Security at Qopanza

What this service does with your data, and where it actually stands. Every claim here names a specific mechanism, so you can check it.

How your data is handled

Real post-quantum cryptography, or it will not start
ML-KEM-768 for key encapsulation and ML-DSA-65 for signatures, through liboqs — the NIST-standardised algorithms, not a simulation of them. A simulated backend exists for development on machines without a C toolchain, and the service refuses to boot on it outside development: cryptographically inert code that returns correctly-shaped values would look perfectly healthy while providing none of what this product is sold for.
Your key material is never stored beside the data it protects
Private keys are envelope-encrypted, and the wrapping key is never in the application database — so a database compromise alone does not yield usable keys. On qopanza.com that wrapping key is held in the service environment. KMS backends are supported and are what we recommend for self-hosted and enterprise deployments: HashiCorp Vault's transit engine, or AWS, GCP and Azure KMS, which move the key off the host entirely. We will say here when the hosted service moves to one.
The audit log is tamper-evident, and we say which one that is
Every entry carries a hash of its predecessor, so an altered or deleted entry breaks the chain and the break is detectable. That is tamper-EVIDENCE, not tamper-proofing: anyone able to rewrite the whole table could also recompute the chain. Ship entries to your own SIEM if you need an independently held copy.
Client-side encryption, where we cannot read it at all
For the cases where trusting us is not acceptable, keys can be registered public-key-only. We hold no private key, so we cannot decrypt your data — and there is no escrow, which means losing that key loses the data. The trade is real and stated up front rather than in a footnote.
Least privilege in the boring places
Containers run as unprivileged users. The dashboard is served with a Content-Security-Policy that makes an injected script inert. API keys are stored as hashes, shown once at creation, and can carry an IP allowlist. Authentication failures are rate-limited and audited.
Nothing is fetched that you did not ask us to fetch
The code scanner reads only what you paste or the repository you name. The public scanner, which fetches a URL on an anonymous caller's behalf, is throttled and fails closed — a few minutes of 503 is cheaper for everyone than a few minutes of open proxy.

What this page is not

The dashboard has a page called Compliance. It scores your estate — your scans, your keys, your findings — against SOC-2-shaped controls, and it is a paid feature. It is not a statement about us, and this page is not a statement about you. Keeping those apart matters: a score on a marketing page reads as a certification, and we do not hold one.

Terms and privacy