4QVault
Air-gapped cryptographic attestation for IL5/IL6, federal, and intelligence environments.
Same Decision Ledger code as Attest. Fully offline. No telemetry. SEALSQ EK chain anchor. Single-binary verifier. SBIR / SEWP / OTA path. Built for the environments where the internet doesn't go.
Air-gapped by construction
No outbound calls. No phone-home. No telemetry. Verification works against the local ledger and a SEALSQ-bound EK chain.
SEALSQ TPM/HSM-bound
Endorsement Key chain anchored on the customer's SEALSQ TPM. Attestation packets include the chip serial — physical chain of custody is provable.
Single-binary verifier
`4q attest verify packet.json --offline` — no Python runtime needed. One static binary deployable on a SCIF laptop. Reproducible builds.
Strict liboqs
liboqs 0.10+ with strict mode (no SIKE, no fallback). FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) only.
Ledger export + offline anchor
Export the full Merkle tree as a portable artifact, anchored to the SEALSQ EK. Verify on a clean room machine without trust in 4Qubits.
No telemetry
Zero metrics, zero logs, zero analytics. Operator opt-in only. Built to the IC threat model first.