Each check below calls the API (https://api.pqcrypta.com/compliance/*) or measures
this browser, and shows what came back. Nothing is precomputed. The library behind it is
/encryption/compliance/; the documentation
gives every endpoint's request, response and access, and what each module calls.
PQ Crypta holds no FIPS 140-3 (CMVP), Common Criteria or SOC 2 certificate: these are
algorithm-level and host-level checks, and the API says so (cmvp_validated: false).
API key (for the last two checks)
The first three checks are public and run without a key, whatever is entered here. Compliance proofs need any API key; the CIS host controls need an administrator's. A key the API does not recognise is refused, with the API's reason shown under the check. The key stays in this page and is sent only to api.pqcrypta.com.
FIPS standing of every engine
Each engine's declared primitives against NIST's standards (FIPS 186-5, 197, 198-1, 202, 203, 204, 205; SP 800-38D, 800-132, 800-232). POST /compliance/fips/validate
Policy profiles
Which engines meet a profile, requirement by requirement. POST /compliance/profiles/evaluate
Entropy: this browser beside the server
A million bits from crypto.getRandomValues through six NIST SP 800-22 tests and three SP 800-90B min-entropy estimators, beside the same tests the server runs on its own generator (GET /compliance/entropy). A test passes at P ≥ 0.01, so a perfect source fails one of the seven now and then.
Zero-knowledge proof of approval
For each primitive an engine declares, a Groth16 proof that it is one of the FIPS-approved primitives, without saying which; then each proof verified. An engine with an unapproved primitive gets no proof. Needs an API key. POST /compliance/zk/generate, /compliance/zk/verify
CIS host controls
CIS Linux Benchmark recommendations checked on the host the API runs on (SSH and sudo, kernel and network parameters, logging, file permissions, updates), plus platform controls. Needs an administrator's key. POST /compliance/cis/validate