Platform

PILOT

Post-quantum authorization for critical operations

Qryption is a post-quantum authorization platform for IAM, PAM, infrastructure and security teams. In its private pilot, the platform combines the Qryption Key and Qryption SDK to bind physical presence to an ML-DSA proof before a critical operation is authorized and recorded.

Current status: Published information; product availability remains limited to the private pilot where stated.

Private pilotML-DSA signaturesRetrofit integrationReviewed 18 Aug 2026

The authorization gap

Privileged credentials can identify an operator without proving that the expected person is physically present for a specific high-impact action. Qryption is being evaluated as an additional authorization signal for administrative changes, key-management approvals and other critical operations.

The platform is not presented as a replacement for IAM, PAM, HSM or FIDO2. It is designed to add a verifiable post-quantum approval step to an existing control plane.

Platform components

  • Qryption Key: a pilot physical root of trust intended to bind user presence to a cryptographic operation.
  • Qryption SDK: the integration layer for creating challenges, verifying ML-DSA proofs and returning an authorization decision.
  • Existing authorization layer: remains responsible for policy, identity, sessions and the final protected operation.
  • Audit evidence: records the relationship between the request, proof and resulting decision.

Five-step authorization flow

  1. The existing system creates a scoped authorization challenge.
  2. The operator confirms physical presence with the Qryption Key.
  3. The operation is bound to a post-quantum signature.
  4. The verifier checks the proof and policy context.
  5. The system authorizes or denies the action and records evidence.

Status and limitations

Qryption is in private pilot. Public materials do not currently claim product certification, a completed independent security audit, production availability, or compatibility with every IAM/PAM platform. Those properties must be demonstrated through versioned documentation, reproducible tests and pilot evidence before they are stated as product capabilities.

Private pilot

Evaluate the authorization flow in a bounded use case.