RANNTA PQ CloudOpen Console
Menu

Hosted ML-DSA-65 verification · separate Mainnet transport reference

Post-Quantum Verification for Authorization Paths

PQ Cloud cryptographically verifies ML-DSA-65 signatures over a canonical payload. Your system performs its existing classical authorization first and submits classical_verified=true as a customer assertion. PQ Cloud requires that assertion under its HybridRequired service policy, but does not independently verify your classical signature or authorization event.

RANNTA X-Chain Mainnet separately operates hybrid post-quantum authorization and validator-sensitive transport. That Mainnet transport is a production reference for professional integration work, not a feature automatically added to traffic by a hosted PQ Cloud subscription.

Customer-held keysML-DSA-65 verificationCustomer classical assertionFail-closedCanonical payloadValid / Rejected

HOW IT WORKS

1. Your backend completes its existing classical authorization and determines whether it passed.2. Your signer creates ML-DSA-65 evidence over the exact canonical payload. The private key stays with you.3. Your backend submits the payload, ML-DSA-65 evidence, registered public-key reference, policy context and its classical_verified assertion.4. PQ Cloud cryptographically verifies ML-DSA-65 evidence, key state and policy, and requires the customer classical assertion to be true.5. PQ Cloud returns Valid or Rejected. Your backend makes the final business decision.

SECURITY MODEL

ML-DSA-65
Cryptographic signature verification over the canonical payload.
HybridRequired service policy
Requires the customer's classical-authorization assertion plus valid ML-DSA-65 evidence. PQ Cloud does not cryptographically verify the customer's classical factor.
Fail-closed
Missing, invalid or policy-rejected evidence is not treated as authorization.
Customer-held keys
PQ private keys remain in the customer's signer, service or HSM.
Canonical payload
Verification binds to a deterministic payload representation.
Mainnet reference
RANNTA X-Chain operates HybridRequired authorization and validator-sensitive X25519 + ML-KEM-768 transport. This is RANNTA-published implementation evidence, not a third-party audit.

WHAT PQ CLOUD DOES

  • Cryptographically verifies ML-DSA-65 evidence over the canonical payload.
  • Checks the registered public key, key version and configured service policy.
  • Requires the caller's classical_verified assertion when HybridRequired is configured.
  • Returns Valid or Rejected to the calling backend.

WHAT PQ CLOUD DOES NOT DO

  • Does not receive or custody customer PQ private keys.
  • Does not independently cryptographically verify the customer's classical authorization factor.
  • Does not automatically convert customer network transport to ML-KEM.
  • Does not make the customer's final business allow/deny decision.

Professional engineering

Production integration is a separate engagement

Hosted API plans pay for verification capacity. Engineering RANNTA into an exchange withdrawal path, treasury system, blockchain validator stack, protocol administration path or validator-sensitive transport path is scoped and priced separately.

Architecture assessment · from $2,500
Authorization and transport boundary review, threat model, integration design and implementation plan.
Exchange integration · from $10,000
Withdrawal, treasury, wallet-backend or administrative authorization integration.
Blockchain / validator integration · from $25,000
Validator, node, protocol-operation or treasury authorization integration, with validator-sensitive hybrid transport integration where required.
Enterprise / custom engineering
Complex deployments, multiple authorization or transport paths, custom operational requirements and audit support are quoted by scope.

Assurance boundary: RANNTA publishes its own implementation and Mainnet acceptance evidence. No independent third-party audit, NIST ACVP/CAVP validation, CMVP validation or certification is claimed unless a specific external report or certificate is linked.

Trust package

Inspect the verification boundary before integration

Review canonicalization, customer-side cross-checks, failure cases, service status and sandbox reject paths. These materials are RANNTA-published implementation evidence unless explicitly identified otherwise.

Mainnet and PQ Cloud implementation evidence

Hosted API · prepaid 30-day plans

PQ Cloud API Pricing

These plans price hosted ML-DSA-65 verification request entitlement. They do not include production integration engineering, a guaranteed requests-per-second rate, burst capacity, concurrency level, availability commitment or SLA unless separately agreed in writing.

Important: the $599 Business plan is a hosted API entitlement for up to 10,000,000 verification requests during its 30-day period. It is not an exchange, blockchain, validator or transport integration fee, and it is not a statement that 10,000,000 requests can be delivered at any particular RPS, burst or concurrency level. Additional API keys do not multiply a project's plan quota.