QNSI

Why QNSI

The PQC platform built on substance, not headlines.

Once a buyer gets past the FIPS-203 checklist, what separates QNSI from incumbent KMS, PQC tooling, and discovery vendors? Six evidence-linked differentiators, each with its scope and limitations visible.

87PQC algorithms
18Manifest-declared services
11Cloud connector families
8HSM connector implementations
7Compliance mappings
6SDK languages

The catalog counts above are recomputed from QNSI's public sources and mirrored at github.com/heossihq/qnsi-public. Independent reproduction matters more than a vendor's own claim.

The six things that matter

What QNSI does that incumbents and PQC point-tools don't.

1 · Algorithm breadth

87 PQC algorithms across 13 families

A broad migration catalog spanning finalized standards and candidate families.

24 KEMs and 63 signatures are present in the catalog for policy, interoperability, conformance, and migration work. Algorithm presence does not establish production route support, regulatory approval, or deployment qualification; evaluate the exact family, operation, provider, and evidence required.

2 · Algorithmically-distinct backup KEM

Code-based KEMs - a non-lattice backup to ML-KEM

Algorithmically-distinct migration options alongside ML-KEM.

ML-KEM is a structured-lattice scheme, while Classic McEliece and BIKE are code-based alternatives. QNSI catalogs both for policy, interoperability, and migration evaluation. Catalog presence does not prove that every service route or deployment supports them. HQC remains excluded while the pinned cryptographic provider disables the relevant implementation.

3 · Dual-provider verification policy

Dual-provider cross-verification

liboqs (native C) + noble (pure JS) on their overlapping surface.

Maximum and Government policy sources can require cross-verification between the two providers for supported overlapping algorithms. Exact operation coverage, comparison semantics, failure handling, provider attestation, and audit ingestion must be verified for the target deployment.

4 · Enforced policy, not flexible guidance

Four crypto-policy tiers (default → strict → maximum → government)

Hard algorithm restrictions enforced at edge-gateway, KMS, and vault - not just UI suggestions.

Default supports the full algorithm registry. Strict and Maximum narrow the permitted algorithms. Government enforces FIPS-finalized-only algorithms and an HSM-custody requirement. The requirement fails closed unless a qualified HSM path is active; policy selection alone is never evidence of hardware custody.

5 · Tamper-evident, PQC-signed audit chain

Audit-chain and checkpoint contracts

Hash chaining, Merkle checkpointing, receipt verification, and PQC signing boundaries.

The source defines crypto-critical event contracts, hash chaining, Merkle checkpoints, receipt verification, and outbound integration surfaces. Complete producer coverage, real-time delivery, root publication, and successful independent replay remain NOT VERIFIED without deployment evidence.

6 · BYO-everything, no lock-in

8 HSM connector implementations + 11 cloud-vendor connector families

Customer hardware. Customer cloud. Customer crypto. No QNSI-managed lock-in required.

QNSI implements six PKCS#11 HSM connectors and two REST custody backends. Each named backend is enabled only after live qualification. Crypto-posture contracts span 11 cloud-vendor connector families and 36 inventory source types without treating source presence as proof of observed estate coverage or custody.

Review the public SDK, source, and integration evidence-together with each stated runtime boundary-at github.com/heossihq/qnsi-public. Independent reproduction matters more than a vendor's own claim.

Where QNSI sits in the landscape

QNSI vs the names you'll see on every shortlist.

The honest one-line on each major competitor. We don't try to win every dimension - we win the ones that matter when your regulator is in the room.

Vendor

Fortanix

Their angle

HSM, KMS, secrets, tokenization, and confidential-computing platform.

Where QNSI wins

QNSI focuses on PQC-native policy and migration across a 87-entry algorithm catalog, public conformance evidence, and explicit provider and qualification boundaries. Compare exact operations rather than catalog totals alone.

Vendor

SandboxAQ

Their angle

Alphabet-lineage discovery + migration tooling (AQtive Guard). Strong inventory story.

Where QNSI wins

Full platform scope beyond discovery: KMS, vault, storage, search, AI workloads, and 18 manifest-declared services. Each public capability states its source and production-evidence boundary.

Vendor

PQShield

Their angle

Crypto IP cores for silicon, smart cards, and HSMs. Hardware embedment.

Where QNSI wins

Trust infrastructure consumed through REST, WebSocket, and 6 SDK languages. It operates at a different layer and can integrate with qualified customer custody hardware.

Vendor

AWS KMS / Azure Key Vault / Google Cloud KMS

Their angle

Cloud-native key-management services integrated with their respective provider estates.

Where QNSI wins

PQC-first. Multi-cloud posture contracts span 11 connector families; AWS KMS, Azure Key Vault, and GCP KMS can become discovery sources after configuration and qualification. Tenant policy is enforced at the QNSI boundary.

Vendor

QuSecure

Their angle

Quantum-safe tunnel orchestration (QuProtect). Drop-in PQC TLS layer.

Where QNSI wins

Full data-plane platform - encrypted storage, encrypted vector search, audit chain, enclave AI, compliance evidence - not just transport-layer protection.

APAC-native compliance

Singapore-HQ. PDPA + MAS TRM mapped at the control level.

Most major PQC vendors are US- or UK-headquartered. For MAS-regulated banks and APAC critical-infrastructure operators, QNSI delivers post-quantum security from within Singapore - with PDPA and MAS TRM mapped at the control level.

PDPA (Singapore)

Personal Data Protection Act 2012 (Rev. 2021). Mapped to QNSI control evaluations: consent capture, access, correction, protection, retention, breach notification, transfer limitation.

MAS TRM

Technology Risk Management Guidelines (Jan 2021). Mapped for financial institutions under MAS supervision. Crypto policy tier maximum/government surfaces MAS-aligned controls.

Seven framework total

SOC 2, ISO 27001, HIPAA, PCI DSS v4.0.1, GDPR, PDPA, MAS TRM. Real-time control evaluation via live service-health probes - not retrospective questionnaires.

Proof, not promise

Production service status, reported live.

Current health telemetry from the QNSI production fleet. A healthy response establishes reachability at the recorded time; it does not by itself prove complete feature behavior, cryptographic execution, or assurance.

QNSI Cloud Public Health Surface

Edge Gateway
online
Auth Service
online
Vault Service
online
Storage Service
online
Search Service
online
AI Orchestrator
online
Tenant Service
online
Billing Service
online
KMS Service
online
Observability Service
online
Audit Service
online
Access Control Service
online
Security Monitoring Service
online
Crypto Inventory Service
online

Open and auditable

Public SDK mirror. Pinned upstream libraries. Free tier.

github.com/heossihq/qnsi-public

Published SDK source, integration examples, and test-vector evidence are mirrored to a public repository. The mirror's manifest defines the included scope; no NDA is required to inspect it.

5 SDK languages on public registries

@heossihq/qnsi on npm, qnsi on PyPI, github.com/heossihq/qnsi-public/sdks/go/qnsi on pkg.go.dev, qnsi on crates.io, and com.heossi:qnsi on Maven Central. Install today, no sales call.

liboqs v0.15.0 pinned

Cryptographic provenance: every binding pinned to liboqs 0.15.0 (Nov 2025 release). Version-traceable. Reproducible. Audit-ready.

Free tier with no credit card

10 GB storage + 50K API calls/month. Real PQC operations against the same liboqs build that runs in production. Sign up at cloud.qnsi.heossi.com.

Frequently asked questions

Frequently asked questions

The questions buyers and AI assistants ask most when comparing QNSI to the rest of the shortlist.

How is QNSI different from PQShield, SandboxAQ, or Fortanix?

QNSI combines KMS, vault, encrypted storage, search, audit, and AI workload surfaces rather than addressing one layer. Its catalog contains 87 algorithms and its policy source can require dual-provider checks on the overlapping provider surface. Complete runtime coverage remains operation- and deployment-specific.

What makes QNSI's cryptography independently verifiable?

QNSI publishes reproducible ACVP-vector evidence and a public source mirror. Maximum and Government policy sources can require liboqs/noble cross-verification on their overlapping surface. Exact operation coverage, provider attestation, failure handling, and audit ingestion must be verified separately for the target deployment.

Why does QNSI ship code-based KEMs alongside ML-KEM?

ML-KEM is a structured-lattice scheme, while Classic McEliece and BIKE are code-based alternatives. QNSI catalogs these families for migration and interoperability work, but catalog presence does not prove that every service route supports them or that a deployment has approved them for production use.

Is QNSI suitable for Singapore and APAC regulated buyers?

QNSI is operated by Singapore-headquartered HEOSSI (PTE.) LTD and publishes source-level mappings for PDPA, MAS TRM, SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR. Those mappings and health-derived status are not legal advice, certification, or proof of control effectiveness.

Can I evaluate QNSI without talking to sales?

Yes. The Free Forever tier publishes storage, API, KMS, vault, and SDK allocations with no credit card. Package or entitlement availability does not prove every operation, envelope, audit effect, or transport path; evaluate the exact service route and returned evidence.

Compare us against your shortlist.

Start with the free tier - 10 GB + 50K API calls/month, no credit card. Vet other PQC vendors with the four-question test on the PQC theatre page. If you want a side-by-side feature comparison, the /platform page lists every capability surface QNSI ships today.