Security at Quantum Shield Platform
We hold ourselves to the same standard we sell. This page summarizes the controls protecting our platform, our customers and the data entrusted to us.
Post-quantum by design
All key establishment and digital signatures across our stack use NIST-standardized post-quantum algorithms — ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) — in hybrid mode alongside classical primitives during migration.
Layered defense in depth
Five independent security layers — from hardened infrastructure and network isolation to application controls and continuous verification — ensure no single point of failure can expose customer data.
24/7 monitoring & self-healing
Our infrastructure is continuously monitored. The self-healing layer detects anomalous behavior, isolates affected components, rotates compromised material and restores known-good state automatically — without waiting for a human on-call.
Key & secret management
Keys are generated in hardened modules, never leave controlled boundaries in plaintext, and are rotated on schedule and on demand. Customer keys are segregated per tenant with hardware-backed root of trust.
How Photon Light breaks the email-compromise chain
The theft charged by the U.S. Department of Justice did not begin with broken encryption. It began with a login. Below is the chain the attackers used, step by step, and the point at which each step stops working once the username and password are removed.
With passwords and one-time codes
Each link depends on a secret a human being can be persuaded to share.
- Step 1
The email account falls first
A convincing phone call, a fake support page or a reused password hands over the victim's email login. Nothing is stolen yet — but the master key just changed hands.
- Step 2
Password reset becomes the attacker's tool
Every other account offers to email a reset link. Owning the inbox means owning the reset flow for the exchange, the wallet service, the cloud drive and the bank.
- Step 3
The one-time code is simply asked for
The six-digit code is read aloud to an attacker posing as support, intercepted on a cloned number, or approved by a tired user tapping through a flood of prompts.
- Step 4
Recovery data completes the takeover
Backup phrases, screenshots of seed words and stored documents sit in the same inbox and cloud account, giving permanent control rather than a single session.
- Step 5
The funds move faster than the response
By the time anyone notices, assets are split across dozens of destinations. In the case charged by the Justice Department, that total reached hundreds of millions of dollars.
With Photon Light
The same five moves, attempted against hardware-bound light authentication.
- Blocked at Step 1
There is no password to give away
Photon Light replaces the username and password entirely. A caller cannot talk a user out of a secret the user does not have, and a fake login page has nothing to capture.
- Blocked at Step 2
Email is no longer the master key
Access is bound to the physical card-sized device, not to an inbox. Owning the email account no longer unlocks anything else, so the reset chain collapses at its first link.
- Blocked at Step 3
Nothing exists that can be repeated
Authentication happens through a light exchange between the device and the machine in front of it. There is no code to read aloud, forward, screenshot or replay later.
- Blocked at Step 4
Secrets never sit in a mailbox
Key material stays inside the hardware and never travels as readable text, so there are no recovery phrases or backup documents worth stealing from storage.
- Blocked at Step 5
Takeover attempts surface immediately
Continuous verification and self-healing isolate an anomalous session and revoke its trust automatically, rather than waiting for the victim to notice missing funds.
| Attacker move | Password login | Photon Light |
|---|---|---|
| Attacker learns the password | Full account access | No effect — no password exists |
| Attacker controls the email inbox | Can reset every linked account | No effect — access is not email-based |
| Victim reads out a one-time code | Session handed to the attacker | No effect — no code is ever issued |
| Credentials leaked in a data breach | Reusable until rotated | Nothing reusable is stored |
| Convincing fake login page | Captures everything typed | Nothing to type or capture |
Verify this for yourself
The case described above is a matter of public record. We link to the primary sources so any reader can confirm the facts independently.
Found a vulnerability?
We operate a responsible disclosure program and commit to rapid, fair handling of researcher reports.
Responsible DisclosureCompliance & standards
See how our controls map to NIST, CNSA 2.0, NCSC and EU requirements, and the deployment models we support for regulated environments.
Compliance