QNSP

About QNSP

A Singapore-based deep-tech company building the trust fabric for the post-quantum era.

CUI Labs (Pte.) Ltd. — Singapore-incorporated deep-tech company. QNSP is our flagship platform: verifiable post-quantum cryptography infrastructure for AI, data, and mission-critical systems.

Why we exist

"Harvest now, decrypt later" is no longer a thought experiment. Adversaries are already collecting encrypted traffic that they intend to break with cryptanalytically relevant quantum computers later this decade. Every long-lived secret encrypted with RSA, ECDH, or ECDSA today is on a clock — and the regulated industries that hold the most sensitive long-lived data (finance, defense, healthcare, government) have the least appetite for migration improvisation.

NIST finalised the first batch of post-quantum standards in August 2024 (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA), with FIPS 206 FN-DSA following. CNSA 2.0 gives U.S. federal systems a 2030–2033 migration window. The work is not "discover PQC" — it is "deploy PQC verifiably, with evidence regulators and auditors can check."

That gap — between standards on paper and verifiable deployment — is QNSP.

What we build

QNSP is one platform, four product surfaces:

  • Quantum-safe KMS, vault, and SSE-X storage — ML-KEM, ML-DSA, Falcon, SLH-DSA across 14 algorithm families, with dual-provider cross-verification (liboqs + noble) and per-tenant policy tiers.
  • Hardware-backed key management — 8 HSM vendors, AWS CloudHSM, customer-bring-your-own-HSM, Intel SGX / AMD SEV / AWS Nitro Enclaves for AI workload isolation.
  • Tamper-evident audit + compliance evidence — PQC-signed Merkle-tree audit trail, evidence packs for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, PDPA, MAS TRM.
  • Public verifiability — NIST ACVP conformance vectors (noble 435/435, liboqs 240/240) live at /verify/conformance. Benchmarks at /benchmarks. The crypto path is open to inspection in the public mirror at cuilabs/qnsp-public.

How we work

QNSP is engineered as production infrastructure, not a research project. Every claim the marketing site makes — algorithm coverage, latency, conformance, hardware support — is verifiable from public artefacts. There are no demos, no toy benchmarks, no filler pages dressed up as features. If a capability is on the roadmap, it is labelled as such; if it ships, it ships with evidence.

The platform is built in TypeScript and Rust, runs on AWS in Singapore (ap-southeast-1), and is operated under a strict regulated-buyer-grade engineering discipline: signed audit trails, immutable production change records, deterministic deploys, no shortcuts on cryptographic correctness.

Who we are

CUI Labs was founded in Singapore. We choose Singapore deliberately: it is one of the few jurisdictions with a coherent national posture on AI, cryptography, and financial infrastructure, and the MAS TRM Guidelines and PDPA give us a regulatory baseline that maps cleanly onto the obligations our international customers face.

We work with regulated buyers — financial institutions, defense contractors, healthcare systems, sovereign AI programmes, and critical-infrastructure operators — in Asia, Europe, and North America. We do not court hype cycles. We ship.

Company facts

Legal entity
CUI LABS (PTE.) LTD.
Headquarters
Singapore
Production region
AWS ap-southeast-1
Governing law
Singapore

Registered office

CUI LABS (PTE.) LTD.
552 Ang Mo Kio, Avenue 10, #21-1982
Cheng San Place, Singapore 560552

Contact

For more channels (compliance, billing, support, incident escalation), see the Contact page.