Quantum-safe protection for sensitive information
Encrypt files locally, deliver them to verified recipient devices, authenticate the sender, and control package status through one workspace.
QW-R1 Verified Recipient
Public-key delivery between real QuakWrap devices
Recipient-owned keys: each active device publishes an ML-KEM-768 encapsulation key.
Encrypt once: the file uses one AES-256-GCM content key, independently wrapped for each recipient device.
Authenticated sender: an ML-DSA-65 signature covers the package profile, recipients, policy, nonce, and encrypted payload digest.
Live identity: the opening workflow compares the signed sender key with the active directory record.
How QuakWrap works
Choose the security profile that matches the delivery workflow without changing how the source file is handled.
Protect
The source file is encrypted inside the browser before a package is created.
Address
Choose a portable passphrase or active recipient-owned ML-KEM device keys.
Authenticate
QW-R1 signs the package manifest with the sender device's ML-DSA-65 key.
Control
Register fingerprints, verify status, expire access, and revoke authorization online.
Protection that works in layers
Every component has a defined job, and the package records the exact versioned profile.
View technical validationML-KEM-768
Recipient-owned post-quantum key establishment standardized in NIST FIPS 203
ML-DSA-65
Sender authentication standardized in NIST FIPS 204
AES-256-GCM
Authenticated encryption for the file payload and wrapped content keys
HKDF-SHA-256
Independent key derivation for each recipient device
PBKDF2-SHA-256
Passphrase protection for encrypted device-key backups and portable packages
Available workflows
QW-P1 Portable
Create a self-contained passphrase-protected .quak package for accountless, removable-media, or offline handoff.
QW-R1 Verified Recipient
Encrypt the content key to recipient-owned ML-KEM-768 devices and authenticate the sender with ML-DSA-65.
Private Verify
Confirm a sensitive identifier against an active secret-bound commitment without storing the original value.
Agent API
Connect internal tools and automated workflows through scoped, revocable API credentials.
Useful across personal and industry workflows
Personal records
Protect tax documents, identification records, insurance paperwork, contracts, and other sensitive files.
Professional handoffs
Send legal evidence, engineering exports, client deliverables, and confidential project material to verified devices.
Credential verification
Confirm employee, contractor, license, training, membership, or vendor references against active records.
Field operations
Wrap incident reports, imagery, maps, and exports while keeping source content out of the registry.
IBM Quantum Assurance for enterprise readiness
Optional IBM Quantum work supports readiness demonstrations, education, and migration assessments while customer file protection stays local and efficient.