Skip to main content
Koperateur native cryptography

Signed commitments, monitored integrity

We develop our own cryptographic engine and integrate it into our systems. Post-quantum signatures, hybrid encryption and integrity monitoring serve a shared requirement: retaining control over evidence and protection.

Koperateur Consulting seal Sphere bringing together classical bits and qubits
View the signed evidence
01 · Our engineering

A cryptographic engine under our control

Developed through our work on QSN, our binary brings together signing, key establishment, encryption and attestation. We control its integration and maintenance, using documented cryptographic primitives.

Sign and verify

The declaration published here carries an SLH-DSA-SHAKE-256s signature produced by our binary. The document, detached signature and public key allow its authenticity and integrity to be checked.

Protect exchanges

Our engine also supports hybrid post-quantum cryptography, or HPQC. It combines mechanisms including X25519 and ML-KEM to establish the keys that protect exchanges within our QSN network systems.

Distinct uses, shared control

The evidence on this page is a post-quantum document signature. Hybrid encryption and network transport are QSN capabilities. This distinction makes clear what is implemented and what each piece of evidence can establish.

Protected engineering, accessible evidence

Our source code and cryptographic binaries remain private. We make signed documents, signatures, public keys and verification results available so that our commitments can be examined.

Our history includes many contributions to open source. We have chosen to protect our new developments to sustainably fund research, security reviews, fixes and maintenance. AI accelerates the reuse of code and concepts, reinforcing the need for responsibility and reciprocity. We support our clients through documented interfaces and defined audit scopes.

Limiting the distribution of our implementation preserves our know-how. Cryptographic resistance rests on documented primitives, protected keys and a controlled implementation.

02 · Our integrity monitor

Detect discrepancies and support protective action

The integrity monitor developed by Koperateur compares monitored files against a signed reference. A detected discrepancy can trigger an alert and take the affected site offline to stop serving altered content.

Define the expected state

Versioning and sealing establish a reference for the monitored scope. Authorised changes are accompanied by a new release and a new reference.

Maintain control over time

Monitoring extends the work of system design and operation. It complements the system’s other safeguards; its scope and response are defined for each integration.

03 · Public evidence

Our declaration, signed by our binary

This warrant canary is a dated declaration by Koperateur Consulting. Our binary verifies the post-quantum signature before publication and when this evidence is opened.

Post-quantum signature verified Dated declaration published Declared date: September 8, 2026 Scheduled renewal: October 1, 2026

SLH-DSA-SHAKE-256s · Detached signature · Empty context

KOPERATEUR WARRANT CANARY
Publication: https://koperateur.com
Document profile: Koperateur Canary PQC v1
Date: 2026-09-08
Signature: Koperateur Consulting / SLH-DSA-SHAKE-256s
Public key fingerprint (SHA-256): 434da2749174c0c7669338948c05b62ef55c1b98ff22f58ac3e35fc2a95f8b35

STATEMENT:
1. We have NOT received any National Security Letter.
2. We have NOT been served with any secret court order.
3. We have NOT placed any backdoors in our hardware or software.
4. We have NOT received any gag order.
5. We have NOT been compelled to disclose any user data outside of public legal process.

If this file is not updated within 40 days, please treat this as a warning requiring investigation.
Next scheduled signature: 2026-10-01

Previous signed declaration hash (SHA-256):
b5c4ea5652997a5cad2e8e2060a471cd50075c7e461ee199f032077e4a7df8de
Document fingerprint · SHA-256 cb64c7870d3807693a77810de0aa83f34ed3d0adeab60922a01096b999d249b0
Public key fingerprint · SHA-256 434da2749174c0c7669338948c05b62ef55c1b98ff22f58ac3e35fc2a95f8b35

Verify the evidence on Quaric.org

Download the evidence bundle above, then import it into the Quaric demonstration. Our engine checks the signature, Koperateur’s reference public key and their correspondence with the signed document. Fingerprints and dates are displayed for comparison. No software installation is needed.

Open the Quaric verifier

What the signature establishes

It allows the link between the document and the published key to be checked, together with the absence of changes since signing. It does not, by itself, establish the truth of every statement. A renewal delay calls for investigation without automatically establishing its cause.

Continuity of evidence

The OpenPGP declaration from the earlier system remains accessible during this transition. The declaration shown here is generated and verified internally by Koperateur’s native engine.

View the OpenPGP declaration
04 · Prepare for the transition

The post-quantum transition has already begun

French and European roadmaps already set out the progressive adoption of post-quantum cryptography. The milestones are defined; preparing for them is part of managing systems over time.

In France, ANSSI has announced that integrating PQC will become mandatory for certain types of cryptographic products entering its qualification process from 2027.

The French government roadmap requires ministries to inventory long-term sensitive data by the end of 2026 and identify the relevant cryptographic components before the end of 2027. It requires PQC deployment across all systems handling information marked Diffusion Restreinte before the end of 2030.

The European roadmap calls for Member States to start their transition by the end of 2026 and migrate high-risk use cases no later than the end of 2030.

Koperateur Consulting has chosen to build this capability ahead of these deadlines.

Our engineering brings together proprietary components for network transport, hybrid encryption, signing and verification. The verifiable post-quantum signature on this page is a concrete application. We draw on this integration and operational experience to support the transition of systems already in production.

Official references

Prepare your post-quantum transition

Map your data and cryptographic uses, identify dependencies and components to replace, then build a progressive path towards PQC or HPQC. We start with your systems, constraints and deadlines.