Security

AVAILABLE

Security scope and explicit limitations

Qryption is evaluating an additional authorization proof for critical operations; it is not a complete security boundary by itself. Security depends on trustworthy challenge creation, operation binding, ML-DSA verification, key lifecycle, host integrity, policy enforcement and auditable failure handling across the integrating system.

Current status: Published information; product availability remains limited to the private pilot where stated.

Threat-model baselineFail closedNo audit claimDisclosure: contact@qryption.io

Assets and trust boundaries

The protected assets are the authorization decision, the integrity of the operation context, the private signing material, verifier configuration and resulting audit evidence. Trust boundaries exist between the host application, SDK, physical key, verifier and the service that performs the protected operation.

Threats considered during pilot evaluation

  • Stolen or lost physical key.
  • Compromised host or misleading operation display.
  • Replay, relay and challenge substitution.
  • Algorithm or protocol downgrade.
  • Verifier misconfiguration and key lifecycle failures.
  • Firmware, build and supply-chain compromise.

Failure behavior

A missing, expired or invalid proof must not silently degrade to a weaker authorization path. Recovery and break-glass procedures belong to organizational policy and must be separately authenticated, logged and reviewed.

Assurance status and disclosure

No independent product audit, FIPS validation, Common Criteria certification or regulatory compliance claim is published for Qryption. Security researchers can report a potential issue to contact@qryption.io. Do not include active secrets or personal data in an initial report.

Private pilot

Evaluate the authorization flow in a bounded use case.