing & IP Protection",
      "tagline": "Trade-secret protection, CAD/CAM file vaulting, and supply-chain PQC for manufacturers and IP-heavy industries.",
      "url": "https://qnsi.heossi.com/solutions/manufacturing-ip-protection",
      "buyerPersona": [
        "CISO",
        "IP Counsel",
        "OT Security Lead",
        "Supply Chain Security"
      ],
      "threatModel": [
        {
          "title": "Trade-secret exfiltration over decades",
          "description": "A captured CAD file or process recipe today is exploitable on a 5–50 year horizon. PQC vaulting today neutralises HNDL exposure on the IP itself."
        },
        {
          "title": "Supply-chain firmware tampering",
          "description": "OT/IoT firmware signed with RSA-2048 today is vulnerable when CRQC arrives. ML-DSA-87 signatures on firmware survive that transition."
        },
        {
          "title": "Multi-jurisdiction manufacturing partnerships",
          "description": "OEM ↔ tier-1 ↔ tier-2 IP flows across borders. Per-partner PQC keys + tenant isolation contain breach scope to a single partner."
        }
      ],
      "complianceDrivers": [
        "ISO/IEC 27001:2022",
        "SOC 2 Type II",
        "GDPR"
      ],
      "outcomes": [
        "PQC-encrypted vaulting of CAD/CAM files and process recipes — multi-decade HNDL-safe",
        "ML-DSA-87 firmware signatures that survive CRQC arrival",
        "Per-partner cryptographic isolation across OEM ↔ supplier flows",
        "Continuous CBOM inventory across the manufacturing supply chain"
      ],
      "keywords": [
        "manufacturing PQC",
        "trade secret PQC",
        "IP protection PQC",
        "CAD vault PQC",
        "supply chain PQC",
        "firmware signing PQC",
        "OEM PQC"
      ],
      "minTier": "business-advanced",
      "cryptoPolicyTier": "strict"
    }
  ],
  "developerPatterns": [
    {
      "slug": "legaltech-contract-management",
      "name": "LegalTech Contract Management",
      "tagline": "Source-linked contract-management integration pattern spanning storage, search, AI, and audit surfaces.",
      "url": "https://qnsi.heossi.com/developers/use-cases/legaltech-contract-management",
      "primarySdk": "typescript",
      "evidenceBoundary": "Source presence and snippet rendering do not prove mounted routes, encryption semantics, retention, AI isolation, audit coverage, or deployment behavior; all remain NOT VERIFIED.",
      "timeToFirstPqcMinutes": null,
      "keywords": [
        "LegalTech PQC",
        "contract management encryption",
        "clause search SSE",
        "AI contract analysis encrypted",
        "legal hold PQC"
      ]
    },
    {
      "slug": "healthcare-phi-records",
      "name": "Healthcare PHI / Patient Records",
      "tagline": "Source-linked PHI integration pattern spanning storage, search, tenant isolation, and audit contracts.",
      "url": "https://qnsi.heossi.com/developers/use-cases/healthcare-phi-records",
      "primarySdk": "python",
      "evidenceBoundary": "The pattern is not a compliance attestation or deployment proof. PHI protection, policy enforcement, isolation, audit completeness, and runtime behavior remain NOT VERIFIED.",
      "timeToFirstPqcMinutes": null,
      "keywords": [
        "PHI PQC",
        "HIPAA records encryption",
        "patient records PQC",
        "clinical data encryption",
        "de-identification PQC"
      ]
    },
    {
      "slug": "investment-broker-dealer-archives",
      "name": "Investment & Broker-Dealer Archives",
      "tagline": "Source-linked archive pattern for evaluating retention, audit, and searchable-encryption contracts.",
      "url": "https://qnsi.heossi.com/developers/use-cases/investment-broker-dealer-archives",
      "primarySdk": "typescript",
      "evidenceBoundary": "The pattern is not evidence of WORM enforcement, regulatory compliance, immutable audit coverage, searchable encryption, or deployment behavior; all remain NOT VERIFIED.",
      "timeToFirstPqcMinutes": null,
      "keywords": [
        "WORM PQC",
        "SEC 17a-4 PQC",
        "FINRA encryption",
        "broker-dealer archive",
        "investment document retention"
      ]
    },
    {
      "slug": "multi-tenant-b2b-platform",
      "name": "Multi-Tenant B2B Platform",
      "tagline": "Source-linked multi-tenant integration pattern for onboarding, policy, storage, and metering contracts.",
      "url": "https://qnsi.heossi.com/developers/use-cases/multi-tenant-b2b-platform",
      "primarySdk": "typescript",
      "evidenceBoundary": "SDK source presence does not prove route reachability, tenant isolation, policy enforcement, quota accounting, billing, or deployment behavior; all remain NOT VERIFIED.",
      "timeToFirstPqcMinutes": null,
      "keywords": [
        "multi-tenant PQC",
        "B2B SaaS encryption",
        "tenant isolation PQC",
        "per-tenant crypto policy"
      ]
    },
    {
      "slug": "edtech-secure-lms",
      "name": "EdTech Secure LMS",
      "tagline": "Source-linked education-record integration pattern for storage, search, isolation, and retention contracts.",
      "url": "https://qnsi.heossi.com/developers/use-cases/edtech-secure-lms",
      "primarySdk": "typescript",
      "evidenceBoundary": "The pattern is not a compliance attestation or deployment proof. Record protection, selective indexing, retention, isolation, and runtime behavior remain NOT VERIFIED.",
      "timeToFirstPqcMinutes": null,
      "keywords": [
        "EdTech PQC",
        "FERPA LMS",
        "student records encryption",
        "coursework PQC"
      ]
    },
    {
      "slug": "govtech-public-records",
      "name": "GovTech Public Records",
      "tagline": "Source-linked public-records pattern for evaluating access, audit, and retention contracts.",
      "url": "https://qnsi.heossi.com/developers/use-cases/govtech-public-records",
      "primarySdk": "typescript",
      "evidenceBoundary": "The pattern is not evidence of FOIA compliance, authorization enforcement, audit completeness, immutable retention, isolation, or deployment behavior; all remain NOT VERIFIED.",
      "timeToFirstPqcMinutes": null,
      "keywords": [
        "GovTech PQC",
        "FOIA records PQC",
        "public records encryption",
        "government records audit"
      ]
    },
    {
      "slug": "ai-agent-mcp-integration",
      "name": "AI Agent / MCP Integration",
      "tagline": "Source-linked MCP integration pattern for evaluating QNSI tool, signing, and audit contracts.",
      "url": "https://qnsi.heossi.com/developers/use-cases/ai-agent-mcp-integration",
      "primarySdk": "mcp",
      "evidenceBoundary": "Package and snippet presence do not prove MCP route reachability, PQC signing, audit effects, secret handling, or deployment behavior; all remain NOT VERIFIED.",
      "timeToFirstPqcMinutes": null,
      "keywords": [
        "MCP PQC",
        "Claude QNSI",
        "AI agent encryption",
        "Model Context Protocol PQC",
        "PQC tool calls"
      ]
    },
    {
      "slug": "browser-sdk-e2e",
      "name": "Browser-to-Vault PQC Reference Architecture",
      "tagline": "Reference architecture for browser-side ML-KEM-768 and a PQC-native vault handoff. Deployed browser-to-vault behavior is NOT VERIFIED.",
      "url": "https://qnsi.heossi.com/developers/use-cases/browser-sdk-e2e",
      "primarySdk": "browser",
      "evidenceBoundary": "No executable handoff contract or independent deployment evidence exists for this architecture. Browser-to-vault confidentiality, PQC continuity, edge negotiation, and plaintext handling remain NOT VERIFIED.",
      "timeToFirstPqcMinutes": null,
      "keywords": [
        "browser PQC primitives",
        "@noble/post-quantum",
        "browser-to-vault PQC architecture",
        "client-side encryption",
        "composite interoperability TLS"
      ]
    },
    {
      "slug": "service-to-service-mtls",
      "name": "Service-to-Service PQC Reference Architecture",
      "tagline": "Reference architecture for PQC-native service authentication and explicit composite interoperability. Production mTLS and ML-DSA SVID behavior is NOT VERIFIED.",
      "url": "https://qnsi.heossi.com/developers/use-cases/service-to-service-mtls",
      "primarySdk": "go",
      "evidenceBoundary": "No independently verified service-mesh execution path exists for this architecture. PQC mTLS, SVID issuance, certificate rotation, audit coverage, and deployment behavior remain NOT VERIFIED.",
      "timeToFirstPqcMinutes": null,
      "keywords": [
        "PQC service authentication",
        "composite interoperability TLS",
        "X25519MLKEM768",
        "SPIFFE PQC architecture",
        "service mesh PQC"
      ]
    }
  ],
  "competitors": [
    {
      "slug": "aws-kms",
      "name": "AWS KMS",
      "angle": "cloud-KMS incumbent without a PQC key path",
      "comparisonUrl": "https://qnsi.heossi.com/compare/aws-kms"
    },
    {
      "slug": "azure-key-vault",
      "name": "Azure Key Vault",
      "angle": "cloud-KMS incumbent",
      "comparisonUrl": "https://qnsi.heossi.com/compare/azure-key-vault"
    },
    {
      "slug": "hashicorp-vault",
      "name": "HashiCorp Vault",
      "angle": "secrets manager without PQC",
      "comparisonUrl": "https://qnsi.heossi.com/compare/hashicorp-vault"
    },
    {
      "slug": "fortanix",
      "name": "Fortanix DSM",
      "angle": "HSM/DSM platform",
      "comparisonUrl": "https://qnsi.heossi.com/compare/fortanix"
    },
    {
      "slug": "pqshield",
      "name": "PQShield",
      "angle": "cryptographic IP and libraries, not a platform",
      "comparisonUrl": "https://qnsi.heossi.com/compare/pqshield"
    },
    {
      "slug": "qusecure",
      "name": "QuSecure QuProtect",
      "angle": "crypto-agility overlay, not a platform",
      "comparisonUrl": "https://qnsi.heossi.com/compare/qusecure"
    },
    {
      "slug": "sandboxaq",
      "name": "SandboxAQ AQtive Guard",
      "angle": "discovery/inventory, not a platform",
      "comparisonUrl": "https://qnsi.heossi.com/compare/sandboxaq"
    }
  ],
  "listings": [
    {
      "platform": "AWS Marketplace",
      "integration": "built-and-mounted",
      "status": "not-listed",
      "listingUrl": null
    },
    {
      "platform": "Azure Marketplace",
      "integration": "built-and-mounted",
      "status": "not-listed",
      "listingUrl": null
    },
    {
      "platform": "Google Cloud Marketplace",
      "integration": "built-and-mounted",
      "status": "not-listed",
      "listingUrl": null
    },
    {
      "platform": "GitHub Marketplace",
      "integration": "built-and-mounted",
      "status": "not-listed",
      "listingUrl": null
    },
    {
      "platform": "Vercel Marketplace",
      "integration": "built-and-mounted",
      "status": "not-listed",
      "listingUrl": null
    }
  ],
  "byohsm": {
    "total": 8,
    "pkcs11": 6,
    "rest": 2,
    "fips140_3Level3": {
      "availableWithCustomerProvisionedService": true,
      "currentlyConfigured": false,
      "qualifiedInQnsiEnvironment": true,
      "via": "AWS CloudHSM",
      "certificate": "#4703",
      "certificateHolder": "Marvell Semiconductor, Inc.",
      "pqcInsideBoundary": false
    },
    "pqcAlgorithmsAvailableInAnyHsm": 3,
    "pqcCertifiedNotYetSupported": [
      "Crypto4A",
      "Idemia",
      "Kryptus",
      "Securosys"
    ],
    "vendors": [
      {
        "id": "aws-cloudhsm",
        "name": "AWS CloudHSM",
        "interface": "pkcs11",
        "keyOps": "live-backend-verified",
        "attestation": "collector-implemented-unqualified",
        "validatedAgainstLiveBackend": true,
        "pqcOperationsQualified": false,
        "pqcInFirmware": false
      },
      {
        "id": "azure-dedicated-hsm",
        "name": "Azure Dedicated HSM",
        "interface": "pkcs11",
        "keyOps": "connector-implemented-unqualified",
        "attestation": "collector-implemented-unqualified",
        "validatedAgainstLiveBackend": false,
        "pqcOperationsQualified": false,
        "pqcInFirmware": false
      },
      {
        "id": "thales-luna",
        "name": "Thales Luna",
        "interface": "pkcs11",
        "keyOps": "connector-implemented-unqualified",
        "attestation": "collector-implemented-unqualified",
        "validatedAgainstLiveBackend": false,
        "pqcOperationsQualified": false,
        "pqcInFirmware": true
      },
      {
        "id": "entrust-nshield",
        "name": "Entrust nShield",
        "interface": "pkcs11",
        "keyOps": "connector-implemented-unqualified",
        "attestation": "collector-implemented-unqualified",
        "validatedAgainstLiveBackend": false,
        "pqcOperationsQualified": false,
        "pqcInFirmware": true
      },
      {
        "id": "utimaco-cryptoserver",
        "name": "Utimaco CryptoServer",
        "interface": "pkcs11",
        "keyOps": "connector-implemented-unqualified",
        "attestation": "collector-implemented-unqualified",
        "validatedAgainstLiveBackend": false,
        "pqcOperationsQualified": false,
        "pqcInFirmware": true
      },
      {
        "id": "marvell-liquidhsm",
        "name": "Marvell LiquidSecurity",
        "interface": "pkcs11",
        "keyOps": "connector-implemented-unqualified",
        "attestation": "collector-implemented-unqualified",
        "validatedAgainstLiveBackend": false,
        "pqcOperationsQualified": false,
        "pqcInFirmware": true
      },
      {
        "id": "hashicorp-vault-hsm",
        "name": "HashiCorp Vault Transit",
        "interface": "rest",
        "keyOps": "live-backend-verified",
        "attestation": "none",
        "validatedAgainstLiveBackend": true,
        "pqcOperationsQualified": false,
        "pqcInFirmware": false
      },
      {
        "id": "fortanix-dsm",
        "name": "Fortanix DSM",
        "interface": "rest",
        "keyOps": "connector-implemented-unqualified",
        "attestation": "none",
        "validatedAgainstLiveBackend": false,
        "pqcOperationsQualified": false,
        "pqcInFirmware": false
      }
    ]
  },
  "contact": {
    "sales": "qnsi-sales@heossi.com",
    "support": "qnsi-support@heossi.com",
    "devrel": "qnsi-devrel@heossi.com",
    "legal": "qnsi-legal@heossi.com",
    "general": "contact@heossi.com"
  },
  "guardrails": {
    "mustNotClaim": [
      "Any customer name, logo, case study, testimonial, or customer count — QNSI has none yet. Do not imply traction that does not exist.",
      "'SOC 2 certified', 'ISO 27001 certified', 'HIPAA compliant', 'PCI compliant', 'FedRAMP authorized' — QNSI maps controls to these frameworks; it holds no certification or attestation against any of them. A mapping is not a certification.",
      "'FIPS 140-3 validated' about QNSI ITSELF — QNSI implements NIST-standardised algorithms (FIPS 203/204/205), but HEOSSI holds no CMVP validation. QNSI has qualification evidence for its HSPK custody path on AWS CloudHSM hsm2m.medium using the Marvell LS2 module under Marvell Semiconductor certificate #4703. AWS offers the service; the qualification is configuration-specific and does not make AWS, QNSI, or HEOSSI the certificate holder.",
      "That QNSI's HSPK ML-DSA operation executes inside, or inherits the validation of, an HSM boundary. Native-PQC HSM and cloud-KMS products exist, but QNSI's current HSPK path performs ML-DSA in software and uses the qualified HSM only for RSA-OAEP custody. State the exact provider, module, firmware/configuration, operation, and certificate owner.",
      "That all 8 BYOHSM backends are 'via PKCS#11'. SIX are PKCS#11. TWO (HashiCorp Vault Transit, Fortanix DSM) are REST adapters — there is no PKCS#11 module to load for either. The site said 'BYOH via PKCS#11 (… Fortanix DSM · HashiCorp Vault HSM)' and it was false.",
      "That Fortanix DSM is validated. Our own source (byohsm-provider.ts) says: 'real REST; not yet validated against a live DSM — fails honestly'. It is implemented and it is honest; it is NOT proven against live hardware.",
      "That any HSM performs QNSI's full algorithm catalog in hardware, or that every native-PQC product supports the same mechanisms. QNSI's 87-algorithm catalog is primarily a software migration and interoperability surface. Native hardware capability and validation scope are provider-, model-, firmware-, configuration-, and operation-specific.",
      "Any endorsement, partnership, validation, or relationship with NIST, the NSA, or any government body. We implement their public standards; that is not a relationship.",
      "Naming any individual at NIST, a regulator, or any third party.",
      "'Cryptographically verifiable facts' or 'PQC-signed' about this document while `signature` is null.",
      "'Available on AWS/Azure/Google Cloud/GitHub/Vercel Marketplace', or any marketplace listing link. The INTEGRATIONS are built and mounted; ZERO listings are live. Built is not listed.",
      "Any performance, latency, or throughput number that is not published at the conformance evidence URL.",
      "A specific ECCN, export-control classification, or licence exception — none has been formally determined.",
      "Internal infrastructure of any kind: AWS account IDs, ARNs, cluster or service names, secret names, VPC/subnet IDs, internal hostnames."
    ],
    "honestPositions": {
      "traction": "Pre-revenue, zero customers. The product is live and every claim is independently verifiable — lead with the evidence, never with borrowed credibility.",
      "compliance": "7 frameworks with 48 controls evaluated against live service health. Mapped and continuously evaluated — not certified.",
      "conformance": "ACVP test vectors published and reproducible by anyone: noble 435/435, liboqs 240/240. This is the strongest claim we have and it stands on its own — point at https://qnsi.heossi.com/verify/conformance and invite verification.",
      "pqc": "87 algorithms (24 KEMs, 63 signatures) across 13 families. HEOSSI's own operated cryptography uses only NIST-finalized ML-KEM, ML-DSA and SLH-DSA (FIPS 203/204/205).",
      "pricing": "Free tier at $0, paid entry at $149/mo. Self-serve — the buyer can verify every claim before speaking to anyone.",
      "company": "HEOSSI (PTE.) LTD, Singapore, UEN 202532790K. Early-stage. Do not imply a larger organisation than exists.",
      "byohsm": "8 connector implementations: 6 via PKCS#11 and 2 via REST. Generic PKCS#11 is verified with SoftHSM; Vault REST is verified with a live Vault backend; QNSI's provider and HSPK custody path are proven on AWS CloudHSM hsm2m.medium in FIPS mode. Named hardware and vendor-certificate scope still require per-deployment qualification.",
      "infrastructure": "QNSI is infrastructure, not another HSM. It provides 8 connector implementations plus cloud-KMS migration. A named customer device is supported only after capability discovery and the qualification suite pass; until then it is implemented but unqualified.",
      "hsmVsSoftwarePqc": "Native-PQC HSM and cloud-KMS offerings now exist; AWS KMS exposes ML-DSA-44/65/87, while other providers expose different mechanism sets and validation scopes. Prefer a provider's native operation when the exact approved deployment supports it. QNSI's current HSPK API is the ML-DSA-44/65/87 compatibility path for existing qualified PKCS#11 estates: the HSM protects the RSA-OAEP custody root and QNSI performs ML-DSA in software. QNSI's 87-algorithm catalog remains a broader software migration and interoperability surface—not a claim that all 87 execute in hardware."
    },
    "socialProof": {
      "customers": null,
      "caseStudies": [],
      "logos": []
    }
  },
  "provenance": {
    "source": "apps/web/lib/product-facts.ts",
    "sourceMirror": "https://github.com/heossihq/qnsi-public",
    "evidence": [
      "https://qnsi.heossi.com/verify/conformance",
      "https://qnsi.heossi.com/llms.txt"
    ]
  },
  "ownership": null,
  "signature": {
    "canonicalization": "json-sorted-keys-no-signature/v1",
    "signedAt": "2026-07-29T12:14:33.502Z",
    "keysUrl": "https://qnsi.heossi.com/.well-known/facts-signing-key",
    "algorithms": {
      "ML-DSA-65": {
        "signature": "d1lQGoYYN78BIJeLSBREp8g7xQ8ZKprjsS300sRPiRfStOcnEqb7d0d3sCx/oHVoQcB7yIHqBLL7+9sASiuiBp6xVutOvaqWdclL5/vkmDts05fSAAwSW4DJvc5NN0+CDDfLr7KiMdalvvihvUtQFFYnlouCuaTA1dr3J/mifiGimfYyoO5PD5DmjbEOv3INlPGI0uxDiBJ1rIXaSMVBy60uSPpzJIaO52QFFKwqkd0c40Yz0PzqCVXgOirpfNoBnRgkjnRF7fr0iuEWXRWoySWlLPhvSIjWugtajo5hBjXwTiaWTBVw+6x+65CrT62UeucFdIWVGAUY64PMK8E1pDt5GOnYlYbwyH9e9RCr/8YuKr+hIsPyDc6YYRlFiLQJj9jSk/yGX0k3dud0o5xPoeWMwlDTVao7IAB46VWiseEw1KxSkKvC1GlvfRNou9qMu/UrZjXKZAHwmGez8Z0+35WPUPnvbt2plFm/o5MlQByt2R3fbRTaigaFAzmo7zynDNUcyA/xJa41f7tfoLCX5cK2geHZjZKPR0b7et0mBAHCF7akKsWjHsUDlFlnqklFzUNs6nndlcNv0pgfVhbLSejIZ9g4RiW8OY3lYe+s2KAyBS1mbCEhEe4VGE45lLmlWCQcAtZuIn3GtsfE95TuMoF58VhbTVW8mNm3a+I+M1yvvPV6w6mgEGyllvmf0O0zSeccGsWwkIlhplU3Uit5Awkr3e3OYx0JqzASDC2sWmQFIEIQ3jYChd23DGaTkG94QPpa4EY3QXw6oB0fNTHoribElt/FLQw4Ggs/QQaR586AwE9GcyXVt4f/m4dDbLVkrzj7/lrpgJHwlPFR/+NmmbIJIXIAxsA90ZdCmpYnCwLQzmbSeyJFovvXPBHVE/1pfNbnn1F3G3B2bo2lVIlcWXQRWVJjQJo4fPh9b4hSHyutR6fREZdz+9Qrx185xrFgYGA/XB5h7VuRue9FDPD6WEcvZyatA5cYJOicviNfrJvSQZ149jtiTbSFAkTZobXr1gpHooHEPKo9Rw1w268JD91yVJFoxZhAzOBFFD0kVt8qAf8ecvc41r6SNeW24KPSqn0u5sJP3KwahPPLGdK6k7spOLXrfd9nBlQBm/tlkO7CMHfKl/7SYVDqAIZAGKU4i9FPg+ucpT1k89Pn48STtx91fdt9+J1Zux8p3Yf5H51dn2vcfIoJHpC0KJSMo7f7Gw7KkIJR9PLSo0s6r88iHc2lzK+Jfr+LYEl5s4JediBhonlzZJhxyVd9yaiV94088puh+/4IQ5HXBSrbbOmtGkN6e9+2EM5EApofQ3lFTAvZR/j6z6zwBvnBo4sWNM/jJ4vOeaSCM2annJ912GlZOo6Ceq6aV4FoqC1bsbWKWmUlsjv2ATHvkSc6j4vM66Yy410kgixntNisRiJqjg9kymrKoB1PqHb13oXQdzJbVTSPiUn3irIdNBVwhP/gAlf1zHlBzwgZo5YWDYxekXVsUNuDkDsecT+Gyewr+xq9XJTMfZwRTHN/thK4uxVP9nwTRZRkFD4LFqyhfjwrjadR3CYIU5TROgr4P/7GtMi+dLAFXG13ZNQGY6BpLbQ5s4Oe/OlcR6z8FHFiVVbRy2bKHtLDXkQLa45dUkjF+ve1KXpw0/QALe/SirV+UaIZw4iEK0SbM87FPfAE/pQ0E+0QLm/9Pnb3of/dH9HhmFzfpEFLIAOMgMXCexMPPzS4WuQ3qFgSDKF9oe4Bp18RcH/6wBsYHwmOMjBRwrbtrQXt0RFwxbB1APwPLkWDE/pZ2nLRwaw0Eqg7FnIsKsW31v2+AiczY/8d150tsJIym8Bjj+E/55F2QxntwPKPdjloz3zJMMnq7A6RpCQDODce4rc4fqpwPvRoRzRoJzYACYbuOt8VwZnyokhIbWfUFYCnBeW6PLYQtFgw5ISmP4qNtEgTxqRzsXLLLCMz/DOaSVy0m+sZTfL2hnhD8vGQWIDFtbEyb3s+6nuwoH2MIeq0M25XK9EdUohiOKbXIlw2hRDu+DGOl51tJ8Ih5fwq+N+qUY1GSO1BD9Zt99Qip1+YWI0V4fujg+kDBUE2+bMfjongmyLY5BZzWFsodiS7RAaywC0EZC0y3QyUKUdvUMqrpcpFDt+PaBosYLp7yOv71uJaTMCrrWn4sUb2Mk0KrR0Qq+U2F9g4DuBu9OUx8+pG1+es4Vhr1OKVvL6DSoUeg5aGQsQwGEGYb4ZEOj5Q0L2Gx59HFMQW4pm56fsSA6UR7BeLq9laSWng9budvrzPa57XSUnsvGYCkreMVAFkYug+zPJwqqRPeGAwzpQpRL14so+3a7nFxUYhxAO4pTqP0Gzu//ganDqfexAGPRynnKN+1winf5aJhLTNfZ4iwmzaMAC9tZ75gnet7tVWFMOMnHHY7Wsok+hNvrGvtvJCstdQjx1ofIfH8niGn+SP3djlkwm2DDXbOM6ILRP/TrpQ1gr36vvUnvAK04KkhGBY04DHvDQ1jTVg0eialpDyEnBtAdXCUS8oZ8f/AUWpN0FjgJQr4nS7I75jp9L0oLMFlwN05AQqK9M+N2QSdXz6rv/Mm1LrYDGf2v8UaV39+VfGOx77QBU0P3ry5Lv/8tvuR2Nl+RDWY+ctqTM2DqXyEFH06ieY6Wnxy8cHYiRYY5D2NLZJLDuXQWWOojt2QMbRL/BMBXAuIb3mkL6Z1tlpDypKlN1Fr8HxXFCwU8n/kwf8yInykbygQSGR9MF9e88podWp7EEMDhardqWmiMS2JTzgQJDbhpSWreDAT8dcDWT9GEMoFSCpDq+6EfKDZLmClTQsXxBf7xKhGqoXCd120F7d7X2jWx9nc8sbN23QQbiv0iTMo8o2IcYJFds1eJJaLXgDmRZcJ82TD5cDSln1ptvbiGr6sfhwgFY42dw+jUpMfwdIXNKus0g+PtiCRLcdDYSDkQMBY5gssCeGiW02UXt6p8ovTtEUmdZgVhHtiyFoxRe6pR1FvsvpK0suwg5iY4CbVP1ir+lC3yfti+O1pmvf08n19xnzyboUevFFWDZUhc6TTYWckLEUoDYt1Grbt55ntZZv3yFwun3FjQ8iGPl45hSA9b5wjF8Y7oEbKEBO0mjSbGidVDnOEnYsYWWG2lLlkreng+6X/J3thKpidYQqBFFwkjxi0SN9Xq+rnckEpgK0NeugwKGlsQOqpdZcDt3S6jqDFt588HdybVFlxZyzKN3EID6dktfR/PmLOhuInrRcqRy+sCqNpFY8zBSfG81V+wxs1hFnHpV9T2Xm6lyTTJFgZtSoP4XgbQ9lSMcKesucqjCxsuA2UElzjWU+lA/enI6dKPEF7K+YLF+VsLXa0S1iAnH3ojICUQiqKCVTykG9pegGWcn+VqNl3XGu99EE3l5lm36XUe/qLiMSIgOhNgC2A0sMR2ThIVoAPeX2KqGXI6g6n2puTWpoRrGkuNbLfdKMoEDGHVbw0pb6386rhGhXiWbkFv1ShuDobUn8J6vaPnCV3lhyazeeTRz7/6XKdqe9/JeNcH5p5utntRjOyEDvWYfdi/gyTjefBCox7KfGxVVM1y83OBJfLDJj/9AtxoC17RbID9pZuaQuobHTnLiZakrbBDY5tSwt0OQTzWMWZnYJKyMbQ4fq7AIQwhavn6VD+8LyMUSLBufTnwyXdGtDn6twKkg36brmIgjzZgbTNzumsJWgKDlUBRuPHATK0BNG89K+VzoTgsX0vvjKT8WirIGMqqhShGUpV1BNqgo6rWI9c2ox1W1dWcyigGl8Vl0VeJ/TTaXKNjHfthKxyZ88d4JNdHmMdopqHviXVBV44D8/tR5rckmOkD8EDL7RECTUMWDFNpN8n4zEvnMfRYK8T/nVRjFsoy3dWik7M9NbfoVGaxjdjZZNFw0FeGqQrQ8od+8Lb9XI6lUsWylbVkp9Vu4fsvqhVsq1GZn8u6aaDHGqYJex61LAKdVqDyEHb+gYip1R0mrV3MPaiTCExdReh8j4zV1JvnXZB0ufweS/0w09GOp1xhb8XUTuPFjFlzkdb7zmGpDipjMGvAvameSD1zAfxQhBi6ntxL5vCo6xKTB2ZydNtHrtXTUnJUQatRmjILUfJTD+iJowH4XMOM80hmB9GXuMu0srWgVGUws5rpJtPvcfH1WSG1w87J9POZUZE+RTf04J8eAIIHBJPQa14EQCXKM0BbaBCU2YnaExTcqXUwDhYVllTOvK80PNX2GlpLOzEwDu6DbSNiGgdmyNHdT2Xma3yktDgen7tQwcHWcuZTbk5QRliXPCV5Z1pMcit4rG5h6QGUUwSOp8cFsEz156/Z/Q09yfioCDdiP+r0cBCj2CBIO52BotO46SmlN8oaLUJzM1ZWkFBhBKjMcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAgOExge",
        "publicKeyFingerprint": "8407a28bc50529a71ed3fc408f19f8694ef839837e63bb77204833779770b690"
      },
      "Ed25519": {
        "signature": "sWAdA60u5RQHKQ81+GDL5+dSS8DZ0J+nXzCi8zGpuJ9LJ/9rXvsMl7ViDP4Yx9mziaEofFuD5dv7/iiwiZQMCQ==",
        "publicKeyFingerprint": "52fe0441be88692e9fdb3d35e1c196c3d15ee418776945905d3dbf79bef4b60e"
      }
    }
  }
}
