Sign today what must still verify after 2030
Releases, firmware, contracts and licences are verified for years after they are signed. QuantumLock adds ML-DSA signatures to them now, alone or next to the classical signature your verifiers already check.
- Algorithm
- ML-DSA (FIPS 204)
- Modes
- Post-quantum or hybrid
- Interfaces
- REST API and Python SDK
The problem
A signature is a promise that has to outlast its algorithm
When RSA and ECC can be broken, a forged signature on a new release looks exactly like a real one to a verifier that still trusts those algorithms. Artifacts with long lives, such as device firmware, signed documents and software licences, need a post-quantum signature before that day, not after it.
Your files stay with you
You hash the artifact locally and send only the digest. QuantumLock never receives the file.
Hybrid keeps today's verifiers working
The classical signature stays in place while the ML-DSA signature is added beside it.
One service for signing and licensing
One service covers artifact signatures and licence validation.
How it works
From artifact to verified signature
- 01
Hash locally
Compute the digest of the release, firmware image or document on your own systems.
- 02
Request a signature
Send the base64 digest to QuantumLock and choose post-quantum (ML-DSA) or hybrid (classical and ML-DSA).
- 03
Distribute
Ship the signature with the artifact, as you do today.
- 04
Verify
Verification of a hybrid pair succeeds only when both signatures verify.
Options
Choose the mode that fits your verifiers
| Option | What it does | When to use it | Stage |
|---|---|---|---|
| Post-quantum signing | Signs a digest with ML-DSA | New artifacts whose verifiers already accept ML-DSA | In production |
| Hybrid signing | Signs a digest with a classical key and an ML-DSA key; both must verify | During the transition, while some verifiers still expect a classical signature | In production |
| Hybrid licence validation | Validates a software licence under classical and post-quantum rules | Licensing that must move with the rest of the estate | In production |
ML-DSA in QuantumLock comes from liboqs. It implements the FIPS 204 algorithm and is not CAVP-validated.
Questions
Signing questions buyers ask first
Does my file leave our network?
No. You send a digest, not the artifact. QuantumLock signs the digest and returns the signature.
Why hybrid instead of post-quantum only?
Hybrid lets verifiers that only know classical algorithms keep working while you add post-quantum protection. A forger would have to break both schemes for a hybrid pair to fail.
Is the ML-DSA implementation validated?
QuantumLock uses ML-DSA from liboqs, which is not CAVP-validated. If your policy requires a validated module, raise it before procurement.
Where do I start if I do not know what we sign today?
Start with a cryptographic inventory. It shows which systems rely on quantum-vulnerable signatures.
Sign one artifact with us
Bring a release or a firmware image to a demo and leave with a hybrid signature and a verification you can repeat.