Architecture
Two live layers. One named roadmap.
What's built today, and where we're going — clearly labeled, item by item, so you can plan your evaluation against what's real.
Layer 01
Signing Engine
Live
The cryptographic core — crypto-agile by design, built to survive algorithm changes without a platform rewrite.
Zero-downtime algorithm retirement — flip a flag, not a platform.
- Three ML-DSA strengths
- Live
- ML-DSA-44 / 65 / 87 — all FIPS 204 compliant, selectable per keypair.
- Deprecation registry + migration
- Beta
- Retire an algorithm with a dashboard flag; migrate every affected key in a controlled background job.
- KEK rotation
- Live
- Re-encrypt every key at rest on demand — no downtime, full audit trail.
- Public API & SDK
- Early Access
- The REST API already powers Qausal's own frontend; early-access integration partnerships open now.
Layer 02
Document Lifecycle
Live
A complete workflow with multi-party signing, tamper-evident audit trails, and offline-verifiable proof bundles.
Every signer's proof re-checked independently — not just the first signature in the chain.
- Multi-party signing with roles
- Live
- Owner, signer, verifier — decline with a reason, cancel with a comment, both fully audited.
- Visual document journey
- Live
- See who's signed, who's pending, and who declined — with their stated reason.
- Immutable audit trail
- Live
- Tamper-evident and enforced at the database level — even a compromised admin can't alter history.
- Compliance dashboard
- Coming Next
- Map each signed document to the framework driving your requirement — EO 14412, CNSA 2.0, ASD 2030.
- Retention & collection
- Live
- Held for collection, not for custody — we hold it to sign it, and briefly so you can collect it. Never to keep it.
Layer 03
Archival Vault
Coming Next
The Regulated / Archival tier — adds independent, third-party time-witnessing on top of the signature-bound proof you already get today.
Independently witnessed timestamps — not just tamper-evident ones.
- Dual-anchor timestamping
- Coming Next
- An accredited external Time-Stamping Authority plus a public blockchain anchor — not a self-issued re-sign.
- Built on today's crypto-agility engine
- Beta
- Runs on the same deprecation registry and migration infrastructure that's already built and tested — not a from-scratch promise.
- Retention policies
- Coming Next
- Configurable to your obligations: 7 years for tax, 30+ for property, lifetime for medical.
- Standards-compliant export
- Coming Next
- PDF/A and PAdES output, so archives outlive any one vendor — including us.
- Archival custody
- Coming Next
- For when you want us to hold it too. Not built today — the vault is roadmap.
If long-term archival is a requirement for your evaluation timeline, talk to us.