IT REGULATIONS COMPLIANCE.

Global Standards & Frameworks

1. Global Cryptographic Standards

Quantum Blue strictly adheres to the final Post-Quantum Cryptography (PQC) standards published by the National Institute of Standards and Technology (NIST). We implement FIPS 203 (ML-KEM) for key encapsulation and FIPS 204 (ML-DSA) for digital signatures. We do not use deprecated Round-3 submissions (Kyber/Dilithium).

2. Legal Evidence & Timestamping

Our timestamping authority operates in strict compliance with IETF RFC 3161. Certificates and verification logs generated by the platform are formatted specifically to meet the evidentiary requirements of the Indian Evidence Act, 1872 — Section 65B(4), ensuring electronic records are legally admissible in courts.

3. Data Protection & Privacy Laws

Quantum Blue is designed with Privacy by Design principles to comply with:

  • GDPR (General Data Protection Regulation): Providing transparent data processing and ensuring data subject rights.
  • DPDPA (Digital Personal Data Protection Act, India): Lawful processing of digital personal data within the territorial scope of India.
  • CCPA (California Consumer Privacy Act): Safeguarding consumer privacy rights and data transparency.
  • UAE PDPL (Federal Decree-Law No. 45 of 2021): Ensuring compliance with personal data protection laws within the UAE.

4. DIFC / UAE

Quantum Blue's output format has been mapped to DIFC Electronic Transactions Law (DIFC Law No. 2 of 2017) and DIFC Courts (RDC Parts 28 & 29) requirements, alongside the UAE National Encryption Policy (NEP 2025). [Status: complete — legal review pending].

5. Audit Trails & CBOM

The platform generates Cryptographic Bill of Materials (CBOM) conforming to the CycloneDX standard. This ensures organizations can maintain comprehensive, standardized audit trails of their cryptographic assets for regulatory compliance and zero-trust architectures.