Post-quantum security and quantum computing, sold by stage
SoftQuantus sells two product lines. QuantumLock protects signatures, licences and cryptographic inventories through the move to post-quantum algorithms. QCOS runs quantum algorithms and leaves a sealed record of every runtime call that a reviewer can recheck.
Each offering below carries its stage today, so you can tell what is in production from what is in preview or still in development.
- In production
- QuantumLock signing, licensing and inventory
- Available
- QCOS simulation, MCP server and verifier
- Preview and development
- Softquantus Cloud HPC and quantum hardware
The catalogue
Every offering, what it solves and how you use it
Stages follow the product lifecycle. A stage changes only when the offering has passed the gate for the next one.
| Offering | What it solves | How you use it | Stage |
|---|---|---|---|
| QuantumLock post-quantum signing | Releases, firmware and documents that must still verify after RSA and ECC can be broken | REST API and Python SDK; ML-DSA (FIPS 204) | In production |
| QuantumLock hybrid signing | Adding a post-quantum signature without dropping the classical one | REST API and Python SDK; accepted only when both signatures verify | In production |
| QuantumLock licensing | Software licences that validate under classical and post-quantum rules | REST API and Python SDK | In production |
| Cryptographic inventory | Knowing which systems still depend on quantum-vulnerable algorithms | Import a CycloneDX 1.6 CBOM and evaluate it against a versioned policy pack | In production |
| QCOS quantum simulation | Running chemistry, optimisation and error-correction algorithms reproducibly | REST API, Python SDK and CLI (softqcos) | Available |
| QCOS MCP server | Letting AI agents run and inspect quantum experiments | MCP server (softqcos-mcp) with 140 tools | Available |
| Evidence verifier | Checking a result without trusting the party that produced it | softquantus-verify, an open-source (MIT) Python package that runs offline | Available |
| Softquantus Cloud HPC | Large simulations without building a GPU cluster | Through Softquantus Cloud, access on request | Preview · request access |
| Softquantus Cloud quantum hardware | Running circuits on trapped-ion, superconducting and neutral-atom machines through one account | Through Softquantus Cloud | In development |
| QuantumLock MCP server | Letting AI agents sign and evaluate inventories | MCP server | In development |
ML-DSA in QuantumLock comes from liboqs and is not CAVP-validated. Results from QCOS today come from simulators; every result carries an execution_mode label that says how it was produced.
Where to start
Start from the problem in front of you
Plan the post-quantum migration
Regulators have put dates on RSA and ECC. See the timeline and the first three steps.
Post-quantum cryptographyFind vulnerable cryptography
Turn a CBOM into a pass, review or fail decision with a reproducible id.
Cryptographic inventorySign for the long term
ML-DSA signatures, alone or alongside a classical signature, from one API.
Quantum-safe signaturesRun quantum algorithms
Chemistry, optimisation, dynamics and error correction, with the conditions of every result stated.
Quantum algorithmsProve a result is unchanged
Records sealed under a SHA-256 Merkle root and rechecked offline.
Verifiable computationConnect AI agents
The QCOS MCP server gives agents the same contract as the API.
MCP integrationInterfaces
One contract, four ways in
Every QCOS capability is defined once in an OpenAPI contract and reached through the interface that fits your team. Packages are versioned on PyPI and changes are listed in the changelog.
REST API
293 documented paths for QCOS, and REST endpoints for QuantumLock signing, licensing and inventory.
Python SDK
softqcos for QCOS, quantumlock-sdk for QuantumLock.
Command line
The softqcos CLI for scripted runs and CI pipelines.
MCP server
softqcos-mcp exposes 140 tools to AI agents. The QuantumLock MCP server is in development.
Tell us which problem comes first
We will map it to the offering that is ready for it today, and say plainly when it is not.