{
  "$schema": "https://kxco.ai/.well-known/pqc-evidence.schema.json",
  "generated": "2026-09-13T03:31:01Z",
  "vendor": {
    "name": "KXCO",
    "url": "https://kxco.ai"
  },
  "product": {
    "name": "kxco-post-quantum",
    "modality": "library",
    "summary": "An Apache-2.0 post-quantum cryptography library published on npm, installable and runnable by anyone without contacting KXCO.",
    "scopeOfThisDocument": "This document describes the library and the fifteen Apache-2.0 packages built on it. It does not describe the commercial KXCO registry and relay service, which is a separate subject recorded under relatedOffering. Assessments that score the two together produce a result that is true of neither.",
    "languages": [
      "JavaScript",
      "C"
    ],
    "languagesNote": "JavaScript throughout; C by way of OpenSSL 3.5, which performs the primitives on Node 24 and later. TypeScript declarations ship with the package but no TypeScript is compiled into it.",
    "runtime": {
      "node": ">=20.19",
      "moduleFormat": "ESM",
      "typeDeclarations": true
    },
    "license": "Apache-2.0",
    "repository": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum",
    "registry": "https://www.npmjs.com/package/kxco-post-quantum",
    "evidenceBundle": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/releases/latest/download/evidence-node24.x.zip",
    "evidenceManifest": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/releases/latest/download/manifest-node24.x.json",
    "evidenceBundleNote": "Permanent, unauthenticated URLs. The manifest carries a SHA-256 for every file in the bundle and records which backend produced each result. The bundle is SLSA-attested and signed with ML-DSA-65 against the public key at https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/release-signing-key.pub.hex"
  },
  "algorithms": [
    {
      "parameterSet": "ML-DSA-44",
      "standard": "FIPS 204",
      "nistSecurityCategory": 2,
      "family": "ML-DSA",
      "purpose": "digital signature"
    },
    {
      "parameterSet": "ML-DSA-65",
      "standard": "FIPS 204",
      "nistSecurityCategory": 3,
      "family": "ML-DSA",
      "purpose": "digital signature"
    },
    {
      "parameterSet": "ML-DSA-87",
      "standard": "FIPS 204",
      "nistSecurityCategory": 5,
      "family": "ML-DSA",
      "purpose": "digital signature"
    },
    {
      "parameterSet": "ML-KEM-1024",
      "standard": "FIPS 203",
      "nistSecurityCategory": 5,
      "family": "ML-KEM",
      "purpose": "key encapsulation"
    },
    {
      "parameterSet": "ML-KEM-512",
      "standard": "FIPS 203",
      "nistSecurityCategory": 1,
      "family": "ML-KEM",
      "purpose": "key encapsulation"
    },
    {
      "parameterSet": "ML-KEM-768",
      "standard": "FIPS 203",
      "nistSecurityCategory": 3,
      "family": "ML-KEM",
      "purpose": "key encapsulation"
    },
    {
      "parameterSet": "SLH-DSA-SHA2-128f",
      "standard": "FIPS 205",
      "nistSecurityCategory": 1,
      "family": "SLH-DSA",
      "purpose": "digital signature"
    },
    {
      "parameterSet": "SLH-DSA-SHA2-192s",
      "standard": "FIPS 205",
      "nistSecurityCategory": 3,
      "family": "SLH-DSA",
      "purpose": "digital signature"
    },
    {
      "parameterSet": "SLH-DSA-SHAKE-256f",
      "standard": "FIPS 205",
      "nistSecurityCategory": 5,
      "family": "SLH-DSA",
      "purpose": "digital signature"
    }
  ],
  "nistSecurityCategories": [
    1,
    2,
    3,
    5
  ],
  "hybrid": [
    {
      "name": "ML-KEM-768 with X25519",
      "purpose": "key exchange",
      "package": "kxco-pq-tls"
    }
  ],
  "implementation": {
    "backends": [
      {
        "name": "OpenSSL",
        "version": "3.5",
        "usedWhen": "Node 24 and later"
      },
      {
        "name": "@noble/post-quantum",
        "usedWhen": "Node 20 and 22, and browsers"
      }
    ],
    "note": "Both backends are exercised in full by the interoperability matrix, and every generated report records which produced it."
  },
  "conformance": {
    "acvp": {
      "source": "NIST ACVP",
      "total": 2103,
      "passed": 1793,
      "failed": 0,
      "skipped": 310,
      "skippedReason": "pre-hash pairings the library refuses as weaker than the parameter set",
      "reproduce": "npm run conformance:acvp"
    },
    "interoperability": {
      "checks": 225,
      "failed": 0,
      "notApplicable": 42,
      "rows": 38,
      "bothDirections": true,
      "negativeControls": true,
      "peers": [
        {
          "name": "liboqs",
          "version": "0.16.0",
          "language": "C"
        },
        {
          "name": "Bouncy Castle",
          "version": "1.85.2",
          "language": "Java"
        },
        {
          "name": "dilithium-py + kyber-py",
          "language": "Python"
        }
      ],
      "reproduce": "npm run conformance:interop"
    },
    "protocol": {
      "description": "X.509 certificates and CMS SignedData issued by OpenSSL and verified by the package, with its own DER parsing on the verifying side.",
      "checks": 33,
      "failed": 0,
      "notApplicable": 0,
      "rows": 6,
      "artefacts": [
        "X.509 certificate",
        "CMS SignedData"
      ],
      "parameterSets": [
        "ML-DSA-44",
        "ML-DSA-65",
        "ML-DSA-87"
      ],
      "issuer": "OpenSSL 3.5.8 25 Aug 2026 (Library: OpenSSL 3.5.8 25 Aug 2026)",
      "negativeControls": true,
      "freshlyGenerated": true,
      "reproduce": "npm run conformance:protocol"
    },
    "acvts": {
      "source": "NIST ACVTS Demo, server-graded",
      "cases": 2130,
      "failed": 0,
      "certificate": "A11025",
      "coverage": "ML-KEM keyGen and encapDecap, ML-DSA keyGen, sigGen and sigVer, SLH-DSA keyGen, sigGen and sigVer; every parameter set NIST offers for each",
      "note": "Distinct from the acvp entry above, which is this project running NIST sample vectors itself. These cases were graded by NIST. See certifications.nistAcvts for what the certificate is and is not."
    }
  },
  "supplyChain": {
    "provenance": "SLSA, per release, verifiable with `npm audit signatures`",
    "sbom": {
      "format": "CycloneDX",
      "url": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/releases/download/v1.7.2/sbom.cyclonedx.json"
    },
    "reproducibleBuilds": {
      "verified": true,
      "method": "the published tarball rebuilds byte for byte from its own tag, checked in CI on every run"
    },
    "dependencyPolicy": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/SECURITY.md",
    "dependencyAudit": {
      "description": "Every production dependency reviewed by a person, with each mechanical claim in that review re-derived from the lockfile, the registry and the installed tree by a harness that fails on any drift.",
      "productionDependencies": 4,
      "developmentDependencies": 0,
      "checks": 26,
      "failed": 0,
      "knownAdvisories": 0,
      "registrySignaturesAndAttestations": "verified across the installed tree: 0 invalid, 0 missing",
      "installScripts": "none",
      "installScriptsScope": "checked against the lockfile flag and every installed manifest in the tree",
      "licences": [
        "MIT"
      ],
      "pinning": "every direct dependency pinned to an exact version; ranges fail the audit",
      "reachabilityAnalysed": true,
      "packagesOnCodePath": 3,
      "independentlyReviewedByNamedFirms": 3,
      "reproduce": "npm run audit:deps",
      "url": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/DEPENDENCIES.md"
    }
  },
  "documentation": {
    "conformance": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/CONFORMANCE.md",
    "threatModel": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/THREAT-MODEL.md",
    "benchmarks": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/BENCHMARKS.md",
    "migration": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/MIGRATION.md",
    "security": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/SECURITY.md",
    "dependencies": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/DEPENDENCIES.md"
  },
  "packages": [
    {
      "name": "kxco-post-quantum",
      "version": "1.7.2",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-post-quantum",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-post-quantum@1.7.2"
    },
    {
      "name": "kxco-pq",
      "version": "2.0.3",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq@2.0.3"
    },
    {
      "name": "kxco-pq-sdk",
      "version": "2.0.2",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-sdk",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-sdk@2.0.2"
    },
    {
      "name": "kxco-pq-cli",
      "version": "2.1.0",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-cli",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-cli@2.1.0"
    },
    {
      "name": "kxco-pq-vault",
      "version": "1.1.5",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-vault",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-vault@1.1.5"
    },
    {
      "name": "kxco-pq-tls",
      "version": "1.2.1",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-tls",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-tls@1.2.1"
    },
    {
      "name": "kxco-pq-chain",
      "version": "2.1.4",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-chain",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-chain@2.1.4"
    },
    {
      "name": "kxco-pq-attest",
      "version": "2.0.3",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-attest",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-attest@2.0.3"
    },
    {
      "name": "kxco-pq-hsm",
      "version": "1.4.2",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-hsm",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-hsm@1.4.2"
    },
    {
      "name": "kxco-pq-audit",
      "version": "1.4.0",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-audit",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-audit@1.4.0"
    },
    {
      "name": "kxco-pq-agent",
      "version": "1.1.0",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-agent",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-agent@1.1.0"
    },
    {
      "name": "kxco-verify",
      "version": "1.3.0",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-verify",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-verify@1.3.0"
    },
    {
      "name": "kxco-post-quantum-webhook",
      "version": "1.2.2",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-post-quantum-webhook",
      "provenanceNote": "none: this version was not published through the Trusted Publishing workflow, so npm minted no provenance for it"
    },
    {
      "name": "eslint-plugin-kxco-pq",
      "version": "1.0.1",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/eslint-plugin-kxco-pq",
      "provenanceNote": "none: published from a private source repository, which npm does not sign provenance for"
    },
    {
      "name": "kxco-pq-network",
      "version": "1.0.4",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-network",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-network@1.0.4"
    },
    {
      "name": "kxco-pq-scan",
      "version": "1.1.2",
      "provenance": "https://registry.npmjs.org/-/npm/v1/attestations/kxco-pq-scan@1.1.2",
      "license": "Apache-2.0",
      "registry": "https://www.npmjs.com/package/kxco-pq-scan"
    }
  ],
  "productionEvidence": {
    "description": "Every article published on Live Trading News is signed with ML-DSA-65 and anchored on Armature L1 at publication. The page declares the signing key, the envelope digest and the transaction; the chain returns the same values.",
    "chainRpc": "https://chain.kxco.ai/rpc",
    "chainId": 1111111,
    "worked_example": {
      "article": "https://www.livetradingnews.com/kxco-native-post-quantum-cryptography-for-the-ai-and-blockchain-era",
      "transaction": "0xbb7c7cc5fca921e151b457ad18a5b9c4f2c562e70b7c2afb66e23fbd826563c1",
      "block": 90633,
      "kid": "6b8e4750027cfe89",
      "calldata": "bytes8 kid left aligned at byte 4, bytes32 digest at byte 36"
    }
  },
  "contact": "https://chain.kxco.ai/contact",
  "certifications": {
    "fips140_3": {
      "validated": false,
      "statement": "kxco-post-quantum is NOT a FIPS 140-3 validated cryptographic module and KXCO makes no such claim. The library implements algorithms specified in FIPS 203, FIPS 204 and FIPS 205; implementing a standard is not validation against it."
    },
    "cnsa_2_0": {
      "productCertified": false,
      "algorithmsOnApprovedList": true,
      "statement": "ML-KEM-1024 and ML-DSA-87, both shipped, are on the CNSA 2.0 approved list, and SLH-DSA is listed there for firmware signing. KXCO is not a CNSA 2.0 validated product and does not assert compliance. This is an algorithm mapping, not a certification.",
      "mapping": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/CONFORMANCE.md"
    },
    "nistAcvts": {
      "programme": "NIST Automated Cryptographic Validation Test System, Demo environment",
      "certificate": "A11025",
      "validationRecord": "/acvp/v1/validations/42204",
      "module": "kxco-post-quantum 1.7.2 (Software)",
      "environment": "Node.js 26.1.0 on Windows 10 Pro 22H2, Intel Core i7-7700K",
      "casesGradedByNist": 2130,
      "failures": 0,
      "sessions": [
        767289,
        767291,
        767292
      ],
      "issued": "2026-09-13",
      "statement": "Graded by NIST ACVTS servers, not self-reported. This is a DEMO certificate. It is NOT a CAVP validation, it does NOT appear on the public NIST algorithm validation list, and it is NOT a certification of KXCO as a firm. It is the reference NIST asks to be quoted when Production access is requested."
    }
  },
  "relatedOffering": {
    "name": "KXCO post-quantum registry and relay",
    "modality": "service",
    "licence": "commercial",
    "statement": "A paid, KXCO-operated service that answers questions about the present, such as whether a key was revoked after a signature was made. The cryptography is free and the source is Apache-2.0; the operated service is not. It is named here so an assessor does not attribute its commercial terms to the library.",
    "documentation": "https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/LICENCE-PRODUCT.md"
  }
}
