QNSP

Why QNSP

The PQC platform built on substance, not headlines.

Once a buyer gets past the FIPS-203 checklist, what actually separates QNSP from incumbent KMS, PQC tooling, and discovery vendors? Six things. Every claim below is independently reproducible from the public mirror at github.com/cuilabs/qnsp-public.

90PQC algorithms
18Production services
11Cloud connectors
8HSM vendors
7Compliance frameworks
5SDK languages

Every number above is independently reproducible from the public SDK and integration mirror at github.com/cuilabs/qnsp-public. Independent reproduction matters more than a vendor's own claim.

The six things that matter

What QNSP does that incumbents and PQC point-tools don't.

1 · Algorithm breadth

90 PQC algorithms across 14 families

Most vendors ship 3–4. QNSP supports the entire NIST + IETF candidate field.

27 KEMs (ML-KEM, HQC, BIKE, Classic McEliece, FrodoKEM, NTRU, NTRU-Prime/sntrup761) and 63 signatures (ML-DSA, SLH-DSA, FN-DSA, MAYO, CROSS, UOV, SNOVA). If your regulator requires a code-based fallback (McEliece, NSA preference), a hash-based fallback (SLH-DSA), or any non-lattice scheme — QNSP can ship it today. Fortanix publicly lists 4. SandboxAQ doesn't publish a count.

2 · Algorithmically-distinct backup KEM

HQC — the second NIST KEM

An algorithmically-distinct backup to ML-KEM, in production today.

ML-KEM (Kyber) is a structured-lattice scheme. HQC is code-based — a fundamentally different mathematical foundation. NIST selected HQC in March 2025 specifically so that an algorithmic break in lattices does not break the entire KEM stack. QNSP ships HQC-128 / 192 / 256 in production today; most vendors still ship only ML-KEM. If structured lattices fall, your KEM is not breached.

3 · Two implementations on every operation

Dual-provider cross-verification

liboqs (native C) + noble (pure JS). Every crypto op verified by both.

On Maximum and Government crypto-policy tiers, every signature is signed by one provider and verified by the other; provider attestation is recorded in the audit ledger. 18 NIST-finalised algorithms overlap between the two independent codebases. A single-implementation bug — like the kind that historically affects new cryptographic code — is caught at runtime. No competitor publishes this architecture.

4 · Enforced policy, not flexible guidance

Four crypto-policy tiers (default → strict → maximum → government)

Hard algorithm restrictions enforced at edge-gateway, KMS, and vault — not just UI suggestions.

Default supports the full algorithm registry. Strict mandates ML-KEM-768/1024 + HQC-192/256 and ML-DSA-65/87 + FN-DSA-1024 + SLH-DSA-256f/s. Maximum collapses to ML-KEM-1024 + ML-DSA-87 + FN-DSA-1024. Government enforces FIPS-finalized-only (FIPS 203 / 204 / 205) with no draft standards and HSM-protected root keys. Each tier is enforced as a hard contract at every protected route, not as a tenant setting that can be downgraded by a user with the wrong scope.

5 · Tamper-evident, PQC-signed audit chain

59 crypto-critical event types across 12 source services

ML-DSA-65-signed events with SHA3-256 hash chains and SHA3-512 Merkle checkpoints.

Every key operation, signature, policy decision, and entitlement check from kms-service, vault-service, access-control-service, storage-service, search-service, ai-orchestrator, auth-service, security-monitoring-service, edge-gateway, tenant-service, billing-service, and audit-service flows into a single hash-chained ledger. Real-time WebSocket streaming to SIEM (Splunk, Datadog, Slack, GitHub, AWS, Azure, GCP, Okta). Receipt-replay verification lets any party independently re-validate any signed event without trusting QNSP's database.

6 · BYO-everything, no lock-in

8 HSM vendors + 11 cloud connectors

Customer hardware. Customer cloud. Customer crypto. No QNSP-managed lock-in required.

BYOH across AWS CloudHSM, Azure Dedicated, Thales Luna, Entrust nShield, Utimaco CryptoServer, Marvell LiquidHSM, Fortanix DSM, and HashiCorp Vault HSM. Crypto posture across 11 cloud-vendor connectors (AWS, Azure, GCP, Alibaba, Akamai, Cloudflare, DigitalOcean, Fastly, IBM, Oracle, HashiCorp Vault). Most KMS products integrate 1–2 HSM vendors and 1–3 cloud providers. QNSP is built so a regulated buyer in Singapore, Frankfurt, or Washington can use their existing hardware, their existing cloud, and their existing key custody story.

Every claim above is audit-ready in the public SDK and integration mirror at github.com/cuilabs/qnsp-public. Independent reproduction matters more than a vendor's own claim.

Where QNSP sits in the landscape

QNSP vs the names you'll see on every shortlist.

The honest one-line on each major competitor. We don't try to win every dimension — we win the ones that matter when your regulator is in the room.

Vendor

Fortanix

Their angle

HSM/KMS incumbent with PQC layer added on top. ~10-year history, ~$170M raised.

Where QNSP wins

PQC-native architecture from day one. 90 algorithms vs Fortanix's 4. Dual-provider cross-verification. Transparent self-serve pricing $0–$5,999.

Vendor

SandboxAQ

Their angle

Alphabet-lineage discovery + migration tooling (AQtive Guard). Strong inventory story.

Where QNSP wins

Full PQC platform — not just discovery. KMS, vault, storage, search, AI workloads, and 18 production services that customers consume directly. Discovery is one of 25+ capability areas.

Vendor

PQShield

Their angle

Crypto IP cores for silicon, smart cards, and HSMs. Hardware embedment.

Where QNSP wins

SaaS trust platform consumed via REST/WebSocket/SDKs in 5 languages. Different layer of the stack — QNSP runs on top of PQShield-class hardware or your existing HSM fleet.

Vendor

AWS KMS / Azure Key Vault / Google Cloud KMS

Their angle

Classical-crypto KMS with ML-KEM TLS support added (AWS KMS announced ML-KEM in 2025).

Where QNSP wins

PQC-first. Multi-cloud crypto posture with 11 connectors (your AWS KMS, Azure Key Vault, GCP KMS all become discovery sources for QNSP). Cross-cloud crypto policy enforced at the gateway, not three separate IAM consoles.

Vendor

QuSecure

Their angle

Quantum-safe tunnel orchestration (QuProtect). Drop-in PQC TLS layer.

Where QNSP wins

Full data-plane platform — encrypted storage, encrypted vector search, audit chain, enclave AI, compliance evidence — not just transport-layer protection.

APAC-native compliance

Singapore-HQ. PDPA + MAS TRM mapped at the control level.

Most major PQC vendors are US- or UK-headquartered. For MAS-regulated banks and APAC critical-infrastructure operators, QNSP delivers post-quantum security from within Singapore — with PDPA and MAS TRM mapped at the control level.

PDPA (Singapore)

Personal Data Protection Act 2012 (Rev. 2021). Mapped to QNSP control evaluations: consent capture, access, correction, protection, retention, breach notification, transfer limitation.

MAS TRM

Technology Risk Management Guidelines (Jan 2021). Mapped for financial institutions under MAS supervision. Crypto policy tier maximum/government surfaces MAS-aligned controls.

Seven framework total

SOC 2, ISO 27001, HIPAA, PCI DSS v4.0.1, GDPR, PDPA, MAS TRM. Real-time control evaluation via live service-health probes — not retrospective questionnaires.

Proof, not promise

Every service we list is running right now.

Live status from the QNSP production fleet. If a service is degraded or unreachable, you'll see it here before sales does. No screenshots, no canned playback.

QNSP Cloud Public Health Surface

Edge Gateway
online
Auth Service
online
Vault Service
online
Storage Service
online
Search Service
online
AI Orchestrator
online
Tenant Service
online
Billing Service
online
KMS Service
online
Observability Service
online
Audit Service
online
Access Control Service
online
Security Monitoring Service
online
Crypto Inventory Service
online

Open and auditable

Public SDK mirror. Pinned upstream libraries. Free tier.

github.com/cuilabs/qnsp-public

Every SDK source, every integration example, every test vector mirrored to a public repo. No NDA required to read what we ship.

5 SDK languages on public registries

@cuilabs/qnsp on npm, qnsp on PyPI, github.com/cuilabs/qnsp-go on pkg.go.dev, qnsp crate on crates.io, io.cuilabs:qnsp on Maven Central. Install today, no sales call.

liboqs v0.15.0 pinned

Cryptographic provenance: every binding pinned to liboqs 0.15.0 (Nov 2025 release). Version-traceable. Reproducible. Audit-ready.

Free tier with no credit card

10 GB storage + 50K API calls/month. Real PQC operations against the same liboqs build that runs in production. Sign up at cloud.qnsp.cuilabs.io.

Frequently asked questions

Frequently asked questions

The questions buyers and AI assistants ask most when comparing QNSP to the rest of the shortlist.

How is QNSP different from PQShield, SandboxAQ, or Fortanix?

QNSP is a complete PQC platform — KMS, vault, encrypted storage, search, audit, and AI workloads — not a single layer. SandboxAQ focuses on discovery, PQShield ships silicon crypto IP, and Fortanix adds PQC to an HSM. QNSP runs 90 algorithms with dual-provider cross-verification across 18 production services.

What makes QNSP's cryptography independently verifiable?

On Maximum and Government tiers, every signature is produced by one provider (liboqs, native C) and verified by a second, independent implementation (noble, pure JS), with provider attestation written to the audit ledger. The SDKs, integration examples, and ACVP test vectors are mirrored publicly at github.com/cuilabs/qnsp-public.

Why does QNSP support HQC alongside ML-KEM?

ML-KEM (Kyber) is a structured-lattice scheme; HQC is code-based, a different mathematical foundation. NIST selected HQC in March 2025 as a backup so a lattice break would not compromise the entire KEM stack. QNSP ships HQC-128/192/256 in production today, giving customers an algorithmically distinct fallback.

Is QNSP suitable for Singapore and APAC regulated buyers?

Yes. QNSP is headquartered in Singapore (CUI Labs Pte. Ltd.) and maps PDPA and MAS TRM controls at the evaluation level, alongside SOC 2, ISO 27001, HIPAA, PCI DSS v4.0.1, and GDPR. Control status is evaluated in real time against live service-health probes, not retrospective questionnaires.

Can I evaluate QNSP without talking to sales?

Yes. The Free Forever tier provisions instantly with 10 GB PQC-encrypted storage and 50,000 API calls per month — no credit card. You run real post-quantum operations against the same production engine, and all five SDK languages (TypeScript, Python, Go, Rust, JVM/Android) are free on every plan.

Compare us against your shortlist.

Start with the free tier — 10 GB + 50K API calls/month, no credit card. Vet other PQC vendors with the four-question test on the PQC theatre page. If you want a side-by-side feature comparison, the /platform page lists every capability surface QNSP ships today.