AqtaAqta

Trust centre · Cryptography

Post-quantum migration

Seal is not post-quantum secure today. This page documents what we sign with, what survives a cryptographically relevant quantum computer (CRQC), and the checkpoints that gate the v2 migration to ML-DSA hybrid signing.

The chain hash (SHA-256) is quantum-resilient. Tampering with any past receipt breaks every later chain hash, whatever an attacker can forge. That bounds the blast radius of a future CRQC under DORA, MiFID II, or EU AI Act long-retention obligations.

What we sign with today

Ed25519 attestation signature
The signature on every receipt. Proves the gateway, not an imposter, made the decision.
Used in: Every receipt on every gateway request
RFC 8032. Forgeable under Shor against any captured public key once a CRQC exists.
Classical only
SHA-256 chain hash
The fingerprint that links each receipt to the previous one for the same org. Tampering breaks the chain.
Used in: Per-receipt live chain (chain integrity)
Grover gives 2x speedup, ~128-bit residual security. Chain integrity preserved.
PQ-resilient
SHA-256 commitments inside the record
The fingerprints a record carries in place of the prompt and request, or an agent's tool arguments and declared intent. Not the signed message: Ed25519 signs the canonical JSON bytes directly, hashing them internally with SHA-512 as part of the algorithm.
Used in: request_hash, args_hash, intent_hash
Same Grover argument as the chain hash.
PQ-resilient
AES-256 (data at rest, when used)
Symmetric encryption for any persisted data. Prompts and responses are not stored, so this surfaces only for retention metadata.
Used in: Encrypted columns, KMS keys
~128-bit residual against Grover. Acceptable.
PQ-resilient

In research, not shipped

Schnorr proof on BN254 G1
A proof of knowledge bound to the public record of one enforcement decision. It does not show that the policy check ran; a proof that does, without revealing the request, is an open research question.
Status: Research only; not part of any receipt
Discrete-log assumption on an elliptic curve; Shor breaks it.
Classical only
Groth16 proof on BN254
A succinct proof of membership in a fixed list, without revealing which entry. A verifier runs over a fixed demo circuit; per-request proving is not shipped.
Status: Research only; not part of any receipt
Bilinear-pairing soundness; Shor breaks it.
Classical only

Where migration sits

This page says what we sign with now rather than when that changes. The hybrid-signing design and the criteria that would gate a migration are shared with security reviewers on request. Contact us for the detail.

Threat model today

  • No risk to receipt confidentiality. v1 receipts contain no plaintext prompt or response. There is nothing for a quantum attacker to decrypt later.
  • Forgery risk in the 2030s. A CRQC could forge receipts under issuer keys that were active before migration, and audit-log retention of 5 to 10 years (DORA, MiFID II) intersects that horizon. The checkpoints above gate the migration, not CRQC headlines.
  • Chain integrity preserved. The SHA-256 receipt chain stays a quantum-resilient tamper-evidence anchor, so auditors can still bound any possibly forged receipts to those signed under a compromised key.

For enterprise security reviewers

The normative text is ATTESTATION-v1, §12 Post-Quantum Migration. Confidential security disclosures: SECURITY.md.

Last reviewed July 2026 · updated on NIST, ANSSI, or BSI guidance changes