The authorization gap
Privileged credentials can identify an operator without proving that the expected person is physically present for a specific high-impact action. Qryption is being evaluated as an additional authorization signal for administrative changes, key-management approvals and other critical operations.
The platform is not presented as a replacement for IAM, PAM, HSM or FIDO2. It is designed to add a verifiable post-quantum approval step to an existing control plane.
Platform components
- Qryption Key: a pilot physical root of trust intended to bind user presence to a cryptographic operation.
- Qryption SDK: the integration layer for creating challenges, verifying ML-DSA proofs and returning an authorization decision.
- Existing authorization layer: remains responsible for policy, identity, sessions and the final protected operation.
- Audit evidence: records the relationship between the request, proof and resulting decision.
Five-step authorization flow
- The existing system creates a scoped authorization challenge.
- The operator confirms physical presence with the Qryption Key.
- The operation is bound to a post-quantum signature.
- The verifier checks the proof and policy context.
- The system authorizes or denies the action and records evidence.
Status and limitations
Qryption is in private pilot. Public materials do not currently claim product certification, a completed independent security audit, production availability, or compatibility with every IAM/PAM platform. Those properties must be demonstrated through versioned documentation, reproducible tests and pilot evidence before they are stated as product capabilities.