One platform for the
post-quantum era.
MyPQC is one layered stack. A Crypto Agility Core Engine sits at the foundation. On top of it run four quantum-safe apps and managed PKI and monitoring services. A single API layer opens the whole platform to the enterprise software providers and Tier-1 integrators who build on it. Post-quantum by default, sovereign by design, and agile enough to swap algorithms by policy.
Aligned with NIST FIPS 203 / 204 / 205 · sovereign KAZ options alongside · W3C DID data model (v1.1) · Digital Signature Act 1997
The platform at a glance
Four layers, one sovereign foundation
An API layer for builders, four turnkey quantum-safe apps for users, and managed services for operators. All of it rests on the Crypto Agility Core Engine, which governs which algorithm runs.
The MyPQC stack. The API layer surfaces the platform to integrators. The ready-to-use apps and managed services sit in the middle. The Crypto Agility Core Engine (risk, agility middleware, PQC orchestration, and policy enforcement) is the foundation everything else builds on.
How the platform is layered
Every layer does one job, cleanly
The crypto-governance foundation stays separate from the apps that use it and the API that exposes it. Each layer can change without breaking the others.
Crypto Agility Core Engine: the foundation
The policy-driven layer beneath everything: crypto-risk assessment, agility middleware, PQC orchestration, and enterprise-wide policy enforcement. A CISO changes the algorithm for a cryptographic purpose from one portal, and every connected system applies it. No application code changes, no redeployment.
Ready-to-use apps
Quantum-safe applications built directly on the core engine: Sovereign PQC Digital ID, Document Signing, and Secure File Sharing & Storage. Quantum-safe Messaging & Video is on the roadmap. Deploy the app suite instead of assembling crypto yourself.
Managed services
Operated capabilities that keep the estate healthy: PQC certificate issuance and management, digital-ID management, and continuous cryptography inventory and monitoring. This is the observability and PKI plane that feeds the core engine what it needs to govern.
API layer
One versioned integration surface for third-party enterprise software providers and Tier-1 system integrators. Partners embed quantum-safe identity, signing, sharing, and crypto-agility into their own products without building cryptography from scratch.
The four apps
Ready to use, quantum-safe, and crypto-agile from day one
Adopt the whole suite or start with a single app. Each one is PQC-native and inherits the same trust anchor, policy model, and tamper-evident audit spine.
Sovereign PQC Digital ID
Self-sovereign identity, adapted from the W3C DID data model, with post-quantum keys and X.509 linkage for legally recognized signatures in Malaysia.
Learn moreMCert: Crypto Inventory
Continuously discover, inventory, and monitor every cryptographic asset: CBOM/SBOM, quantum-risk scoring, and signed regulator reporting.
Learn moreDocument Signing
Add a post-quantum signature to any file, including PDFs. Anyone can verify it with no PQC software of their own.
Learn moreSecure File Sharing
End-to-end encrypted sharing with per-recipient PQC key wrapping, revocation, expiry, and cryptographic shredding after delivery.
Learn moreQuantum-safe Messaging & Video
Sovereign, post-quantum messaging and video on the same platform trust model and Crypto Agility Core Engine. On the roadmap.
Learn moreHow migration works
Discover → Govern → Prove
MyPQC turns post-quantum migration from a one-off project into a repeatable, auditable program. Visibility first, policy-driven control next, verifiable evidence last.
Discover
MCert's containerized, ephemeral scanners find every algorithm, certificate, key, protocol, and crypto library across servers, apps, network devices, containers, and code. Everything is normalized to CycloneDX CBOM/SBOM and scored for quantum risk. You can't migrate what you can't see.
Govern
The Crypto Agility Core Engine turns those findings into policy. Bind a cryptographic purpose to an algorithm, schedule a transition with an effective date, and every connected system switches automatically, with no redeploy. The self-describing envelope keeps everything already encrypted or signed verifiable.
Prove
Signed, optionally encrypted CBOM and risk reports, plus a tamper-evident audit trail, show exactly which algorithms are in use and how far migration has progressed. The next scan auto-verifies remediation against the live environment.
Why sovereign & standards-based
Aligned with the NIST standards. Sovereign by choice.
MyPQC implements the finalized NIST post-quantum algorithms and offers Malaysian sovereign options alongside them. Crypto-agility means the choice is never locked in. You standardize on open standards and keep the freedom to swap algorithms by policy as guidance evolves.
Aligned with NIST FIPS 203 / 204 / 205. MyPQC implements ML-KEM, ML-DSA, and SLH-DSA, the finalized NIST PQC standards. (Standards alignment, not a FIPS-140 validation claim.)
Sovereign KAZ options alongside. KAZ-SIGN and KAZ-KEM are optional, policy-selectable Malaysian sovereign algorithms offered alongside the NIST standards. They never replace them, and they stay swappable at any time.
Digital Signature Act 1997 alignment. Identity and signing link to an X.509 certificate from an MCMC-licensed CA for legal recognition. This is a deployment capability, not an automatic guarantee.
On a credible timeline. NIST's proposed roadmap (draft IR 8547) would deprecate RSA/ECC around 2030 and disallow them around 2035. "Harvest now, decrypt later" already puts today's encrypted data at risk.
Standards & algorithms
| Purpose | NIST standard | Sovereign option |
|---|---|---|
| Key encapsulation | ML-KEM · FIPS 203 | KAZ-KEM (optional) |
| Digital signatures | ML-DSA · FIPS 204 | KAZ-SIGN (optional) |
| Hash-based signatures | SLH-DSA · FIPS 205 | None |
| Symmetric encryption | AES-256-GCM | None |
| Crypto inventory | CycloneDX CBOM / SBOM | MySEAL / NACSA mapping |
Reporting maps to NIST SP 800-131A, MySEAL, NACSA and BNM RMiT, with secure regulator transfer to NACSA and Bank Negara Malaysia. Identity is adapted from the W3C DID data model (v1.1, a Candidate Recommendation).
See the whole platform in action
Get a walkthrough of the layered stack and a quantum-readiness assessment for your organization.