Security Architecture

Security that starts with physics

QKD provides unconditional information-theoretic security for key exchange. Pramatra's architecture adds defense-in-depth layers for authentication, transport, and key storage that hold regardless of algorithmic advances.

Core Principles

Seven layers of independent protection

Each security layer in Pramatra's architecture is independently effective. Compromising one layer does not reduce the protection provided by the remaining layers.

QKD unconditional secrecy
The quantum channel's security is information-theoretic, not computational. No advance in computing power, algorithmic mathematics, or cryptanalysis can retroactively expose key material transmitted via BB84.
Eavesdrop detection
Any measurement on a photon in transit collapses its quantum state, introducing detectable errors. QBER above the 11% threshold triggers automatic session abort before any key material is accepted.
ML-KEM hybrid key exchange
The classical reconciliation channel uses TLS 1.3 with ML-KEM (CRYSTALS-Kyber, NIST FIPS 203) hybrid key encapsulation. The QKD channel and ML-KEM channel must both be compromised independently.
ML-DSA digital signatures
Ground station authentication uses ML-DSA (CRYSTALS-Dilithium, NIST FIPS 204) digital signatures. Classical ECDSA-based authentication is vulnerable to Shor's algorithm; ML-DSA is not.
HSM-backed key storage
Key material at the ground station and KMA appliance resides in hardware security modules validated to FIPS 140-2 Level 3. Keys are never in plaintext outside HSM boundaries. Physical tamper resistance is enforced in hardware.
Continuous key rotation
Session keys rotate at configurable intervals. Per-hour rotation limits decryptable traffic volume to one hour's worth. Per-session rotation means each communication uses a fresh key drawn from the orbital source.
Zero trust access control
The management plane and key delivery API require mutual authentication on every request. There are no persistent sessions. Key endpoint identities are cryptographically bound to ML-DSA certificates.
Standards Alignment

Built on public standards, pursuing formal certification

Pramatra's implementation is built on publicly specified, peer-reviewed standards. Formal certification processes are in progress where applicable.

NIST PQC Standards
ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) are the finalized NIST post-quantum cryptography standards. Pramatra's hybrid mode implements ML-KEM for key encapsulation and ML-DSA for digital signatures. These are public standards, not Pramatra-proprietary algorithms.
ETSI QKD Standards
The key delivery API implements ETSI GS QKD 014 (REST-based key supply interface) and references ETSI GS QKD 011 (component specification) and ETSI GS QKD 012 (orchestration). These are the primary international QKD interoperability standards.
Certification note
Common Criteria evaluation and formal FIPS 140-3 validation processes for the KMA appliance are in planning. Current deployment uses FIPS 140-2 Level 3 validated HSM modules from established hardware vendors. We do not claim certifications that have not been awarded. Where we reference FIPS standards, we are citing the underlying public specifications, not asserting product certification.
Responsible Disclosure

How to report a security vulnerability

If you believe you have found a security vulnerability in Pramatra Space's platform, API, or related systems, we encourage responsible disclosure. We will investigate reports promptly and communicate findings to you.

Contact
Send vulnerability reports to [email protected]. Use PGP encryption if the report contains sensitive technical details. Our public key is available on request.
Response timeline
We target initial acknowledgement within 2 business days. We aim to provide a remediation timeline within 10 business days for confirmed vulnerabilities. We ask for 90 days before public disclosure to allow remediation.
Scope
In-scope: the ETSI QKD API endpoint, the KMA appliance firmware, the management dashboard, and any authenticated API. Out of scope: social engineering, physical attacks requiring hardware access, third-party services not operated by Pramatra Space, and theoretical attacks against the underlying mathematical primitives.