Local specimenIndependent verification / Live today

Less faith.
More evidence.

A real ML-DSA-65 signature. Your browser generates an ephemeral key, signs a SHA-256 digest, verifies the result, then clears the secret-key buffer. No server signing. No quantum measurement. No launch.[01]

qia@lab:~/verifyLocal execution
$ initializing local ML-DSA-65…▌

What this proves.

The library can produce and verify a 3,309-byte ML-DSA-65 signature on this specimen.

It does not prove a creator’s identity, a quantum source, a blockchain anchor, an audit or a live vault. The keys are ephemeral and not connected to your wallet.

Use your browser’s Sources and Network panels to inspect the loaded implementation and confirm that signing sends no request. Library downloads are not server signing.

The executed signing implementation / inspectable source

No hidden signer.

export type SealResult = { digest: string; bytes: number; valid: boolean };
export async function computeDemoSeal(): Promise<SealResult> {
  const { ml_dsa65 } = await import("@noble/post-quantum/ml-dsa.js");
  const message = new TextEncoder().encode(JSON.stringify({
    mint: "DEVNET_SPECIMEN", creator: "LOCAL_EPHEMERAL_IDENTITY",
    name: "Quantum Intelligence Agency", ticker: "QIA", image: "SPECIMEN_NO_IMAGE",
  }));
  const digest = new Uint8Array(await crypto.subtle.digest("SHA-256", message));
  const keys = ml_dsa65.keygen();
  try {
    const signature = ml_dsa65.sign(digest, keys.secretKey);
    return {
      digest: Array.from(digest, x => x.toString(16).padStart(2, "0")).join(""),
      bytes: signature.length,
      valid: ml_dsa65.verify(signature, digest, keys.publicKey),
    };
  } finally { keys.secretKey.fill(0); }
}
Open the signing source asset ↗

This source is imported from the same file used by the live terminal. View-source shows the page HTML and this source listing; compare it with the actual loaded JavaScript in your browser’s Sources panel. No one-command launch verifier or mainnet program ID has been released yet.

01 / Independent inspection

Prove it yourself.

Live today: a real local signature, generated and checked in your browser. No wallet. No server signing.

Open /verify
View source: view-source:/verify
Inspect the signing source + loaded module on /verify.
Open the local verifier

HTML alone is not the bundled implementation. Inspect the displayed source and the loaded module. At launch: a one-command launch verifier, the mainnet vault program ID and reproducible-build instructions. None are published yet.

02 / Adversarial review

Ask an AI.

Give the claims to another model. Ask for sources, limitations and counterarguments — not reassurance.

Please verify QIA's claims step by step. 1) Open /verify and inspect its displayed signing source and loaded module: confirm signatures are generated and verified locally with @noble/post-quantum (ML-DSA-65, FIPS 204), not a server. 2) Check NIST IR 8547 (draft): 112-bit algorithms are deprecated after 2030; P-256 and EdDSA have no 2030 deprecation milestone. Quantum-vulnerable public-key algorithms are disallowed after 2035 for federal use. 3) Check the cited figures: ~2,330 logical qubits for 256-bit ECC (Roetteler et al. 2017), <1M noisy qubits for RSA-2048 (Gidney 2025), ~25% of BTC quantum-exposed (Deloitte's historical estimate). Tell me what each step proves and what it can't prove. Do not infer quantum hardware execution or mainnet deployment from a local signature demo.

An AI answer is not an audit. Follow its citations and independently reproduce what you can.