No enterprise tax. Just bulletproof quantum security for fast-moving teams. See Plans →

Privacy Policy

Effective date: June 1, 2026 Last updated: June 1, 2026

QuantCert, Inc. ("QuantPass," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect information when you use the QuantPass browser extension, web application, and related services (collectively, the "Services").

We built QuantPass on a zero-knowledge architecture — meaning we are technically incapable of reading your stored credentials. This is not a policy choice. It is a cryptographic guarantee.


1. Who We Are

QuantPass is a post-quantum credential management platform developed by QuantCert, Inc. Our Services use NIST-standardized post-quantum cryptographic algorithms — ML-DSA-44 (FIPS 204) for authentication and ML-KEM-1024 (FIPS 203) for encryption — to protect your credentials against both current and future threats.


2. The Zero-Knowledge Guarantee

Your credentials are encrypted on your device before they ever leave it. Specifically:

Your private key never leaves your device. The Dilithium2 (ML-DSA-44) signing key is generated locally and stored in chrome.storage.local. It is never transmitted to our servers under any circumstances.We cannot read your passwords. Credentials are encrypted with AES-256-GCM using keys derived from your public key fingerprint via HKDF-SHA256. We store only the ciphertext. We have no technical means to decrypt it.Authentication is zero-knowledge. We authenticate you by verifying a Dilithium2 digital signature against a stored public key. No password, passphrase, or shared secret is transmitted during authentication.No plaintext credentials are ever stored on our servers. Vault data is encrypted at rest in Amazon DynamoDB. Encryption keys exist solely under your control.


3. Information We Collect

3.1 Information You Provide

  • Email address — Account identity and authentication — stored on our servers

  • Dilithium2 public key — Signature verification — stored on our servers

  • Encrypted credential ciphertext — Vault storage — stored encrypted on our servers

  • Vault names — Vault organization — stored on our servers

3.2 Information Collected Automatically

  • Domain name of authenticated site — Credential association — Yes, as vault metadata

  • Authentication timestamp — Audit log — Yes, 90-day retention

  • IP address — Security monitoring and Trust Engine risk evaluation — Yes, 90-day retention

  • Browser user agent — Device identification for Trust Engine — Yes, 90-day retention

  • Authentication success/failure — Security audit trail — Yes, 90-day retention

3.3 What We Do Not Collect

  • Plaintext passwords or credentials — ever

  • Full browsing history

  • Page content or form data beyond the domain name

  • Your Dilithium2 private key

  • Payment card numbers (processed by our payment provider)

  • Biometric data

3.4 Chrome Extension Specific

The QuantPass browser extension requests the following Chrome permissions:

  • storage — Store your Dilithium2 keypair locally in chrome.storage.local

  • activeTab — Detect login forms on the current page for autofill

  • scripting — Inject credentials into detected form fields

  • identity — Authenticate with your QuantPass account

  • alarms — Schedule session expiry and key rotation checks

The extension does not read page content beyond detecting the presence of login form fields. It does not track your browsing activity across sites.


4. How We Use Your Information

We use the information we collect to:

Provide the Services. Authenticate you, store and retrieve encrypted credentials, and autofill login forms.Operate the AI Trust Engine. Evaluate authentication risk using IP address, user agent, timestamp, and historical patterns to detect anomalous access. Risk scores are stored for 90 days and never shared with third parties.Maintain security. Monitor for unauthorized access attempts, enforce session policies, and generate audit logs for enterprise compliance.Improve the Services. Analyze aggregate, anonymized usage patterns to improve performance and features. We do not use individual credential data for this purpose.Comply with legal obligations. Respond to lawful requests from law enforcement or regulatory authorities where required.

We do not sell your personal information to third parties. We do not use your data for advertising.


5. How We Share Your Information

We share your information only in the following circumstances:

Service providers. We use Amazon Web Services (AWS) to host our infrastructure, including DynamoDB (encrypted vault storage), Cognito (identity), and CloudWatch (audit logging). These providers process data on our behalf under data processing agreements.

Enterprise administrators. If you use QuantPass through an enterprise account, your organization's administrator can view audit log metadata (timestamps, domains accessed, risk scores) but cannot access your encrypted credential content.

Legal requirements. We may disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of QuantPass, our users, or the public.

Business transfers. In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred. We will notify you of any such change and any new privacy terms.

We do not share your information with data brokers, advertisers, or analytics companies.


6. Data Retention

Data typeRetention periodAccount information (email, public key)Until account deletionEncrypted vault credentialsUntil deleted by you or account deletionAuthentication audit logs90 daysTrust Engine events90 daysIP addresses90 daysSupport communications3 years

You can delete your account and all associated data at any time from the QuantPass admin dashboard.


7. Data Security

We implement the following technical and organizational security measures:

Encryption in transit: TLS 1.3 for all communications between your device and our servers.

Encryption at rest: AES-256-GCM for all vault data stored in DynamoDB.

Post-quantum cryptography: ML-KEM-1024 (FIPS 203) for key encapsulation and ML-DSA-44 (FIPS 204) for authentication signatures.

Zero-knowledge architecture: Private keys never transmitted; credentials never stored in plaintext.Access controls: Role-based access controls (RBAC) limit internal access to production systems. All internal access is logged.

Audit logging: Tamper-evident audit logs for all authentication and vault access events.

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at security@quantcert.ai.


8. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

Access: Request a copy of the personal information we hold about you.

Correction: Request that we correct inaccurate information.

Deletion: Request deletion of your account and all associated data.

Portability: Request an export of your encrypted vault data.

Restriction: Request that we limit how we use your information.

Objection: Object to our processing of your information for certain purposes.

To exercise any of these rights, contact us at privacy@quantcert.ai. We will respond within 30 days.

California residents (CCPA/CPRA): You have the right to know what personal information we collect, to delete it, to opt out of its sale (we do not sell personal information), and to non-discrimination for exercising your rights.

European residents (GDPR): Our legal bases for processing your personal information are: performance of contract (providing the Services), legitimate interests (security monitoring, fraud prevention), and legal obligation (compliance with applicable law). You have the right to lodge a complaint with your local data protection authority.


9. Children's Privacy

The QuantPass Services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you believe we have collected such information, contact us at privacy@quantcert.ai.


10. International Data Transfers

QuantPass is operated from the United States. Our servers are located in AWS us-east-2 (Ohio). If you are accessing the Services from outside the United States, your information will be transferred to and processed in the United States. We apply appropriate safeguards for such transfers in accordance with applicable law.


11. Third-Party Links

The QuantPass extension detects login forms on third-party websites. We do not control those websites and are not responsible for their privacy practices. This Privacy Policy applies only to information collected by QuantPass.


12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice in the QuantPass admin dashboard. The "Last updated" date at the top of this policy reflects the most recent revision. Continued use of the Services after changes take effect constitutes your acceptance of the revised policy.


13. Contact Us

If you have questions about this Privacy Policy or how we handle your personal information:

QuantCert, Inc. Email: privacy@quantcert.ai Security issues: security@quantcert.ai Website: https://quantcert.ai

For enterprise customers with a Data Processing Agreement (DPA), please contact your account representative.