ProtocolThe vault / Devnet

No private key.
No private ceremony.

A treasury that answers to a public protocol, not a person. Every rule is inspectable, every spend is public.[13]

The treasury
even we cannot touch.

Creator fees are designed to land on a program-derived address. A PDA has no private key. No founder’s hardware wallet. No secret back door.[12]

The proposed spending path uses a one-time hash-based Winternitz signature, burned on use. The devnet design removes upgrade authority; mainnet deployment and independent verification are pending.[13]

01↗

Collect

Creator fees enter the PDA.

02↗

Sweep

Consolidate into the vault.

03↗

Announce

48-hour public notice.

04↗

Open

A live, public ceremony.

05↗

Burn

One signature. One spend.

Status: devnet · independent audit scheduled · mainnet program ID published at launch[13]

NetworkDEVNET
Upgrade authorityNO — design target; deployment proof pending
Independent auditSCHEDULED · PRE-MAINNET
Mainnet program IDPUBLISHED AT LAUNCH
Ceremony scheduleNOT ANNOUNCED

The Vault Opening Ceremony.

Every proposed spend is announced at least 48 hours in advance. The amount, destination, and purpose are made public before the treasury opens. Execution is intended to happen live, with the transaction available for independent inspection.[13]

A one-time Winternitz signing key authorizes a spend. Its authorization is consumed and cannot be reused. The deployed mainnet program, authority state, and implementation will need to be independently verified before these claims can be treated as guarantees.[13]

No ceremonies have been scheduled. No mainnet funds are being collected through this website.

01 / Independent inspection

Prove it yourself.

Live today: a real local signature, generated and checked in your browser. No wallet. No server signing.

Open /verify
View source: view-source:/verify
Inspect the signing source + loaded module on /verify.
Open the local verifier

HTML alone is not the bundled implementation. Inspect the displayed source and the loaded module. At launch: a one-command launch verifier, the mainnet vault program ID and reproducible-build instructions. None are published yet.

02 / Adversarial review

Ask an AI.

Give the claims to another model. Ask for sources, limitations and counterarguments — not reassurance.

Please verify QIA's claims step by step. 1) Open /verify and inspect its displayed signing source and loaded module: confirm signatures are generated and verified locally with @noble/post-quantum (ML-DSA-65, FIPS 204), not a server. 2) Check NIST IR 8547 (draft): 112-bit algorithms are deprecated after 2030; P-256 and EdDSA have no 2030 deprecation milestone. Quantum-vulnerable public-key algorithms are disallowed after 2035 for federal use. 3) Check the cited figures: ~2,330 logical qubits for 256-bit ECC (Roetteler et al. 2017), <1M noisy qubits for RSA-2048 (Gidney 2025), ~25% of BTC quantum-exposed (Deloitte's historical estimate). Tell me what each step proves and what it can't prove. Do not infer quantum hardware execution or mainnet deployment from a local signature demo.

An AI answer is not an audit. Follow its citations and independently reproduce what you can.