Cryptographic Resilience
Chordian's standards-aligned approach to cryptographic agility, hybrid post-quantum transport, verifiable sovereign memory, and long-term protection.
Chordian's security architecture is designed to preserve the confidentiality, integrity, provenance, and operational trust of sovereign enterprise memory as cryptographic standards evolve.
The programme includes a phased transition to post-quantum cryptography (PQC) using the NIST-standardized ML-KEM key-establishment mechanism under FIPS 203 and ML-DSA digital signatures under FIPS 204. During the interoperability period, post-quantum algorithms are combined with established classical cryptography rather than introduced as a disruptive platform-wide replacement.
Current status
Phase 0 on the established Chordian Cryptographic Resilience Roadmap is complete. Chordian has selected the applicable standards, mapped the principal protection boundaries, established the initial algorithm profile, and defined the phased implementation and evidence model. Phase 1 initial technical verification is complete; deployment-profile validation is in progress.
Why cryptographic resilience matters
Enterprise memory contains information that can remain valuable for many years: intellectual property, source code, contracts, strategic decisions, audit evidence, regulated records, and operational history.
Classical public-key mechanisms such as RSA and elliptic-curve cryptography may eventually become vulnerable to sufficiently capable quantum computers. This creates a present-day risk for long-lived confidential information because an attacker can collect encrypted traffic or archives now and retain them for future decryption. This threat model is commonly described as Harvest Now, Decrypt Later.
Chordian addresses this risk through a staged migration that prioritizes controls with measurable security value for long-lived enterprise data.
Swiss-Engineered Security for the Trusted Workplace
A Trusted Workplace requires more than secure access to individual applications. It requires organisational knowledge, AI interactions, identities, and operational records to remain within clearly defined trust boundaries throughout their lifecycle.
Chordian applies Swiss-engineered security principles centred on data sovereignty, accountability, least-privilege access, operational resilience, and verifiable control over sensitive enterprise information. Institutional memory can be deployed within customer-defined infrastructure and jurisdictional boundaries, with layered identity controls, isolated retrieval, auditable activity, and cryptographic protection designed for long-lived data.
This approach is informed by the security and resilience principles reflected in the Swiss Federal Act on Data Protection and Switzerland's national ICT minimum-standard guidance. For regulated financial-sector deployments, Chordian's controls and deployment evidence can also be mapped against relevant FINMA expectations concerning cyber risk, critical data, outsourcing, and operational resilience.
Trusted Workplace principles
- Sovereign by design — customers retain control over where institutional memory is processed and stored.
- Zero-trust access — every user, service, and agent must be authenticated and authorised before accessing protected knowledge.
- Verifiable activity — sensitive actions, memory operations, and administrative events are recorded for review and assurance.
- Resilient operations — deployment boundaries, recovery processes, and cryptographic controls are designed for continuity and long-term protection.
- Future-ready security — Chordian's cryptographic resilience roadmap prepares long-lived enterprise memory for evolving standards, including the transition to post-quantum cryptography.
The Trusted Workplace is a controlled enterprise environment in which people and authorised AI systems can work with shared institutional knowledge without surrendering ownership, jurisdiction, or security control.
Protection model
| Protection boundary | Purpose | Initial technology profile | Protected assets |
|---|---|---|---|
| Hybrid post-quantum transport | Protect selected network traffic against future decryption | TLS 1.3 with X25519MLKEM768 | API, MCP, connector, and supported origin traffic |
| Verifiable sovereign memory | Detect modification and authenticate protected memory provenance | ML-DSA-65, signed manifests, Merkle evidence | Memory objects, derived records, and audit checkpoints |
| Sovereign trust chain | Protect software, offline updates, exports, and recovery material | ML-DSA signatures, ML-KEM key protection, AES-256 bulk encryption | Releases, backups, exports, and air-gapped update packages |
| Post-quantum identity and BYOI | Transition long-lived machine identity and private infrastructure | PQ-capable mTLS, private PKI, and crypto-agile service identity | Customer infrastructure, services, and sovereign deployments |
Cryptographic policy
Chordian's initial post-quantum profile is based on the following principles.
ML-KEM-768 for key establishment
ML-KEM-768 is the initial Chordian profile for post-quantum key establishment. It is used to establish or derive cryptographic key material. It is not used as a replacement for bulk-data encryption.
ML-DSA-65 for durable signatures
ML-DSA-65 is the initial profile for durable memory manifests, audit evidence, and sovereign release signatures.
A valid ML-DSA signature provides:
- evidence that signed data has not been modified;
- authentication of the holder of the corresponding signing key;
- resistance to signature forgery by future quantum-capable adversaries.
A signature authenticates integrity and provenance. It does not prove that the underlying business information is factually correct.
Hybrid classical and post-quantum operation
During the transition, Chordian uses hybrid cryptographic profiles. For TLS key establishment, the initial target profile is:
X25519 + ML-KEM-768In compatible TLS implementations, this hybrid group is represented as:
X25519MLKEM768The hybrid model preserves established classical protection and compatibility while adding resistance against attacks on classical key establishment.
Symmetric encryption remains in use
AES-256 authenticated encryption remains Chordian's approved profile for bulk-data protection where Chordian controls the encryption layer. Deployment-specific coverage is documented separately. Post-quantum cryptography is introduced around the public-key mechanisms used to establish, distribute, or protect symmetric keys.
Crypto-agility
Algorithm identifiers, key versions, policy versions, and migration states are represented explicitly. This allows cryptographic mechanisms to evolve without requiring Chordian to redesign or re-index the complete memory and retrieval layer.
Established implementation roadmap
Phase 0 — Standards and architecture foundation
Status: Completed · Outcome: Architecture and engineering foundation established
Phase 0 established the implementation baseline for Chordian's post-quantum transition. Completed work includes:
- selection of NIST FIPS 203 and FIPS 204 as the standards baseline;
- mapping of the transport, memory, storage, software, and identity protection boundaries;
- selection of ML-KEM-768 and ML-DSA-65 as the initial algorithm profiles;
- definition of hybrid classical and post-quantum migration principles;
- establishment of evidence, benchmarking, and deployment-compatibility requirements;
- definition of the phased production roadmap.
Phase 1 — Hybrid post-quantum transport
Status: Initial technical verification completed; deployment-profile validation in progress
Phase 1 validates and operationalizes hybrid post-quantum key establishment across
supported TLS 1.3 deployment paths. Hybrid post-quantum TLS validation has
demonstrated X25519MLKEM768 negotiation on a tested Chordian development TLS
boundary. Both forced and default TLS 1.3 negotiation selected the hybrid group with
a compatible client.
This is an initial technical verification milestone. Deployment-specific availability remains subject to validation for each supported environment, including operational fallback behaviour, monitoring, and client compatibility.
Initial scope: public API traffic; MCP connections; connector ingress; supported edge-to-origin connections; selected internal service paths where compatible infrastructure is available.
Technology profile: TLS 1.3; X25519MLKEM768; compatible TLS termination and
OpenSSL-based infrastructure; trusted negotiation telemetry and downgrade monitoring.
Protection provided: hybrid post-quantum transport reduces the risk that encrypted traffic captured today can later be decrypted through attacks against classical public-key key establishment. The protection applies only to connections that successfully negotiate an approved hybrid group.
This TLS key-establishment evidence does not make certificate authentication, identity systems, private infrastructure links, storage, exports, or all internal service traffic post-quantum by default. Those areas remain separate roadmap workstreams.
Phase 2 — Post-quantum verifiable memory
Status: Initial technical demonstrator completed; production integration remains planned
Phase 2 introduces cryptographic evidence that a protected Chordian memory object has not been modified since it was committed and that its provenance record was signed by an authorized identity. Chordian has demonstrated ML-DSA-65-based post-quantum integrity verification on a representative memory-provenance manifest. Production deployment and key-management integration remain separate implementation steps.
Technology profile: ML-DSA-65; canonical signed memory manifests; source and
derived-content hashes; Merkle roots for grouped memory and audit evidence; versioned
signing-key identifiers; a /verify capability for integrity and provenance checks.
Protection provided: tamper evidence for protected memory objects; authentication of the authorized signing identity; long-lived post-quantum verification; cryptographic linkage between source content and derived memory representations; integrity evidence for audit and provenance records.
One signed manifest represents a logical memory transaction. Individual vector entries and graph edges do not require independent signatures when they are covered by the manifest's cryptographic evidence structure.
Phase 3 — Sovereign trust chain
Status: Planned
Phase 3 extends post-quantum integrity and key protection to software, offline updates, exports, and recovery material.
Technology profile: ML-DSA signatures for release and update evidence; signed container, Helm, deployment, and software-bill-of-material manifests; ML-KEM-based key protection for long-lived export and recovery envelopes; AES-256 authenticated encryption for bulk data; customer-controlled key identifiers and recovery procedures.
Protection provided: detection of altered or unauthorized software releases; authentication of offline update packages; protection of long-lived exports and recovery archives; stronger software-supply-chain controls; customer-controlled key protection for sovereign and air-gapped deployments.
The ML-KEM shared secret is never stored with an encrypted package. Stored envelopes contain only the KEM ciphertext, wrapped symmetric-key material, algorithm metadata, and signed evidence required for authorized recovery.
Phase 4 — Post-quantum identity and BYOI
Status: Strategic roadmap
Phase 4 extends the migration to long-lived machine identity, private PKI, service authentication, and customer-controlled Chordian deployments.
Initial scope: PQ-capable mutual TLS; private certificate authorities and machine identity; customer-managed signing and encryption roots; service-to-service authentication; BYOI tunnel hardening; connected and fully air-gapped certificate lifecycle; offline renewal, revocation, and recovery processes.
Protection provided: long-term authentication of services and customer infrastructure; reduced exposure to future signature forgery; stronger customer-controlled trust roots; authenticated communication between Chordian and sovereign environments; a migration path for long-lived classical RSA and elliptic-curve identities.
This phase depends on client, server, private-PKI, key-management, and customer-infrastructure interoperability. Availability will therefore be documented per deployment profile rather than as a single universal platform flag.
Deployment profiles
Post-quantum capabilities are evaluated and documented independently for each deployment model. A capability is described as available only after it has been tested and evidenced in the relevant deployment profile.
| Deployment profile | Hybrid PQ transport | Verifiable memory | Customer-controlled keys | Offline operation |
|---|---|---|---|---|
| Chordian managed cloud | Initial priority | Initial priority | Optional target | Not applicable |
| Chordian dedicated environment | Initial priority | Initial priority | Optional target | Limited |
| Customer cloud account | Provider-dependent rollout | Portable target | Supported target | No |
| Customer-owned server | Runtime-dependent rollout | Portable target | Supported target | Supported target |
| Fully air-gapped environment | Local interfaces only | Portable target | Required profile | Dedicated operating model |
Evidence and assurance
Each implemented capability is supported by technical evidence. Planned capabilities are described as available only after the relevant technical evidence has been captured. Evidence may include:
- cryptographic inventory and migration status;
- verified connection and TLS-termination maps;
- negotiated TLS-group records;
- compatibility and performance benchmarks;
- reproducible signature and tamper tests;
- versioned algorithm and key-management policies;
- deployment-specific support matrices;
- independent security review for production cryptographic designs.
Customer relevance
This programme is designed first for organizations whose information remains valuable or sensitive over long periods, including:
- financial institutions and regulated financial-market organizations;
- government, defence, and national-security supply chains;
- operators of critical infrastructure;
- healthcare and pharmaceutical research;
- legal, compliance, and regulated records;
- industrial research and product intellectual property;
- long-lived source code and technical designs;
- confidential M&A, board, and strategic records;
- sovereign and air-gapped deployments.
A practical qualification question
Would disclosure, alteration, or forgery of this information still cause material harm five, ten, or fifteen years from now? Where the answer is yes, early cryptographic migration can provide meaningful risk reduction.
Standards and external references
- NIST FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism Standard
- NIST FIPS 204 — Module-Lattice-Based Digital Signature Standard
- NIST Post-Quantum Cryptography Project
- European Commission — Coordinated implementation roadmap for the transition to post-quantum cryptography
- UK NCSC — Timelines for migration to post-quantum cryptography
- AWS — Application Load Balancer security policies
- Cloudflare — Post-quantum cryptography between edge and origin
Roadmap status
Phase 0 completed · Phase 1 initial technical verification completed, deployment-profile validation in progress · Phase 2 initial technical demonstrator completed, production integration planned · Phase 3 planned · Phase 4 strategic roadmap