QRX / Security
Post-quantum readiness

Designed for a cryptographic transition, not a marketing shortcut.

QRX uses hybrid and post-quantum components in selected paths and keeps explicit trust boundaries around wallets, models, runtimes, storage and governance.

Quantum resilience

Hybrid today. Migration-aware tomorrow.

QRX avoids the absolute claim “quantum proof.” Post-quantum readiness means selected cryptographic paths already include PQ-capable components and the architecture is built to evolve as standards, dependencies and audits mature.

Wallet identity

Ed25519 + ML-DSA-65

The current wallet layout uses a hybrid signing identity so users do not have to choose individual key technologies in normal UX.

Hashing & content trust

SHA-3 / content roots

QRX uses content-addressed verification and explicit manifest roots across model/runtime distribution and other trust-sensitive paths.

Boundaries

Fail closed

A PQ-capable component does not magically make every dependency, platform, transport or third-party library post-quantum secure.

Trust model

Separate what is signed from who hosts it.

AURA and related delivery paths separate publisher signatures, package hashes, model catalog signatures, manifest roots, provenance, license policy and governance state.

✓Runtime publisher trust root is not accepted just because a download server supplies it.
✓Model/runtime bytes are content-addressed and verified before activation.
✓Relays are transport infrastructure, not holders of endpoint secrets.
✓Mainnet protocol activation is threshold-signed governance state, not a local configuration file.
What QRX does not claim

Readiness is not certification.

QRX does not claim that every dependency is post-quantum, that every privacy path is metadata-free, or that internal regression tests replace an independent cryptographic/security audit.

Important: “PQ-capable” and “designed for quantum resilience” are engineering claims about architecture and selected components, not a blanket guarantee against all future quantum attacks.
Privacy & data sovereignty

Security is broader than cryptography.

QRX combines wallet-key isolation, encrypted Drive data, permission-separated apps/browser surfaces, optional privacy layers and local-first compute so sensitive work does not have to leave the device by default.

Wallet isolation

Apps request controlled capabilities rather than receiving raw private keys.

Secure browser

Page rendering is separated from wallet/DApp permissions.

Encrypted Drive

Decentralizing ciphertext does not expose decryption keys to storage providers.

Local-first AURA

Compatible work can remain on local hardware before network compute is considered.