The sovereign security layer
for autonomous agents.

Payments, finance, files, receipts and decisions made by superintelligence (SI) agents stay private on your own systems. Their fingerprints are anchored on a post quantum network and can be proven to any court or regulator.

Regulators in the European Union, the United Kingdom, the United States, Japan, Korea, Singapore and Hong Kong require automated systems to keep records that are traceable, retained and protected against alteration. Qstamp gives every agent action a private fingerprint that can be verified independently of the company that made it, and that remains valid after quantum computers break classical signatures.

Agent paymentsFinanceFilesReceiptsDecisionsModels

Live on the Quantova Virtual Machine. Integrates with SI models and agents today.

npm install @quantovainc/qstamp
qstamp · evidence pipeline · live sequenceQVM
OPERATOR BOUNDARY · RECORDS NEVER LEAVE QUANTOVA VIRTUAL MACHINE · POST QUANTUM FINALITY SI agentaction record FingerprintSHA3 · 256 bit Salted leafdigest + 32 byte salt Batch treeRFC 9162 · 2^20 leaves Commitment32 bytes · fully bound Quanta contractQVM · ML DSA 65 tx Finalityvalidator signatures Receiptpath + anchor Verificationany party · any time committee · ML DSA 65 · about 0.2 s VALID SI agentaction recordFingerprintSHA3 · 256 bitSalted leafdigest + 32 byte saltBatch treeRFC 9162 · 2^20 leavesCommitment32 bytes · fully boundQuanta contractQVM · ML DSA 65 txFinalityvalidator signaturesReceiptpath + anchorVerificationany party · any time
01 / 09
An SI agent acts
An agent approves a payment, calls a tool or produces an output. Each action is captured as a record.
What Qstamp is

Qstamp is a post quantum evidence toolkit for superintelligence (SI) agents that keeps every record private. SI, short for superintelligence, is the term Quantova uses for the systems commonly called AI. Its SDK fingerprints each agent action and decision on the company's own systems and anchors only a salted cryptographic commitment on the Quantova network. Organisations in banking, government, healthcare and finance can then prove to courts, auditors and regulators exactly what their agents did and when, without disclosing the records themselves. The evidence cannot be forged by a quantum computer.

Classical records can be forged

Where agent logs, audit trails and smart contracts are signed today, they are signed with ECDSA over secp256k1 or P 256, EdDSA over Ed25519 or RSA. Shor's algorithm breaks all three, after which a forged record cannot be told apart from a genuine one.

Quantova accepts no classical signature

Accounts, transactions, contract code attestation and finality certificates on Quantova are signed with ML DSA as specified in FIPS 204. The protocol accepts no classical signature at any layer.

Private records, verifiable proof

The records, their fingerprints and their receipts stay with the company. Only a salted commitment is anchored, which anyone can verify and no one can read. A receipt remains verifiable for the full retention period that the law requires.

Privacy by construction

A public record of proof. Never a record of your data.

Public record means that anyone can check that a record existed and has not been altered. It does not mean that anyone can read it. Prompts, agent inputs and outputs, personal data and payment details never leave the systems of the company that runs the agent.

Published on chain
  • A 32 byte commitment computed from salted fingerprints
  • The block, the time and the transaction
  • The signing account and the contract
  • The record kind, such as SI agent action
Never published
  • Prompts and instructions given to agents
  • Agent outputs, reasoning and tool calls
  • Personal data and customer or patient details
  • Payment details, amounts and account numbers
  • Files, documents and model weights
  • The records themselves and their receipts

Each record is fingerprinted on the company's own systems with SHA3 256 and a fresh 256 bit random salt before anything is sent. The fingerprint is one way. It cannot be turned back into the record, and the salt prevents anyone from confirming a guess, even for a short or predictable prompt. A record is disclosed only when its owner chooses to produce it, for example to a court or a regulator, together with its receipt.

Energy efficiency

Evidence that adds nothing to your energy report.

Energy use is now a reporting duty for data centres and for the organisations that rely on them. Qstamp proves what SI agents did without new hardware, new storage or mining. The SDK runs inside the systems a company already operates, and a single anchoring transaction covers up to a million records.

No new data centre

The SDK runs on the servers a company already uses. It needs no GPU, no model training and no separate storage cluster, because records are never copied to Quantova.

Microseconds per record

A record is fingerprinted with SHA3 256 in microseconds on an ordinary processor. In our benchmark, 65,536 records were fingerprinted and combined into one hash tree in under one second.

One transaction for a million records

Up to 1,048,576 records share one anchoring transaction with a fixed fee, so the network work for each record falls towards zero as batches grow.

No mining

The Quantova network finalises each block with committee signatures under ML DSA 65, not by proof of work, so anchoring consumes no mining energy.

Organisations that report energy and emissions, for example under the EU Energy Efficiency Directive or sustainability reporting rules, can add tamper evident records of their SI agents without adding new infrastructure to that report.

Why transparency now

Systems that improve themselves need a record they cannot rewrite.

SI systems now write code, design experiments, tune models and increasingly contribute to the research that improves SI itself. As capability grows with less human involvement in each step, the actions and decisions of these systems become harder to observe. Today there is no common, tamper evident record of what autonomous and superintelligence agents actually did. Qstamp is built to provide that record, so that the growth of these systems remains accountable to the people and institutions they serve.

Recall every action

Qstamp fingerprints each agent action, model change and decision as it happens and anchors one salted commitment for each batch on chain. Operators, auditors and regulators can later recall exactly what an agent did and confirm that it acted within its mandate.

Quantum secure from first principles

The fingerprints are anchored on Quantova, which signs every account, transaction, contract and finality certificate with post quantum signatures from its first block. No classical signature scheme is inherited anywhere in its accounts, contracts, stored commitments or consensus.

Verifiable on QVMScan

Each anchoring transaction can be checked on QVMScan, the Quantova explorer, which shows when a batch was fixed and by which account. The explorer never shows the content of a record, because the content never leaves its owner.

The problem

A cloud log cannot prove what an agent did.

Most agent records sit in a database controlled by the party being audited and are protected by signatures that quantum computers will break. Qstamp moves the proof outside that boundary. Each record is reduced to a fingerprint and anchored with post quantum signatures, and anyone can check it without seeing its content.

TODAY · CONVENTIONAL CLOUD LOGFORGEABLE ONCE QUANTUM COMPUTERS ARRIVEQSTAMP · PRIVATE RECORDS, VERIFIABLE PROOFREMAINS VERIFIABLE ONCE QUANTUM COMPUTERS ARRIVESI agentaction recordCloud log databaseheld by the operatorAdministrator accessrows can be rewrittenAuditor or courtmust trust the operatorSI agentaction recordSHA3 fingerprintcontent stays privateQuanta contractML DSA 65 · public anchorAuditor or courtverifies independently✕ quantum breakable keys✕ silent edits✕ integrity unprovable✓ 256 bit fingerprint✓ post quantum signature✓ tamper evident proofrecord rewrittenany change is detectedTODAY · CONVENTIONAL CLOUD LOGQSTAMP · POST QUANTUM LAYERSI agentaction recordCloud log databaseheld by the operatorAdministrator accessrows can be rewrittenAuditor or courtmust trust the operatorSI agentaction recordSHA3 fingerprintcontent stays privateQuanta contractML DSA 65 · public anchorAuditor or courtverifies independently✕ quantum breakable keys✕ silent edits✕ integrity unprovable✓ 256 bit fingerprint✓ post quantum signature✓ tamper evident proof
Risk in conventional loggingProtection with Qstamp
What the law requires

Regulators require records that can be trusted.

Across the largest economies, the law now requires operators of automated and AI systems to record what those systems do, to retain the records and to protect them against alteration. Qstamp produces evidence that supports those duties and remains verifiable after classical cryptography is broken.

European Union
AI Act, Regulation (EU) 2024/1689, Articles 12 and 19

High risk AI systems must technically allow the automatic recording of events over their lifetime, and providers must keep those logs for at least six months.

Each logged event is anchored, so its integrity can be shown for the full retention period.

United Kingdom
UK GDPR Article 5(1)(f) · FCA Handbook SYSC 9

Personal data must be processed with appropriate security, including protection against unauthorised processing and accidental loss or damage. Regulated firms must keep orderly records sufficient for the regulator to monitor compliance.

Tamper evident proof that records are complete and unaltered, without publishing their content.

Japan
Electronic Books Maintenance Act · AI Promotion Act 2025

Electronic records must be kept with measures that ensure their authenticity, such as time stamps or a history of corrections and deletions. The AI Promotion Act makes transparency in the development and use of AI a basic principle.

Integrity and time evidence for every record, complementing accredited time stamps and correction histories.

South Korea
AI Basic Act · Personal Information Protection Act

Operators of high impact AI must establish risk management, explanation and user protection measures and keep documents that show them. Records of access to personal information must be kept and protected against forgery and alteration.

Tamper evident records of decisions and access that a regulator can verify independently.

Hong Kong
Personal Data (Privacy) Ordinance (Cap. 486) · HKMA Supervisory Policy Manual TM G 1

Data users must take all practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss or use. Authorised institutions must manage technology risk, including the integrity of their systems and of the records those systems hold.

Verifiable fingerprints of agent records and SI output, so that their integrity can be demonstrated to the HKMA, the Privacy Commissioner or a court.

United States
SEC Rule 17a 4 · Executive Order 14412

Broker dealer records must be kept in a non rewriteable, non erasable form or with a complete time stamped audit trail. Federal systems must migrate to post quantum key establishment and signatures.

A time stamped, tamper evident audit trail signed with post quantum cryptography from the start.

Qstamp supplies evidence that supports these obligations. Each organisation remains responsible for meeting the full requirements of the laws that apply to it. Full mapping by jurisdiction

Agent payments

When an agent pays, every step must be provable.

Qstamp anchors the mandate that authorised the agent, the payment it intended, the control decision that approved it and the settlement that followed. Each record is linked to the one before it, so a bank, a supervisor or a court can verify the whole chain from authority to settlement.

C1 · C2

Authority and intent

The mandate and the intended payment are anchored before any instruction is sent, so the record of what was permitted and what was intended cannot be changed later.

C3 · C4

Control and settlement

The sanctions, limit and anti money laundering checks, any human approval and the settlement confirmation are anchored and linked to the intent.

C5

Reconciliation and dispute

Every link is verified independently, and a missing, altered or reordered record is detected, for the full ten year retention period that payment rules now require.

A real example

How an SI company deploys Qstamp, from installation to a fingerprint a court can verify.

Thirteen steps in four phases, namely set up, integrate, operate and prove. Every value shown is taken from a real deployment of Qstamp on the Quantova Virtual Machine, and any company that integrates Qstamp follows the same procedure.

qstamp · deployment and evidence trail
Set upIntegrateOperateProve
Set up

Install the SDK

The SI company adds the open source Qstamp SDK to the service that runs its agents. It has one dependency, QCore, for post quantum signing.

$ npm install @quantovainc/qstamp
added 2 packages

$ npx @quantovainc/qstamp --version
0.1.4
package@quantovainc/qstamp 0.1.4
signing library@quantovainc/qcore 0.4.2
licenceApache 2.0 or MIT · Copyright 2026 Quantova Inc
Set up

Create the signing account

A signing key is created on the operator's own server or hardware security module. Its account is funded and registered once on the Quantova network.

$ openssl rand -hex 32 > signer.key && chmod 600 signer.key
$ node account.js
address  Q1NUR6ETECQXEVE77TJ9YPZ6WAWYMT45WCJANV5J43X93SF79DWE0S0D572X
status   registered, ready to stamp
account signatureML DSA 65 · FIPS 204
key custodyoperator only, never sent to Quantova
Set up

Choose or deploy the contract

The company stamps through the official Qstamp contract, or deploys its own issuer contract from the Quanta templates. Its own contract is compiled in QIDE at qdock.io by the attested Quanta compiler and deployed with the QMask wallet.

official contractQ1D6TZFRL203P3DFAFVUPZUHGUCM4EWGH6063XNS42VA5235RNQWXS7FXEWX
institution contractQ1DAJ3TZ7AN8JVY2MUCWYUWVPXEJSHH53JNDZ48L07RT6948J2N5QSNF3787
compiled containermatches the audited hash 7cd509e2d21bc4a3
deployment domainfresh random 64 bit value bound into every signed order
Integrate

Register the model

When a model is approved for use, its passport is stamped with the record kind ai_model. Every later decision can then be linked to the exact model that made it.

model-passport.jsonmodel registry
{
  "evaluation": {"approved_by": "Model Risk Committee", "auc": 0.871},
  "model": "risk-model 3.2.1",
  "time": "2026-10-09T09:39:27.273Z",
  "training_data": "dataset manifest 2026-09-30",
  "weights_sha3": "f01483b8e6269760c5c2e2025875b6e5d1b16402443e9a98d73e0a43156bf17b"
}
record kind4 · ai_model
fingerprint1b15118c7e2f1e482f87821a43d8062585b85e93d061bef1f6d429f621cfc850
transactionQTX19P000T7X6TPFPG8XMXV2GPU0XAR94H36LF7TKP6GGTXN2NQPWLZQ8PZJFY
block2,011,764
Integrate

Connect the agent runtime

The agent runtime writes every tool call and decision as a canonical record, keeps it in the company's own log and anchors the batch every minute. The receipts are stored beside the actions.

agent-runtime.jsoperator system
const qstamp = require('@quantovainc/qstamp');
const batch = [];

agent.on('action', (action) => {
  const bytes = Buffer.from(canonicalJson(action));
  log.write(bytes);
  batch.push({ digest: qstamp.digestBytes(bytes) });
});

setInterval(async () => {
  const records = batch.splice(0);
  if (records.length === 0) return;
  const receipts = await qstamp.stamp({
    seed, index: 0, kind: 'ai_agent_action', records,
    onPending: savePending,
  });
  receipts.forEach(storeBesideAction);
}, 60000);
Operate

The agent acts

A credit decision agent at a bank approves a loan. Its action is written as a canonical JSON record with the agent, model, policy, tool, decision and time.

credit-batch-1/action-04.jsonoperator system
{
  "agent": "credit-decision-agent-07",
  "amount_usd": 125000,
  "applicant": "APP-54a49c823275",
  "decision": "approve",
  "human_review": false,
  "model": "risk-model 3.2.1",
  "operator": "Example Bank plc",
  "policy": "retail-lending-policy 2026-10",
  "reasons": ["score_above_threshold"],
  "risk_score": 645,
  "time": "2026-10-09T09:39:25.132Z",
  "tool": "credit_bureau.lookup"
}
Operate

The SDK fingerprints it

On the operator's own systems, the SDK computes the SHA3 256 bit fingerprint of the record. The record itself never leaves the bank.

$ npx @quantovainc/qstamp hash action-04.json
  action-04.json
algorithmSHA3 256 · FIPS 202
fingerprintefb393903da28c2a6221179be662a2bbe2be06dfbd1acdee26bb057b6d2fb11f
Operate

Salted and batched

The fingerprint is bound to a fresh random salt and placed in a hash tree with the other actions of the batch. Six actions share one tree root.

leafH(0x00 ‖ QSTAMP/LEAF/V1 ‖ alg ‖ digest ‖ salt)
saltd275e738d46530b36f2c90e48a16bcd6e37fa9480378eb253c4e7a66a6a6b710
batch size6 actions
tree root34f64b12e5b363f1add6c48c0f85ebd60e4c2d421e5559f5d7b88717db205c54
Operate

One commitment

The root is bound to the chain, the official contract, the signing account, the record kind and the batch size. The result is one 32 byte commitment.

commitmentH(0x02 ‖ QSTAMP/ROOT/V1 ‖ genesis ‖ contract ‖ sender ‖ kind ‖ size ‖ root)
record kind6 · ai_agent_action
value6068a3e9625471530eda32f3292a9ac667c4f543281d62b12c62ad3481f07e0a
Operate

Signed with ML DSA 65

The SDK sends one transaction that calls the Qstamp Quanta contract on the Quantova Virtual Machine. It is signed with ML DSA 65, a post quantum signature.

transactionQTX1V53JW528S64SZYD6EDZ563N0PUUA2ARGNQHV4LTJMNH24PQS5VPQTAH8RQ
signerQ1NUR6ETECQXEVE77TJ9YPZ6WAWYMT45WCJANV5J43X93SF79DWE0S0D572X
contractQ1D6TZFRL203P3DFAFVUPZUHGUCM4EWGH6063XNS42VA5235RNQWXS7FXEWX
signatureML DSA 65 · FIPS 204
fee0.005 TQTOV for the whole batch
Operate

Final on chain

Validators finalise the block with post quantum signatures. The contract records the commitment in a Stamped event. The stamp became final in under one second.

block2,011,753
time2026-10-09 09:39:25 UTC
eventStamped · selector 5a110849
event datasigner ‖ commitment ‖ kind
✓ final · recorded by the official contract
Operate

Visible on the explorer

Anyone can open the transaction on QVMScan, the public Quantova explorer, and read the commitment, the signer, the record kind and the block.

qvmscan.io/tx/QTX1V53JW5…PQTAH8RQ
statusSuccess
block2,011,753
fromQ1NUR6ETECQXEVE77TJ9YPZ6WAWYMT45WCJANV5J43X93SF79DWE0S0D572X
toQ1D6TZFRL203P3DFAFVUPZUHGUCM4EWGH6063XNS42VA5235RNQWXS7FXEWX
Qstamp evidenceStamped · Official Qstamp contract · ai_agent_action
commitment6068a3e9625471530eda32f3292a9ac667c4f543281d62b12c62ad3481f07e0a
Open the live transaction
Prove

A court asks what the agent did

The bank produces the record and its receipt. The verifier recomputes the fingerprint, the tree root and the commitment, and finds the same commitment on chain. Changing a single digit makes the check fail.

$ npx @quantovainc/qstamp verify action-04.json.qstamp.json --file action-04.json
pass format · pass contract · pass content · pass inclusion
pass chain · pass transaction · pass event · pass block
VALID  stamped no later than 2026-10-09T09:39:25Z in block 2011753

$ npx @quantovainc/qstamp verify action-04.json.qstamp.json --file altered.json
FAIL content  the content does not match the fingerprint in the receipt
INVALID
original fingerprintefb393903da28c2a6221179be662a2bbe2be06dfbd1acdee26bb057b6d2fb11f
altered fingerprint93b2b98383cd8fc1d71c9727c358b077149123050b4e1ac78654e1889f37c086
0.2 s
Block finality per anchor
1048576
Records per transaction
128 bit
Quantum preimage security
0.005
TQTOV per anchor, any size
What Qstamp provides

Three operations. One durable proof.

01 · Fingerprint

Records stay where they are

The SDK reduces each record to a 256 bit digest and binds it to a fresh random salt. Content never leaves the operator, and nothing about it can be inferred from what is published.

02 · Commit

One commitment per batch

Up to 1048576 records form a single RFC 9162 hash tree. Its root, the batch size, the chain, the contract, the signer and the record kind are bound into one 32 byte commitment.

03 · Verify

Anyone can check it

Each record carries a receipt. Verification recomputes every link from the record to the finalised block, so trust in Quantova Inc or in the record holder is never required.

Built for superintelligence agents

Verifiable accountability for superintelligence.

Every tool call, decision and output an agent produces can be stamped in batches and verified later by the client, the insurer or the regulator. The record proves what was done, by which system and under which model, and the latest time by which it was done.

  • Action receipts for every tool call, decision and output
  • Model and dataset passports fixed at release
  • Issuer and council controls through Quanta signed orders
  • Mapped to EU AI Act logging and retention duties
Explore the agent architecture →
agent-audit.js@quantovainc/qstamp
const qstamp = require('@quantovainc/qstamp'); records produced by an agent in the last interval const records = actions.map((a) => ({ digest: qstamp.digestBytes(Buffer.from(JSON.stringify(a))), })); const receipts = await qstamp.stamp({ seed, index: 0, kind: 'ai_agent_action', records, }); const result = await qstamp.verify(receipts[0], { bytes: Buffer.from(JSON.stringify(actions[0])), }); result.status is valid, invalid or indeterminate
Why it is different

Post quantum from the first block, not retrofitted.

Evidence is only as durable as the infrastructure that witnesses it. Quantova has used post quantum signatures for every account, every transaction and every finality certificate since its first block, so the history behind a Qstamp receipt has never depended on a primitive that a quantum computer is known to break.

Quantum safe history

Accounts, transactions and validator certificates are signed with ML DSA 65. Infrastructure that migrates later keeps its earlier history under breakable keys.

Attested execution

The QVM admits only contract code signed by the attested Quanta compiler, so the stamping contract cannot be swapped for altered code.

Independent witness

The committee that finalises each block is independent of the party that produced the record, so evidence does not rest on self reporting.

Developers

Review the source. Install the package. Start stamping today.

Everything an engineering or audit team needs to evaluate Qstamp is public and one click away.

GitHubOpen source

Qstamp SDK source

Full source code, the published construction and the release history, open for independent security review.

git clone https://github.com/Quantova/QStamp.git
npmv0.1.4

@quantovainc/qstamp

Command line tool and library for Node 20 or later, with one dependency, QCore, for post quantum signing.

npm install @quantovainc/qstamp
QuantaExample

Contract templates

Open, issuer and council Quanta smart contracts. An independent third party audit is required before production deployment.

git clone https://github.com/Quantova/Qstamp-Quanta-Smart-contract-example-.git
Test networkQ-test-net-1

Endpoint and test units

Public endpoint for the Quantova test network. Claim free TQTOV test units to pay the anchoring fee.

https://rpc-testnet.quantova.org
Start building

Stamp your first record in under a minute.

Install the SDK, fingerprint a file, anchor it and verify the receipt. Open source under the Apache License 2.0 or the MIT licence.

npm install @quantovainc/qstamp npx qstamp hash report.pdf