Trust centre · Cryptography
Post-quantum migration
Seal is not post-quantum secure today. This page documents what we sign with, what survives a cryptographically relevant quantum computer (CRQC), and the checkpoints that gate the v2 migration to ML-DSA hybrid signing.
The chain hash (SHA-256) is quantum-resilient. Tampering with any past receipt breaks every later chain hash, whatever an attacker can forge. That bounds the blast radius of a future CRQC under DORA, MiFID II, or EU AI Act long-retention obligations.
What we sign with today
Where migration sits
Seal is not post-quantum secure today, and this page says what we sign with now rather than when that changes. The hybrid-signing design and the criteria that would gate a migration are shared with security reviewers on request. Contact us for the detail.
Threat model today
- No risk to receipt confidentiality. v1 receipts contain no plaintext prompt or response. There is nothing for a quantum attacker to decrypt later.
- Forgery risk in the 2030s. A CRQC could forge receipts under issuer keys that were active before migration, and audit-log retention of 5 to 10 years (DORA, MiFID II) intersects that horizon. The checkpoints above gate the migration, not CRQC headlines.
- Chain integrity preserved. The SHA-256 receipt chain stays a quantum-resilient tamper-evidence anchor, so auditors can still bound any possibly forged receipts to those signed under a compromised key.
For enterprise security reviewers
The normative text is ATTESTATION-v1, §12 Post-Quantum Migration. Confidential security disclosures: SECURITY.md.
Last reviewed July 2026 · updated on NIST, ANSSI, or BSI guidance changes