Qstamp / FAQ
Questions

Questions and answers about Qstamp.

What Qstamp does, how to use it and how it supports regulatory requirements, in plain language.

What is Qstamp?

Qstamp is a post quantum evidence toolkit for superintelligence (SI) agents that keeps every record private. SI, short for superintelligence, is the term Quantova uses for the systems commonly called AI. Its SDK fingerprints each agent action and decision on the company's own systems and anchors only a salted cryptographic commitment on the Quantova network. Organisations in banking, government, healthcare and finance can then prove to courts, auditors and regulators exactly what their agents did and when, without disclosing the records themselves. The evidence cannot be forged by a quantum computer.

Agent records today rely on classical signatures, namely ECDSA over secp256k1 or P 256, EdDSA over Ed25519 or RSA, all of which are broken by Shor's algorithm. Quantova signs accounts, transactions, contract code and finality with ML DSA and accepts no classical signature in its protocol.

For each record, Qstamp computes a fingerprint on your own systems, combines many fingerprints into one 32 byte commitment and anchors that commitment through a Quanta smart contract on the Quantova Virtual Machine.

Each record then receives a receipt. With the record and its receipt, anyone can later prove that the record existed in exactly that form no later than the anchoring time, without trusting Quantova Inc or the holder of the record.

What does a receipt prove, and what does it not prove?

A valid receipt proves three facts.

  1. The record is identical, byte for byte, to the record that was stamped.
  2. The record existed no later than the time of the block that anchored it.
  3. The anchor was signed by a stated account under a stated record kind.

A receipt does not prove that the content is true, lawful or approved, and it does not identify a person. It is not a qualified electronic time stamp under eIDAS 2 unless it is issued by a certified qualified trust service provider.

Does a public record mean that our prompts or data become public?

No. Public record means public proof, not public data. Anyone can check that a record existed and has not been altered, but no one can read it.

Prompts, agent inputs and outputs, reasoning, tool calls, personal data, payment details, files and model weights never leave your systems. Each record is fingerprinted locally with SHA3 256 and a fresh 256 bit random salt, and only a 32 byte commitment computed from those fingerprints is published, together with the block, the time, the signing account, the contract and the record kind.

The fingerprint cannot be turned back into the record, and the salt prevents anyone from confirming a guess, even for a short or predictable prompt. A record is disclosed only when you choose to produce it, for example to a court or a regulator, together with its receipt.

How much energy does Qstamp use?

Very little. The SDK runs on the servers a company already operates and needs no GPU, no model training and no separate storage, because records are never copied to Quantova. A record is fingerprinted with SHA3 256 in microseconds on an ordinary processor, and in our benchmark 65,536 records were fingerprinted and combined into one hash tree in under one second.

Up to 1,048,576 records share one anchoring transaction, and the Quantova network finalises blocks with committee signatures under ML DSA 65 rather than proof of work, so anchoring consumes no mining energy.

How do I get the Qstamp SDK?

Qstamp is published on npm and on GitHub under the Apache License 2.0 or the MIT licence. Node 20 or later is required.

npm install @quantovainc/qstamp

To review or build from source, clone the repository.

git clone https://github.com/Quantova/QStamp.git
cd QStamp
npm ci

Source on GitHub · Package on npm

How do I stamp my first file on the test network?

  1. Create a signing key that only you can read.
openssl rand -hex 32 > signer.key
chmod 600 signer.key
  1. Save the following script as account.js in the same folder and run it with node account.js. It prints the address of your account.
const fs = require('fs');
const { Client, core } = require('@quantovainc/qcore');

const seed = Uint8Array.from(Buffer.from(fs.readFileSync('signer.key', 'utf8').trim(), 'hex'));
const client = new Client('https://rpc-testnet.quantova.org', { expectedChainId: 'Q-test-net-1' });
const address = core.address(seed, 0);

client.account(address).then(async (account) => {
  console.log('address  ' + address);
  console.log('balance  ' + account.balance + ' quon');
  if (account.has_key) return console.log('status   registered, ready to stamp');
  if (account.balance === '0') return console.log('status   claim test TQTOV at the faucet');
  const { outcome } = await client.register(seed, 0, '100000');
  console.log('status   registration ' + outcome.verdict);
});
  1. Claim free TQTOV test units for that address at the test network faucet.
  2. Run node account.js again. Once the units have arrived, it registers your account on the network. Registration is needed only once per account.
  3. Stamp a file and verify its receipt.
npx qstamp stamp report.pdf --seed-file ./signer.key --index 0 --kind record
npx qstamp verify report.pdf.qstamp.json --file report.pdf

Each anchoring transaction costs 0.005 TQTOV on the test network, whatever the number of files. Keep signer.key secret and backed up. Anyone who holds it can sign as your account.

How do I integrate Qstamp with an SI agent?

Record each action the agent takes, then anchor the actions in batches.

  1. After every tool call or decision, write the action as JSON with a fixed key order. Include the agent identity, the tool, digests of the inputs and outputs, and the time.
  2. Fingerprint that JSON and add it to the current batch.
  3. At a fixed interval, for example every minute, anchor the batch in one transaction with the record kind ai_agent_action. One batch holds up to 1048576 actions.
  4. Store each receipt beside its action in your log. Save pending batches through the onPending option, so that no receipt is lost if the process stops.
const qstamp = require('@quantovainc/qstamp');

const batch = [];

function recordAction(action) {
  const bytes = Buffer.from(JSON.stringify(action));
  batch.push({ digest: qstamp.digestBytes(bytes) });
}

async function anchorBatch(seed) {
  if (batch.length === 0) return [];
  const records = batch.splice(0);
  return qstamp.stamp({
    seed,
    index: 0,
    kind: 'ai_agent_action',
    records,
    onPending: (pending) => savePending(pending),
  });
}

The seed is passed as a Uint8Array of 32 bytes and is wiped by the SDK after signing. Model files and datasets can be stamped the same way with the kinds ai_model and ai_dataset.

Which record kinds can I use?

The record kind is stored on the chain with each commitment, so a verifier can see what class of record was anchored. The named kinds are listed below. Other values are available for private schemes.

0  record
1  file
2  document
3  software_release
4  ai_model
5  ai_dataset
6  ai_agent_action
7  ai_output
8  wallet_binding
9  financial_record
10 public_record

How do I deploy the Quanta contract templates through QIDE at qdock.io?

Most users never deploy a contract. The open Qstamp contract is already live and the SDK uses it by default. An institution deploys its own contract only when it needs an authorised issuer or multi party approval.

  1. Install the QMask wallet extension in Chrome from qmask.io and create an account.
  2. Claim test TQTOV for that account at the test network faucet.
  3. Open QIDE at qdock.io. Nothing else needs to be installed. QIDE compiles on its server with the attested Quanta compiler and adds the compiler signature that the network requires.
  4. Copy a template, for example QStampIssuer.qs, from the contract templates repository into a new file in QIDE and compile it.
  5. Connect QMask, choose Deploy and approve the transaction in QMask. QMask shows the maximum fee before you approve. A test network deployment normally costs less than 1 TQTOV.
  6. Record the contract address and give it to every party that will verify your receipts.

The templates are examples. An independent third party security audit is required before any production deployment. Receipts from your own contract are verified by passing its address with the option trustCustomContract set to true.

How does Qstamp support regulatory requirements?

  1. EU AI Act. Evidence for the automatic logging duty of Article 12, the log and documentation retention duties of Articles 18, 19 and 26, and the content marking duty of Article 50.
  2. eIDAS 2. Integrity and time evidence for electronic records. Qualified status requires issuance by a certified qualified trust service provider.
  3. SEC Rule 17a 4. Tamper evident integrity evidence for broker dealer records kept for three to six years.
  4. GDPR and UK GDPR. Records never leave their owner and only salted commitments are published, which supports data minimisation.
  5. NIST AI RMF and ISO IEC 42001. Traceability evidence for SI governance controls.
  6. Post quantum mandates. Evidence is signed with ML DSA 65 and hashed with SHA3, so it remains verifiable after classical signatures can be forged.

Qstamp supplies evidence. Each organisation remains responsible for meeting the other requirements of the laws that apply to it.

Full regulatory mapping by jurisdiction

Why should SI agent companies integrate Qstamp now?

  1. Deadlines are set. EU AI Act marking duties apply from 2 December 2026 and high risk duties from 2 December 2027. The California AI Transparency Act applies to providers from 2 August 2026 and the Colorado AI law from 1 January 2027.
  2. Evidence cannot be created after the fact. A record stamped today proves its integrity from today. A record kept without an anchor cannot later be shown to be unaltered.
  3. Retention outlives classical cryptography. Regulated records must remain verifiable for up to ten years, which extends beyond the dates on which NIST retires classical signatures (deprecation in 2030 and disallowance in 2035).
  4. The integration effort is small. An agent needs one function call per batch and a place to store its receipts.

Does Qstamp work for superintelligence agents?

Yes. Qstamp records what an agent did, whatever its capability. The same SDK, record kinds and receipts apply to a narrow assistant and to the most capable autonomous systems.

SI systems increasingly contribute to the research that improves SI itself, with less human involvement in each step. Qstamp places a fingerprint of every action, model change and decision on chain as it happens, on a network that is post quantum from its first block, so that each step can later be recalled and checked against what the agent was permitted to do. Every anchoring transaction is visible on QVMScan, the Quantova explorer.

As agents become more capable and act with less human review, independent evidence of each action becomes more important. A receipt lets an operator, an auditor or a regulator confirm what was recorded without trusting the agent or its operator.

Does Quantova see or store my records?

No. Fingerprints are computed on your own systems. The only value published for each batch is a salted 32 byte commitment from which no content can be derived.

A receipt contains no part of the record, but it does contain the record digest and salt. Handle receipts with the same care as the records they describe.

What does it cost?

On the test network, each anchoring transaction costs 0.005 TQTOV whatever the batch size, up to 1048576 records. TQTOV test units have no monetary value and are free from the faucet.

Production use will take place on the Quantova main network, under its published fee schedule, once it launches.

Can test network receipts be used as evidence?

No. Test network receipts carry no evidential weight. Use the test network to build and test your integration. Production use will take place on the Quantova main network once it launches.

How does an auditor or regulator verify a receipt?

The verifier needs the record and its receipt.

npx qstamp verify receipt.qstamp.json --file record.pdf

The result is valid, invalid or indeterminate. Indeterminate means that the network could not be consulted. An indeterminate result is never reported as valid. The first four checks run entirely on the verifier's own machine. An independent verifier can also rebuild every check from the published construction on the Mathematics page.

Why is Qstamp evidence post quantum secure?

Fingerprints and hash trees use SHA3 with a 256 bit output, as specified in FIPS 202, which gives 128 bit security against quantum preimage search. Every transaction and every finality certificate on the Quantova network is signed with ML DSA 65, as specified in FIPS 204.