No enterprise tax. Just bulletproof quantum security for fast-moving teams. See Plans →
Get Help
For questions, bug reports, or feature requests, contact us at:
Email: support@quantcert.ai
Response time: Within 1 business day
QuantPass is a post-quantum password manager and identity platform. It detects login forms automatically, generates strong passwords on signup forms, and authenticates you using NIST-standardized post-quantum cryptography (ML-DSA-44 / Dilithium2) — so your credentials stay protected even against future quantum computing threats.
Classical encryption (RSA, ECDSA) — the foundation almost every password manager relies on today — will eventually be breakable by a sufficiently powerful quantum computer. Researchers call this the "harvest now, decrypt later" threat: adversaries can steal encrypted data today and hold it until quantum computers are powerful enough to break it. QuantPass uses the cryptographic standards NIST finalized in 2024 specifically to resist this future.
QuantPass requests access to all websites because it needs to detect login forms wherever you browse — the same scope every password manager requires. Specifically:
All websites: To detect login and signup forms and offer to autofill or save your credentials, regardless of which site you're visiting.
Storage: To store your encrypted identity keys and extension settings locally on your device.
Active tab: For popup-initiated actions when you click the extension icon.
Alarms: For background session housekeeping, compatible with Chrome's MV3 service worker lifecycle.
QuantPass never reads page content beyond detecting form fields. Your passwords are encrypted on your device before they ever reach our servers.
Yes. QuantPass uses a zero-knowledge architecture:
Your encryption keys are generated on your device and never transmitted.
Vault data is encrypted client-side before reaching our servers.
QuantPass's servers never see your passwords in plaintext.
QuantPass works on any site with a login or signup form. It has been tested on GitHub, GitLab, Google, AWS, and Okta, among others. If you encounter a site where the bar doesn't appear or autofill doesn't work correctly, contact support with the site URL.
QuantPass includes phishing domain detection. It warns you before you enter credentials on domains that show signs of typosquatting (e.g. g00gle.com), homograph attacks (international characters that mimic trusted domains), bare IP addresses, or suspicious top-level domains combined with brand keywords. You can dismiss the warning and continue if you're confident the site is legitimate.
Navigate to the site's login page. When the QuantPass bar appears at the top of the page, type your username into the login form — the bar will update to show a registration prompt. Click the bar to generate a quantum-safe identity for that site. After registration, QuantPass will authenticate you automatically on future visits.
After registering a quantum identity, open the QuantPass extension popup, go to the Vault tab, and click "Enable FIDO2 protection" on the identity card for that site. You'll be prompted to register a fingerprint, face scan, or security key. Once enabled, QuantPass will require a hardware verification step before signing you in — providing an additional layer of protection even if your device is compromised.
Open the QuantPass popup, go to the Vault tab, and click "Forget this site" on the affected identity. This removes both the local identity and the server-side credential, letting you register fresh. For a full reset, use "Lock & Clear All Identities."
