Skip to main content
QCOS LedgerAdd-on

Compliance & Governance for Quantum Execution

Cryptographically signed evidence bundles. Immutable audit trails. Cost governance. The trust layer enterprises and governments require.

From benchmark to legally defensible evidence. Ledger doesn't measure anything — it protects the truth of what was measured.

ML-DSA (FIPS 204) SignaturesSOC 2 / ISO 27001 ReadyRequires QCOS Platform
Core Capabilities

Trust Infrastructure for Quantum

Every execution produces verifiable evidence. Every cost is tracked. Every decision is auditable.

Evidence Bundles

Every quantum job execution produces a cryptographically signed bundle containing circuit hash, parameters, calibration snapshot, results, and full provenance chain.

SHA-256 content hashesML-DSA post-quantum signaturesSLSA Level 3 provenance

Cost Governance

FinOps integration with real-time cost tracking, budget enforcement, and chargeback reporting. Know exactly what each team, project, and workload costs.

Budget soft/hard limitsPer-project chargebackCost estimation pre-submit

Audit Trail

Immutable record of every execution decision — who ran what, when, on which backend, with what parameters, and what it cost. Tamper-evident by design.

Full job lifecycleUser attributionBackend selection rationale

Compliance Export

Export evidence bundles and audit logs in formats required by SOC 2, ISO 27001, and government procurement. Machine-readable, human-verifiable.

SOC 2 Type IIISO 27001Government audit
Technical Specification

Evidence Bundle Format

Every execution produces a complete, self-contained evidence bundle.

evidence_bundle.json
{
  "bundle_id": "QCOS-20260107-a1b2c3d4",
  "version": "1.0.0",
  "job_id": "job-7f3a9b2e1c8d",
  "tenant_id": "org_enterprise",
  
  "circuit_hash": "sha256:7f3a9b...",
  "parameters": {
    "shots": 4096,
    "backend": "ibm_kyiv",
    "optimization_level": 3
  },
  
  "calibration_snapshot": {
    "timestamp": "2026-01-07T10:30:00Z",
    "version": "cal_v2.3.1"
  },
  
  "results": {
    "counts": {"00": 2048, "11": 2048},
    "execution_time_ms": 1234
  },
  
  "provenance": {
    "submitted_by": "user@corp.com",
    "submitted_at": "2026-01-07T10:29:55Z",
    "scheduled_at": "2026-01-07T10:29:56Z",
    "executed_at": "2026-01-07T10:30:00Z"
  },
  
  "cost": {
    "estimated_usd": 0.45,
    "actual_usd": 0.42,
    "pricing_version": "2026-01"
  },
  
  "signature": {
    "algorithm": "ML-DSA-65",
    "public_key_id": "sq-2026-01",
    "signature": "base64:...",
    "timestamp": "2026-01-07T10:30:05Z"
  }
}
1

circuit_hash

SHA-256 of the quantum circuit definition

2

parameters

Job configuration and execution parameters

3

calibration_snapshot

Backend calibration state at execution time

4

results

Raw measurement outcomes and aggregated counts

5

provenance

Full chain: user → scheduler → backend → result

6

cost

Actual cost calculation with pricing breakdown

7

signature

ML-DSA-65 post-quantum cryptographic signature

Who Needs Ledger

Built for Regulated Environments

Government & Defense

Sovereignty requirements, security clearance workflows, and audit mandates. Every execution traceable, every result verifiable.

Pain point: Cannot use cloud quantum without audit trail

Regulated Industries

Financial services, healthcare, and critical infrastructure. Compliance is not optional — it's a prerequisite for quantum adoption.

Pain point: Auditors require proof of execution integrity

Enterprise Procurement

Large organizations with multi-vendor quantum strategies. Need independent verification of what they're paying for.

Pain point: No visibility into quantum spend by team/project

Research Institutions

Reproducibility requirements for peer review. Signed evidence bundles provide third-party verifiable proof of results.

Pain point: Cannot prove research reproducibility

Compliance

Export-Ready for Audits

Ledger evidence bundles are designed to satisfy common compliance frameworks.

SOC 2 Type II

Service organization controls for security, availability, and confidentiality

ISO 27001

Information security management system standard

GDPR

European data protection regulation compliance

FedRAMP

US federal government cloud security authorization (roadmap)

Pricing

Enterprise Add-on

QCOS Ledger is available as an annual subscription for QCOS Enterprise customers.

Starting at

Contact Sales

Annual subscription

  • Unlimited evidence bundles
  • 1-year data retention (extendable)
  • Compliance export (SOC 2, ISO 27001)
  • Dedicated compliance support
Request Quote

Quantum execution you can prove

From benchmark to legally defensible evidence. Close institutional contracts with confidence.

Compliance & governance updates

New certifications, regulatory guidance, and quantum compliance best practices.