Products

PaymentsSmart contractsAttributionTokenizationTreasury & walletsComplianceGovernanceSecurity

Solutions

Platforms & marketplacesAgencies & service firmsEnergy & infrastructureAI agents & autonomous commerceReal-world assets

Developers

DocumentationAPI referenceNetwork statusBridge & webhooks

Company

Pricing Company Contact sales Sign in

XODIAK / Security

Post-quantum by default

Security

Post-quantum signatures, a geometric cipher, and a command authority that assumes keys will move.

Signed for the decade after this one.

A settlement record has to be verifiable long after it is written. Elliptic curve signatures are fine today and are a known liability against a cryptographically relevant quantum computer. XODIAK was built on the NIST post-quantum standards from genesis rather than planning a migration later.

LayerPrimitiveStandard
SignaturesML-DSA-65FIPS 204 / Dilithium-3
Key exchangeML-KEM-768FIPS 203 / Kyber-768
Transaction encodingQBC-G1 geometric cipherProprietary. The encoded shape is the ciphertext.
Hashing and inclusionSHA-256 with Merkle treesStandard
Command authorityQDCAFour-tier distributed authority
QBC-G1

The shape is the ciphertext.

Transaction fields are encoded into a geometric information object before hashing. The hash is taken over that object, the signature is over the hash, and verification runs the same path in reverse. Encoding is part of the transaction identity rather than a wrapper around it.

The cipher is ours and is not a published standard. It sits alongside the NIST primitives rather than in place of them: if you strip QBC out entirely, the signatures and the Merkle inclusion proofs still carry the security argument.

A polished faceted geometric object against black, the visual form of an encoded transaction under the QBC-G1 cipher.
Command authority

Keys are expected to move.

QDCA is a four-tier authority model over who may sign what. It exists because the realistic failure mode for a settlement network is not a broken cipher, it is a key in the wrong place. Rotating a signing key off a machine is a supported operation with a recorded outcome, not an incident.

Rotation is first class

A rotated key leaves a record of the rotation, the hash of the previous key and the time it happened. A node whose signer has been rotated away stops producing rather than producing something unverifiable.

Separation of duties

Proposing a block, attesting a reserve, executing a passed proposal and approving a tier change are distinct authorities. One compromised credential does not carry the others.

Reporting a vulnerability

Send it to bill@bdsrvs.com with enough detail to reproduce. We will confirm receipt and tell you what we are doing about it. Please do not test against production balances that are not yours.

Ready to get started?

Create an account instantly, or talk to us about a settlement design for your business.

See what you'll pay

Per-settlement pricing tied to what actually moves. No seat licences, no hidden spread.

Pricing details

Start building

Open an account, sign a transaction, read a block. About ten minutes end to end.

Integration options