Qstamp / How it works
Architecture

From a record to a receipt that outlives quantum computers.

Qstamp keeps every record private and makes only the proof verifiable. Records, their fingerprints and their receipts stay with the operator. Only a single salted commitment is anchored through a Quanta contract on the Quantova Virtual Machine, where a post quantum validator committee finalises it.

OPERATOR SYSTEMS QSTAMP SDK · LOCAL QUANTOVA VIRTUAL MACHINE VALIDATOR COMMITTEE Recordsagent actions, files DigestSHA3 256 bit Salted leaf0x00 · tag · alg · salt Hash treeRFC 9162 root Commitment0x02 · context · root Signed transactionML DSA 65 · fee capped Quanta contractemits Stamped event Block and event rootcommitment included Finality certificateML DSA 65 committee Receipts returnedone per record · JSON Archivekept with record OPERATOR SYSTEMS QSTAMP SDK · LOCAL QUANTOVA VIRTUAL MACHINE VALIDATOR COMMITTEE Recordsagent actions, files DigestSHA3 256 bit Salted leaf0x00 · tag · alg · salt Hash treeRFC 9162 root Commitment0x02 · context · root Signed transactionML DSA 65 · fee capped Quanta contractemits Stamped event Block and event rootcommitment included Finality certificateML DSA 65 committee Receipts returnedone per record · JSON Archivekept with record
Figure 1 · Stamping. Only the 32 byte commitment crosses the operator boundary. Dashed links are network operations.
A real example

How an SI company deploys Qstamp, from installation to a fingerprint a court can verify.

Thirteen steps in four phases, namely set up, integrate, operate and prove. Every value shown is taken from a real deployment of Qstamp on the Quantova Virtual Machine, and any company that integrates Qstamp follows the same procedure.

qstamp · deployment and evidence trail
Set upIntegrateOperateProve
Set up

Install the SDK

The SI company adds the open source Qstamp SDK to the service that runs its agents. It has one dependency, QCore, for post quantum signing.

$ npm install @quantovainc/qstamp
added 2 packages

$ npx @quantovainc/qstamp --version
0.1.4
package@quantovainc/qstamp 0.1.4
signing library@quantovainc/qcore 0.4.2
licenceApache 2.0 or MIT · Copyright 2026 Quantova Inc
Set up

Create the signing account

A signing key is created on the operator's own server or hardware security module. Its account is funded and registered once on the Quantova network.

$ openssl rand -hex 32 > signer.key && chmod 600 signer.key
$ node account.js
address  Q1NUR6ETECQXEVE77TJ9YPZ6WAWYMT45WCJANV5J43X93SF79DWE0S0D572X
status   registered, ready to stamp
account signatureML DSA 65 · FIPS 204
key custodyoperator only, never sent to Quantova
Set up

Choose or deploy the contract

The company stamps through the official Qstamp contract, or deploys its own issuer contract from the Quanta templates. Its own contract is compiled in QIDE at qdock.io by the attested Quanta compiler and deployed with the QMask wallet.

official contractQ1D6TZFRL203P3DFAFVUPZUHGUCM4EWGH6063XNS42VA5235RNQWXS7FXEWX
institution contractQ1DAJ3TZ7AN8JVY2MUCWYUWVPXEJSHH53JNDZ48L07RT6948J2N5QSNF3787
compiled containermatches the audited hash 7cd509e2d21bc4a3
deployment domainfresh random 64 bit value bound into every signed order
Integrate

Register the model

When a model is approved for use, its passport is stamped with the record kind ai_model. Every later decision can then be linked to the exact model that made it.

model-passport.jsonmodel registry
{
  "evaluation": {"approved_by": "Model Risk Committee", "auc": 0.871},
  "model": "risk-model 3.2.1",
  "time": "2026-10-09T09:39:27.273Z",
  "training_data": "dataset manifest 2026-09-30",
  "weights_sha3": "f01483b8e6269760c5c2e2025875b6e5d1b16402443e9a98d73e0a43156bf17b"
}
record kind4 · ai_model
fingerprint1b15118c7e2f1e482f87821a43d8062585b85e93d061bef1f6d429f621cfc850
transactionQTX19P000T7X6TPFPG8XMXV2GPU0XAR94H36LF7TKP6GGTXN2NQPWLZQ8PZJFY
block2,011,764
Integrate

Connect the agent runtime

The agent runtime writes every tool call and decision as a canonical record, keeps it in the company's own log and anchors the batch every minute. The receipts are stored beside the actions.

agent-runtime.jsoperator system
const qstamp = require('@quantovainc/qstamp');
const batch = [];

agent.on('action', (action) => {
  const bytes = Buffer.from(canonicalJson(action));
  log.write(bytes);
  batch.push({ digest: qstamp.digestBytes(bytes) });
});

setInterval(async () => {
  const records = batch.splice(0);
  if (records.length === 0) return;
  const receipts = await qstamp.stamp({
    seed, index: 0, kind: 'ai_agent_action', records,
    onPending: savePending,
  });
  receipts.forEach(storeBesideAction);
}, 60000);
Operate

The agent acts

A credit decision agent at a bank approves a loan. Its action is written as a canonical JSON record with the agent, model, policy, tool, decision and time.

credit-batch-1/action-04.jsonoperator system
{
  "agent": "credit-decision-agent-07",
  "amount_usd": 125000,
  "applicant": "APP-54a49c823275",
  "decision": "approve",
  "human_review": false,
  "model": "risk-model 3.2.1",
  "operator": "Example Bank plc",
  "policy": "retail-lending-policy 2026-10",
  "reasons": ["score_above_threshold"],
  "risk_score": 645,
  "time": "2026-10-09T09:39:25.132Z",
  "tool": "credit_bureau.lookup"
}
Operate

The SDK fingerprints it

On the operator's own systems, the SDK computes the SHA3 256 bit fingerprint of the record. The record itself never leaves the bank.

$ npx @quantovainc/qstamp hash action-04.json
  action-04.json
algorithmSHA3 256 · FIPS 202
fingerprintefb393903da28c2a6221179be662a2bbe2be06dfbd1acdee26bb057b6d2fb11f
Operate

Salted and batched

The fingerprint is bound to a fresh random salt and placed in a hash tree with the other actions of the batch. Six actions share one tree root.

leafH(0x00 ‖ QSTAMP/LEAF/V1 ‖ alg ‖ digest ‖ salt)
saltd275e738d46530b36f2c90e48a16bcd6e37fa9480378eb253c4e7a66a6a6b710
batch size6 actions
tree root34f64b12e5b363f1add6c48c0f85ebd60e4c2d421e5559f5d7b88717db205c54
Operate

One commitment

The root is bound to the chain, the official contract, the signing account, the record kind and the batch size. The result is one 32 byte commitment.

commitmentH(0x02 ‖ QSTAMP/ROOT/V1 ‖ genesis ‖ contract ‖ sender ‖ kind ‖ size ‖ root)
record kind6 · ai_agent_action
value6068a3e9625471530eda32f3292a9ac667c4f543281d62b12c62ad3481f07e0a
Operate

Signed with ML DSA 65

The SDK sends one transaction that calls the Qstamp Quanta contract on the Quantova Virtual Machine. It is signed with ML DSA 65, a post quantum signature.

transactionQTX1V53JW528S64SZYD6EDZ563N0PUUA2ARGNQHV4LTJMNH24PQS5VPQTAH8RQ
signerQ1NUR6ETECQXEVE77TJ9YPZ6WAWYMT45WCJANV5J43X93SF79DWE0S0D572X
contractQ1D6TZFRL203P3DFAFVUPZUHGUCM4EWGH6063XNS42VA5235RNQWXS7FXEWX
signatureML DSA 65 · FIPS 204
fee0.005 TQTOV for the whole batch
Operate

Final on chain

Validators finalise the block with post quantum signatures. The contract records the commitment in a Stamped event. The stamp became final in under one second.

block2,011,753
time2026-10-09 09:39:25 UTC
eventStamped · selector 5a110849
event datasigner ‖ commitment ‖ kind
✓ final · recorded by the official contract
Operate

Visible on the explorer

Anyone can open the transaction on QVMScan, the public Quantova explorer, and read the commitment, the signer, the record kind and the block.

qvmscan.io/tx/QTX1V53JW5…PQTAH8RQ
statusSuccess
block2,011,753
fromQ1NUR6ETECQXEVE77TJ9YPZ6WAWYMT45WCJANV5J43X93SF79DWE0S0D572X
toQ1D6TZFRL203P3DFAFVUPZUHGUCM4EWGH6063XNS42VA5235RNQWXS7FXEWX
Qstamp evidenceStamped · Official Qstamp contract · ai_agent_action
commitment6068a3e9625471530eda32f3292a9ac667c4f543281d62b12c62ad3481f07e0a
Open the live transaction
Prove

A court asks what the agent did

The bank produces the record and its receipt. The verifier recomputes the fingerprint, the tree root and the commitment, and finds the same commitment on chain. Changing a single digit makes the check fail.

$ npx @quantovainc/qstamp verify action-04.json.qstamp.json --file action-04.json
pass format · pass contract · pass content · pass inclusion
pass chain · pass transaction · pass event · pass block
VALID  stamped no later than 2026-10-09T09:39:25Z in block 2011753

$ npx @quantovainc/qstamp verify action-04.json.qstamp.json --file altered.json
FAIL content  the content does not match the fingerprint in the receipt
INVALID
original fingerprintefb393903da28c2a6221179be662a2bbe2be06dfbd1acdee26bb057b6d2fb11f
altered fingerprint93b2b98383cd8fc1d71c9727c358b077149123050b4e1ac78654e1889f37c086
Stamping sequence

Seven defined steps.

Fingerprint each record

The SDK computes SHA3 with a 256 bit output, or SHA2 with a 256 bit output where an existing system already uses it.

Salt and label every leaf

A fresh 32 byte salt from the operating system's random generator is bound to the digest together with the domain label QSTAMP/LEAF/V1 and the algorithm identifier.

Build the batch tree

Leaves are combined following RFC 9162. Leaf and node hashes use distinct prefixes, which removes second preimage ambiguity.

Derive the commitment

The root is bound together with the genesis hash, contract, signer, record kind and batch size into one 32 byte value.

Sign and submit

The commitment is sent in a transaction signed with ML DSA 65. The fee is capped before signing and the unused part of the metered fee is refunded.

Record and finalise

The Quanta contract emits a Stamped event. The validator committee finalises the block in about 0.2 seconds.

Issue receipts

Each record receives a receipt holding its salt, inclusion path and anchor. A private recovery file protects against interruption.

Receipt anatomy

Small, self describing and verifiable.

contract.pdf.qstamp.jsonqstamp receipt 1
{ "format": "qstamp-receipt/1", "chain": { "id": "Q-test-net-1", "genesis": "ca91e093…" }, "contract": "Q1D6TZFRL203…", "kind": "6", "record": { "alg": "sha3-256", "digest": "9f07acaf…", "salt": "5e1c02d4…" }, "proof": { "index": 2, "size": 8, "path": [ … ] }, "root": "b3f1…", "anchor": { "tx": "QTX1TYDCHMSD…", "height": 1506979, "block": "QBK1…", "time": 1791430364, "sender": "Q1NUR6ETECQX…" } }

Receipts contain no part of the record. They do hold the digest and salt, so they are handled with the same care as the records they describe.

Batching

Logarithmic proofs, constant cost.

A batch of any size is anchored by one transaction. Each record proves its membership with a path whose length grows only with the logarithm of the batch size.

leaf 0leaf 1leaf 2leaf 3leaf 4leaf 5leaf 6leaf 7nodenodenodenodenodenoderootHighlighted · leaf 2 and the nodes it hashes into. Its inclusion path is the sibling at each level, namely leaf 3, node(0,1) and node(4..7), three hashes for eight leaves. root node node node node node node leaf 0 leaf 1 leaf 2 leaf 3 leaf 4 leaf 5 leaf 6 leaf 7
Figure 3 · An inclusion path grows with the logarithm of the batch size. One million records need twenty sibling hashes.
Verification

Trust the mathematics, not the issuer.

Verification returns one of three outcomes. Valid means every link holds. Invalid means at least one link fails. Indeterminate means that the network could not be consulted. An indeterminate result is never reported as valid.

LOCAL CHECKS · NO NETWORK · NO TRUST ANCHOR CHECKS · QVM 1 · Contentrecompute digest 2 · Leafdigest · salt · alg 3 · Inclusionpath to root 4 · Commitmentbind full context 5 · Transactionfinal · signer · data 6 · Eventofficial contract 7 · Blockidentifier · time Verdictone of three outcomes LOCAL CHECKS · NO NETWORK · NO TRUST ANCHOR CHECKS · QVM 1 · Contentrecompute digest 2 · Leafdigest · salt · alg 3 · Inclusionpath to root 4 · Commitmentbind full context 5 · Transactionfinal · signer · data 6 · Eventofficial contract 7 · Blockidentifier · time Verdictone of three outcomes
Figure 2 · Verification. Steps 1 to 4 run entirely on the verifier's machine. Steps 5 to 7 confirm the anchor on the Quantova network.

Fails closed

An unreachable endpoint, a truncated response or malformed data can never produce a valid verdict.

Pinned contract

Receipts verify only against the official contract of their network unless a custom deployment is explicitly trusted.

Accurate time

Block time never decreases and is accepted only if it is within 15 seconds of the validators' clocks.