QAPP is an open trust layer that lets regulated organisations prove their post-quantum compliance work to regulators and auditors without exposing the sensitive details inside it. It anchors tamper-evident fingerprints of compliance evidence to Filecoin, turning a legal obligation that already affects roughly 182,000 organisations in the EU alone into recurring, verifiable, paid storage demand for the network. Built by DeployQuantum, with the record format, the pipeline that writes evidence to Filecoin, and the verifier that checks it all released open source so any compliance vendor can use it.
Make verifiable compliance a public good, and bring a large class of paying regulated organisations onto Filecoin in the process. Roughly 182,000 entities in the EU alone now carry legal post-quantum deadlines, and each one needs a trustworthy, private way to prove its readiness over many years. By building the trust layer in the open, we want every compliance vendor, not just DeployQuantum, to be able to use Filecoin as the place where regulated evidence is anchored and verified.
Regulated organisations face a contradiction. Laws like DORA, NIS2, and CNSA 2.0 require them to prove their post-quantum readiness to regulators, and to show that their vendors are ready too. But the evidence that proves it, things like cryptographic inventories and exposure assessments, maps out exactly where their weak points are, so they cannot safely publish it. Today they are left with two poor options: expose sensitive details to prove the work is real, or keep it private and ask everyone to take their word for it. There is no neutral way to prove that a piece of compliance evidence existed, when it existed, and that it has not been altered, without revealing what is inside it.
QAPP turns each piece of compliance evidence into a fingerprint, a hash commitment that reveals nothing about the contents but changes completely if a single detail changes. We anchor that fingerprint, with a timestamp, to Filecoin as a paid, verifiable, tamper-evident storage deal. When a regulator or auditor needs to check the evidence, the organisation shows them the document privately and they recompute the fingerprint against the one stored on Filecoin. They confirm the evidence existed at a given time and has not been touched since, without ever seeing the underlying systems. The record schema, the pipeline that writes evidence to Filecoin, and the verifier that checks it are all open source, so any compliance vendor can adopt Filecoin as a neutral evidence layer.
DeployQuantum runs a three-layer model. The open trust layer, the record format, the pipeline, and the verifier, is free and open source. Revenue comes from the upstream commercial work that produces the evidence in the first place: cryptographic inventories, exposure assessments, and vendor attestation services sold to regulated organisations on fixed-scope, fixed-price engagements. Over time, optional enterprise workflow software on top of the open layer, things like dashboards, reporting, and multi-tenant management, becomes a recurring revenue line. The open layer drives adoption and trust; the paid services and the software capture the value.
Global, with primary focus on EU and US regulated sectors. Team based in Athens, Greece.