Skip to content
FIPS 140-3 LEVEL 2 · CERTIFIED NIST PQC ALIGNED
PROOF / EVIDENCE DOSSIER

Certifications, awards, and customer outcomes — documented, benchmarked, and third-party validated.

Every claim on this page is backed by an issuing body, a published benchmark, or a customer reference. No marketing superlatives. Below: the credentials Q6of has earned since 2021 and the regulated institutions running our post-quantum stack in production today.

DOSSIER.ID Q6OF-PROOF-2025-Q1 / LAST.VERIFIED 2025-01-14
DOSSIER.HEADER PROOF / 001
  • FIPS 140-3 Level 2 Certified Mar 2024
  • Enterprise customers 312 incl. 14 Fortune 500
  • Crypto operations / day 8.4B+ Across managed estate
  • Control plane SLA 99.997% 12-month rolling
CREDENTIAL STRIP

Recognized by the institutions your security team already trusts.

  • NIST.PQC NIST PQC Co-Author 4 of 7 selected algorithms
  • GARTNER.CV Gartner Cool Vendor Post-Quantum Security — Q2 2024
  • RSA.SB RSA Innovation Sandbox “Most Likely to Succeed” — 2024
  • FORBES.RS Forbes Cloud 100 Rising Stars Class of 2024
  • FIPS.140-3 FIPS 140-3 Level 2 Issued March 2024
  • IN-Q-TEL In-Q-Tel Strategic Investment Series B — Oct 2024
OUTCOME PATTERN / FOUR REGULATED VERTICALS

The same migration methodology delivers consistent outcomes across very different cryptographic estates.

  • CS.02 / FEDERAL-DEFENSE U.S. Federal Civilian Agency

    142,000 PKI certificates rotated against NSA’s CNSA 2.0 deadline.

    • 142,000certificates rotated
    • 19 wkengagement duration
    • 0outages during business hours

    Federal PKI aligned with the Commercial Solutions for Classified (CSfC) program’s post-quantum requirements; CBOM used as continuous monitoring feed.

  • CS.03 / FINTECH Global Payments Processor

    Reduced TLS handshake compute cost by 41% on the merchant API tier.

    • −41%handshake CPU
    • 5.6Bmonthly handshakes protected
    • 9 daysend-to-end rollout

    Hybrid ML-KEM-768 + X25519 deployed at the edge; legacy ECDHE-ECDSA-AES256-GCM retained as a fallback for embedded POS devices on older firmware.

  • CS.04 / HEALTHCARE U.S. National Health Information Exchange

    HIPAA-aligned cryptographic inventory across 47 connecting provider systems.

    • 47connected provider systems inventoried
    • 3,800quantum-vulnerable primitives remediated
    • 100%audit-ready CBOM coverage

    Per-system risk scoring aligned with HHS 405(d) guidance; PHI transmission channels upgraded without breaking any HL7 / FHIR endpoints.

  • CS.05 / CRYPTO CUSTODY Institutional Digital Asset Custodian

    HSM firmware re-keyed against quantum-vulnerable ECDSA in a single maintenance window.

    • 2HSM clusters re-keyed
    • 4 hrmaintenance window
    • $1.8Bassets under custody — zero exposure

    MPC signing ceremonies migrated to a hybrid ML-DSA-65 + Ed25519 scheme; cold-storage signing keys rotated ahead of regulatory sunset on bare ECDSA.

COMPLIANCE DOSSIER / CERTIFICATION INVENTORY

A referenceable inventory of the certifications Q6of has actually obtained.

Issue dates, certifying bodies, and certificate numbers are available under NDA from the Q6of trust center.

  1. 01 SPEC.SHEET 02 / FIPS-140-3

    FIPS 140-3 Level 2

    Cryptographic module validation for the Q6of Crypto Agility Control Plane and the on-prem signing appliance.

    Issued
    March 2024
    Certifying Body
    NIST CAVP & CMVP
    Scope
    Hardware & software modules
  2. 02 SPEC.SHEET 03 / SOC2-T2

    SOC 2 Type II

    Annual audit covering Security, Availability, and Confidentiality trust service criteria across the managed control plane.

    Issued
    December 2024
    Auditor
    Independent registered firm
    Period
    12-month observation window
  3. 03 SPEC.SHEET 04 / ISO-27001

    ISO/IEC 27001:2022

    Information Security Management System certification covering engineering, operations, and customer support functions.

    Issued
    August 2024
    Certifying Body
    UKAS-accredited body
    Scope
    Full ISMS · 3 sites
  4. 04 SPEC.SHEET 05 / GDPR-CNSA2

    GDPR Posture & CNSA 2.0 Alignment

    Documented GDPR data-processing posture with EU/UK SCCs and a CNSA 2.0-aligned product roadmap against the 2033 NSS deadline.

    GDPR DPA
    Published · v3.2
    CNSA 2.0
    Software & firmware signing aligned
    OWASP CBOM
    Reference tool adoption confirmed
NEXT STEP

See your own estate the way we just showed you theirs.

A 30-minute cryptographic risk assessment with a Q6of solutions engineer produces a CBOM of your current estate, a quantum-exposure score against NIST PQC baselines, and a migration roadmap sized to your timeline. No NDA required for the initial call.

  • CBOM inventory of keys, certificates, and algorithm usage across your environment
  • Quantum-vulnerability heatmap aligned with NIST PQC & CNSA 2.0
  • Migration plan with sequencing, risk tiering, and engineering-hour estimates