Qstamp / Compliance
Regulatory alignment

Compliance evidence for the obligations institutions now face.

Qstamp produces technical evidence of integrity and time that supports record keeping, logging, provenance and post quantum migration obligations across major jurisdictions. This page maps those obligations to the specific mechanisms Qstamp provides.

Control mapping

What Qstamp provides, control by control.

Control objectiveRequirementQstamp mechanism
IntegrityDetect any alteration of a record after its creationSalted SHA3 leaf, RFC 9162 inclusion path and bound commitment
Time evidenceShow that a record existed no later than a stated timeBlock time finalised by an ML DSA 65 committee, accurate to within 15 seconds
TraceabilityLink a record to the system and account that produced itAuthenticated signer and record kind bound into every commitment
Non repudiationPrevent the producer from denying an anchored recordTransaction signed with ML DSA 65 by the producing account
Data minimisationPublish no personal or confidential dataOnly a salted 32 byte commitment is published
Long term validityRemain verifiable through the cryptographic transitionPost quantum signatures across the full history of the network
Independent verificationAllow third parties to verify without the producerOpen verification procedure and open source verifier
Segregation of authorityRequire authorised or multi party approvalIssuer and council Quanta contract templates
Jurisdictions

Regulation by country and body.

The following obligations create demand for durable, verifiable evidence of integrity and time. Dates reflect the position as of 2026.

JurisdictionInstrumentRequirementKey dates
European UnionAI Act, Regulation (EU) 2024/1689Automatic logging for high risk AI, documentation kept for ten years, marking of generated contentContent marking from 2 December 2026, high risk duties from 2 December 2027 and 2 August 2028
European UnioneIDAS 2, Regulation (EU) 2024/1183Qualified electronic ledgers and qualified time stamps recognised in all member statesIn force since 20 May 2024
European UnionNIS Cooperation Group post quantum roadmapMigration of public key cryptographyHigh risk systems by the end of 2030, medium risk by the end of 2035
United StatesExecutive Order 14412Post quantum key establishment and signatures for federal systems and contractorsKeys by 31 December 2030, signatures by 31 December 2031
United StatesNIST IR 8547 (draft)Retirement of classical public key algorithmsDeprecated 2030, disallowed 2035
United StatesSEC Rule 17a 4Broker dealer records kept three to six years in tamper evident formIn force
United StatesCalifornia AI Transparency ActProvenance data embedded in AI content, detected by large platformsProviders 2 August 2026, platforms 1 January 2027
United StatesColorado AI law (SB 26 189)Disclosure and transparency for automated decisions in consequential mattersFrom 1 January 2027
United StatesTexas TRAIGADisclosure of AI use by agencies and healthcare providersSince 1 January 2026
United KingdomNCSC migration timelinePost quantum migrationPlans by 2028, priority systems by 2031, all by 2035
CanadaFederal migration roadmapPost quantum migrationHigh risk by the end of 2031, all by 2035
AustraliaSignals Directorate guidanceCease classical public key cryptographyBy 2030
Hong KongHKMA quantum preparedness whitepaper and indexQuantum readiness of the banking sector, supported by a post quantum cryptography toolkitFull sector readiness by 2030
South KoreaAI Basic ActLabelling of AI generated content, stricter rules for deepfakesSince 22 January 2026
IndiaIT Rules amendment 2026 · national task forceSynthetic content labels with provenance metadata · post quantum migrationLabels since 20 February 2026 · critical systems by 2030
SingaporeMonetary Authority of SingaporeQuantum resilience expectations for financial institutionsSector resilience before 2030
G7Cyber Expert Group quantum roadmapCoordinated migration in the financial sectorJanuary 2026

Framework alignment

Qstamp supplies traceability evidence for the Govern, Map, Measure and Manage functions of the NIST AI Risk Management Framework and for the record and monitoring controls of ISO IEC 42001.

Data protection by design

Records never leave their owner and only salted commitments are published, supporting the data minimisation and storage limitation principles of GDPR and UK GDPR.

Scope of evidence

A Qstamp receipt establishes integrity and time. Qualified status under eIDAS 2 requires issuance by a certified qualified trust service provider.

Policies for regulators and institutions

The policies that govern Qstamp and this website are published for review by supervisory authorities, public bodies and institutional clients.