Cryptographic Resilience

Chordian's standards-aligned approach to cryptographic agility, hybrid post-quantum transport, verifiable sovereign memory, and long-term protection.

Chordian's security architecture is designed to preserve the confidentiality, integrity, provenance, and operational trust of sovereign enterprise memory as cryptographic standards evolve.

The programme includes a phased transition to post-quantum cryptography (PQC) using the NIST-standardized ML-KEM key-establishment mechanism under FIPS 203 and ML-DSA digital signatures under FIPS 204. During the interoperability period, post-quantum algorithms are combined with established classical cryptography rather than introduced as a disruptive platform-wide replacement.

Current status

Phase 0 on the established Chordian Cryptographic Resilience Roadmap is complete. Chordian has selected the applicable standards, mapped the principal protection boundaries, established the initial algorithm profile, and defined the phased implementation and evidence model. Phase 1 initial technical verification is complete; deployment-profile validation is in progress.

Why cryptographic resilience matters

Enterprise memory contains information that can remain valuable for many years: intellectual property, source code, contracts, strategic decisions, audit evidence, regulated records, and operational history.

Classical public-key mechanisms such as RSA and elliptic-curve cryptography may eventually become vulnerable to sufficiently capable quantum computers. This creates a present-day risk for long-lived confidential information because an attacker can collect encrypted traffic or archives now and retain them for future decryption. This threat model is commonly described as Harvest Now, Decrypt Later.

Chordian addresses this risk through a staged migration that prioritizes controls with measurable security value for long-lived enterprise data.

Swiss-Engineered Security for the Trusted Workplace

A Trusted Workplace requires more than secure access to individual applications. It requires organisational knowledge, AI interactions, identities, and operational records to remain within clearly defined trust boundaries throughout their lifecycle.

Chordian applies Swiss-engineered security principles centred on data sovereignty, accountability, least-privilege access, operational resilience, and verifiable control over sensitive enterprise information. Institutional memory can be deployed within customer-defined infrastructure and jurisdictional boundaries, with layered identity controls, isolated retrieval, auditable activity, and cryptographic protection designed for long-lived data.

This approach is informed by the security and resilience principles reflected in the Swiss Federal Act on Data Protection and Switzerland's national ICT minimum-standard guidance. For regulated financial-sector deployments, Chordian's controls and deployment evidence can also be mapped against relevant FINMA expectations concerning cyber risk, critical data, outsourcing, and operational resilience.

Trusted Workplace principles

  • Sovereign by design — customers retain control over where institutional memory is processed and stored.
  • Zero-trust access — every user, service, and agent must be authenticated and authorised before accessing protected knowledge.
  • Verifiable activity — sensitive actions, memory operations, and administrative events are recorded for review and assurance.
  • Resilient operations — deployment boundaries, recovery processes, and cryptographic controls are designed for continuity and long-term protection.
  • Future-ready security — Chordian's cryptographic resilience roadmap prepares long-lived enterprise memory for evolving standards, including the transition to post-quantum cryptography.

The Trusted Workplace is a controlled enterprise environment in which people and authorised AI systems can work with shared institutional knowledge without surrendering ownership, jurisdiction, or security control.

Protection model

Protection boundaryPurposeInitial technology profileProtected assets
Hybrid post-quantum transportProtect selected network traffic against future decryptionTLS 1.3 with X25519MLKEM768API, MCP, connector, and supported origin traffic
Verifiable sovereign memoryDetect modification and authenticate protected memory provenanceML-DSA-65, signed manifests, Merkle evidenceMemory objects, derived records, and audit checkpoints
Sovereign trust chainProtect software, offline updates, exports, and recovery materialML-DSA signatures, ML-KEM key protection, AES-256 bulk encryptionReleases, backups, exports, and air-gapped update packages
Post-quantum identity and BYOITransition long-lived machine identity and private infrastructurePQ-capable mTLS, private PKI, and crypto-agile service identityCustomer infrastructure, services, and sovereign deployments

Cryptographic policy

Chordian's initial post-quantum profile is based on the following principles.

ML-KEM-768 for key establishment

ML-KEM-768 is the initial Chordian profile for post-quantum key establishment. It is used to establish or derive cryptographic key material. It is not used as a replacement for bulk-data encryption.

ML-DSA-65 for durable signatures

ML-DSA-65 is the initial profile for durable memory manifests, audit evidence, and sovereign release signatures.

A valid ML-DSA signature provides:

  • evidence that signed data has not been modified;
  • authentication of the holder of the corresponding signing key;
  • resistance to signature forgery by future quantum-capable adversaries.

A signature authenticates integrity and provenance. It does not prove that the underlying business information is factually correct.

Hybrid classical and post-quantum operation

During the transition, Chordian uses hybrid cryptographic profiles. For TLS key establishment, the initial target profile is:

X25519 + ML-KEM-768

In compatible TLS implementations, this hybrid group is represented as:

X25519MLKEM768

The hybrid model preserves established classical protection and compatibility while adding resistance against attacks on classical key establishment.

Symmetric encryption remains in use

AES-256 authenticated encryption remains Chordian's approved profile for bulk-data protection where Chordian controls the encryption layer. Deployment-specific coverage is documented separately. Post-quantum cryptography is introduced around the public-key mechanisms used to establish, distribute, or protect symmetric keys.

Crypto-agility

Algorithm identifiers, key versions, policy versions, and migration states are represented explicitly. This allows cryptographic mechanisms to evolve without requiring Chordian to redesign or re-index the complete memory and retrieval layer.

Established implementation roadmap

Phase 0 — Standards and architecture foundation

Status: Completed · Outcome: Architecture and engineering foundation established

Phase 0 established the implementation baseline for Chordian's post-quantum transition. Completed work includes:

  • selection of NIST FIPS 203 and FIPS 204 as the standards baseline;
  • mapping of the transport, memory, storage, software, and identity protection boundaries;
  • selection of ML-KEM-768 and ML-DSA-65 as the initial algorithm profiles;
  • definition of hybrid classical and post-quantum migration principles;
  • establishment of evidence, benchmarking, and deployment-compatibility requirements;
  • definition of the phased production roadmap.

Phase 1 — Hybrid post-quantum transport

Status: Initial technical verification completed; deployment-profile validation in progress

Phase 1 validates and operationalizes hybrid post-quantum key establishment across supported TLS 1.3 deployment paths. Hybrid post-quantum TLS validation has demonstrated X25519MLKEM768 negotiation on a tested Chordian development TLS boundary. Both forced and default TLS 1.3 negotiation selected the hybrid group with a compatible client.

This is an initial technical verification milestone. Deployment-specific availability remains subject to validation for each supported environment, including operational fallback behaviour, monitoring, and client compatibility.

Initial scope: public API traffic; MCP connections; connector ingress; supported edge-to-origin connections; selected internal service paths where compatible infrastructure is available.

Technology profile: TLS 1.3; X25519MLKEM768; compatible TLS termination and OpenSSL-based infrastructure; trusted negotiation telemetry and downgrade monitoring.

Protection provided: hybrid post-quantum transport reduces the risk that encrypted traffic captured today can later be decrypted through attacks against classical public-key key establishment. The protection applies only to connections that successfully negotiate an approved hybrid group.

This TLS key-establishment evidence does not make certificate authentication, identity systems, private infrastructure links, storage, exports, or all internal service traffic post-quantum by default. Those areas remain separate roadmap workstreams.

Phase 2 — Post-quantum verifiable memory

Status: Initial technical demonstrator completed; production integration remains planned

Phase 2 introduces cryptographic evidence that a protected Chordian memory object has not been modified since it was committed and that its provenance record was signed by an authorized identity. Chordian has demonstrated ML-DSA-65-based post-quantum integrity verification on a representative memory-provenance manifest. Production deployment and key-management integration remain separate implementation steps.

Technology profile: ML-DSA-65; canonical signed memory manifests; source and derived-content hashes; Merkle roots for grouped memory and audit evidence; versioned signing-key identifiers; a /verify capability for integrity and provenance checks.

Protection provided: tamper evidence for protected memory objects; authentication of the authorized signing identity; long-lived post-quantum verification; cryptographic linkage between source content and derived memory representations; integrity evidence for audit and provenance records.

One signed manifest represents a logical memory transaction. Individual vector entries and graph edges do not require independent signatures when they are covered by the manifest's cryptographic evidence structure.

Phase 3 — Sovereign trust chain

Status: Planned

Phase 3 extends post-quantum integrity and key protection to software, offline updates, exports, and recovery material.

Technology profile: ML-DSA signatures for release and update evidence; signed container, Helm, deployment, and software-bill-of-material manifests; ML-KEM-based key protection for long-lived export and recovery envelopes; AES-256 authenticated encryption for bulk data; customer-controlled key identifiers and recovery procedures.

Protection provided: detection of altered or unauthorized software releases; authentication of offline update packages; protection of long-lived exports and recovery archives; stronger software-supply-chain controls; customer-controlled key protection for sovereign and air-gapped deployments.

The ML-KEM shared secret is never stored with an encrypted package. Stored envelopes contain only the KEM ciphertext, wrapped symmetric-key material, algorithm metadata, and signed evidence required for authorized recovery.

Phase 4 — Post-quantum identity and BYOI

Status: Strategic roadmap

Phase 4 extends the migration to long-lived machine identity, private PKI, service authentication, and customer-controlled Chordian deployments.

Initial scope: PQ-capable mutual TLS; private certificate authorities and machine identity; customer-managed signing and encryption roots; service-to-service authentication; BYOI tunnel hardening; connected and fully air-gapped certificate lifecycle; offline renewal, revocation, and recovery processes.

Protection provided: long-term authentication of services and customer infrastructure; reduced exposure to future signature forgery; stronger customer-controlled trust roots; authenticated communication between Chordian and sovereign environments; a migration path for long-lived classical RSA and elliptic-curve identities.

This phase depends on client, server, private-PKI, key-management, and customer-infrastructure interoperability. Availability will therefore be documented per deployment profile rather than as a single universal platform flag.

Deployment profiles

Post-quantum capabilities are evaluated and documented independently for each deployment model. A capability is described as available only after it has been tested and evidenced in the relevant deployment profile.

Deployment profileHybrid PQ transportVerifiable memoryCustomer-controlled keysOffline operation
Chordian managed cloudInitial priorityInitial priorityOptional targetNot applicable
Chordian dedicated environmentInitial priorityInitial priorityOptional targetLimited
Customer cloud accountProvider-dependent rolloutPortable targetSupported targetNo
Customer-owned serverRuntime-dependent rolloutPortable targetSupported targetSupported target
Fully air-gapped environmentLocal interfaces onlyPortable targetRequired profileDedicated operating model

Evidence and assurance

Each implemented capability is supported by technical evidence. Planned capabilities are described as available only after the relevant technical evidence has been captured. Evidence may include:

  • cryptographic inventory and migration status;
  • verified connection and TLS-termination maps;
  • negotiated TLS-group records;
  • compatibility and performance benchmarks;
  • reproducible signature and tamper tests;
  • versioned algorithm and key-management policies;
  • deployment-specific support matrices;
  • independent security review for production cryptographic designs.

Customer relevance

This programme is designed first for organizations whose information remains valuable or sensitive over long periods, including:

  • financial institutions and regulated financial-market organizations;
  • government, defence, and national-security supply chains;
  • operators of critical infrastructure;
  • healthcare and pharmaceutical research;
  • legal, compliance, and regulated records;
  • industrial research and product intellectual property;
  • long-lived source code and technical designs;
  • confidential M&A, board, and strategic records;
  • sovereign and air-gapped deployments.

A practical qualification question

Would disclosure, alteration, or forgery of this information still cause material harm five, ten, or fifteen years from now? Where the answer is yes, early cryptographic migration can provide meaningful risk reduction.

Standards and external references

Roadmap status

Phase 0 completed · Phase 1 initial technical verification completed, deployment-profile validation in progress · Phase 2 initial technical demonstrator completed, production integration planned · Phase 3 planned · Phase 4 strategic roadmap

Was this page helpful?
Report an issue

On this page