Portable and recipient-bound profiles

Quantum-safe protection for sensitive information

Encrypt files locally, deliver them to verified recipient devices, authenticate the sender, and control package status through one workspace.

ML-KEM-768ML-DSA-65AES-256-GCMLocal encryption

QW-R1 Verified Recipient

Public-key delivery between real QuakWrap devices

Recipient-owned keys: each active device publishes an ML-KEM-768 encapsulation key.

Encrypt once: the file uses one AES-256-GCM content key, independently wrapped for each recipient device.

Authenticated sender: an ML-DSA-65 signature covers the package profile, recipients, policy, nonce, and encrypted payload digest.

Live identity: the opening workflow compares the signed sender key with the active directory record.

How QuakWrap works

Choose the security profile that matches the delivery workflow without changing how the source file is handled.

Protect

The source file is encrypted inside the browser before a package is created.

Address

Choose a portable passphrase or active recipient-owned ML-KEM device keys.

Authenticate

QW-R1 signs the package manifest with the sender device's ML-DSA-65 key.

Control

Register fingerprints, verify status, expire access, and revoke authorization online.

Protection that works in layers

Every component has a defined job, and the package records the exact versioned profile.

View technical validation

ML-KEM-768

Recipient-owned post-quantum key establishment standardized in NIST FIPS 203

ML-DSA-65

Sender authentication standardized in NIST FIPS 204

AES-256-GCM

Authenticated encryption for the file payload and wrapped content keys

HKDF-SHA-256

Independent key derivation for each recipient device

PBKDF2-SHA-256

Passphrase protection for encrypted device-key backups and portable packages

Available workflows

Available

QW-P1 Portable

Create a self-contained passphrase-protected .quak package for accountless, removable-media, or offline handoff.

Available beta

QW-R1 Verified Recipient

Encrypt the content key to recipient-owned ML-KEM-768 devices and authenticate the sender with ML-DSA-65.

Available

Private Verify

Confirm a sensitive identifier against an active secret-bound commitment without storing the original value.

Available

Agent API

Connect internal tools and automated workflows through scoped, revocable API credentials.

Useful across personal and industry workflows

Personal records

Protect tax documents, identification records, insurance paperwork, contracts, and other sensitive files.

Professional handoffs

Send legal evidence, engineering exports, client deliverables, and confidential project material to verified devices.

Credential verification

Confirm employee, contractor, license, training, membership, or vendor references against active records.

Field operations

Wrap incident reports, imagery, maps, and exports while keeping source content out of the registry.

IBM Quantum Assurance for enterprise readiness

Optional IBM Quantum work supports readiness demonstrations, education, and migration assessments while customer file protection stays local and efficient.