Pricing
Product subscription for QNSQY, the post-quantum cryptography tool (CLI, GUI, TUI, MCP). Database migration, cold storage PQC, migration-as-a-service, and readiness assessments are priced as separate engagements. ML-KEM-512 + ML-DSA-44 data protection is always free and unlimited.
For context: the incumbent route to post-quantum migration is an enterprise platform or consulting engagement, quoted by a sales team. QNSQY is self-serve at a published price because the cryptography runs on your machine, not on consultants' timesheets. And because the deliverable matters more than the feature list: see a real sample of the migration evidence before you spend anything.
- Real NIST-standardized post-quantum encryption, free forever: unlimited use, no data-size limit (ML-KEM-512 + ML-DSA-44, 0 credits)
- Default algorithms are always free with no file size limit on every tier. Same encryption engine as Pro and Business.
- AES-256-GCM (NIST SP 800-38D approved) + XChaCha20-Poly1305 (IETF RFC 8439 extended-nonce, widely deployed) AEAD, all tiers
- Argon2id (128 MB, 3 iterations)
- BLAKE3 integrity verification
- 100 MB per file limit (applies only to higher-tier algorithms like ML-KEM-768/1024)
- Encrypt / Decrypt / Shred / Hash / Sign / Verify
- Decrypt, Verify, Hash, Keygen always free on all tiers
- GUI + CLI + TUI + MCP server (84 tools) included
- Linux x86_64 (glibc 2.35+) and Windows 10/11 (macOS soon)
- $0.05/credit pay-as-you-go for advanced algorithms
- Everything in Free, plus:
- ML-KEM-512/768 + ML-DSA-44/65: unlimited, 0 credits, no file limit
- 1,200 credits/month for ML-KEM-1024, ML-DSA-87, SLH-DSA (50% rollover, max 1,800)
- ML-KEM-768/1024 + X25519 (NIST Level 3/5)
- ML-DSA-44/65/87 signatures (FIPS 204)
- SLH-DSA hash-based signatures (FIPS 205)
- Hybrid signatures (ML-DSA + Ed25519)
- 25 GB per file (advanced algorithms)
- Batch operations
- Password change (rekey)
- Password vault (encrypted manager)
- Audit logging (hash chain)
- Custom Argon2 parameters (up to 256 MB)
- Key import/export
- R74 advanced (Pro & Business):
- Triple-polyglot (JPEG + ZIP + PDF in one artefact)
- Self-extracting polyglot (.sh / .bat re-execs qnsqy)
- Tripwire URL (canary token in PNG carrier)
- Keyfile-from-any-file (BLAKE3 derived AES key)
- ABE: Attribute-Based Encryption, policy expressions, PQC-safe
- $0.05/credit pay-as-you-go after 1,200
- Everything in Pro, plus:
- Unlimited credits/month
- All R74 advanced (triple-polyglot, self-extracting, tripwire URL, keyfile-from-any-file, ABE)
- FN-DSA-512/1024 (FIPS 206 (draft) Falcon)
- FN-DSA + Ed25519 hybrid signatures
- HQC-128/192/256 + X25519 (code-based KEM)
- Pure KEM mode (no classical hybrid)
- LMS stateful signatures (SP 800-208)
- M-of-N threshold encryption
- Shamir secret sharing (split/combine)
- Time-lock encryption
- Steganography
- Deniable encryption
- Polyglot files (dual-format carrier + payload)
- PQ Migration Scanner + migration tools
- Recipient groups & encryption policy
- Key escrow & recovery
- SIEM export (CEF/JSON/Syslog)
- Custom Argon2 parameters (up to 512 MB)
- No per-file size limit
- Custom company watermark
- Priority support (24h response)
- Compliance documentation package on request (control mapping, algorithm usage, data flow). QNSQY itself is not FIPS-validated or SOC 2-certified.
- Services (scoped, quoted separately):
- PQC readiness assessment
- Database migration to PQC
- Cold storage PQC migration
- Migration-as-a-Service (MaaS)
- Implementation support
- Everything in Business, plus:
- Custom seat counts with volume pricing
- Air-gapped license mode (v7.3 roadmap)
- HSM integration (v7.3 roadmap)
- Team workspace + RBAC (v7.3 roadmap)
- Signed SLA: business hours response (standard)
- Premium SLA: 24/7, 4-hour response available
- Dedicated Slack / email channel
- Quarterly 4-hour readiness consult included
- White-glove onboarding
- Named customer success contact
- Honest note: Enterprise maps to the Business cryptographic tier at runtime. The difference is contract, SLA, onboarding, and the air-gap/HSM roadmap features. QNSQY is not FIPS-validated, not SOC 2-certified, not FedRAMP-ATO today.
Professional Services
QNSQY is the product (CLI, GUI, TUI, MCP server). Around it we offer scoped engagements for organizations that need help migrating off classical cryptography. Each service is quoted separately from the product subscription.
- PQC readiness assessment: Inventory of your classical cryptography (RSA, ECDH, ECDSA) across applications, databases, backups, and cold storage. Risk-ranked migration plan aligned to NIST FIPS 203/204/205 and SP 800-208.
- Database migration to PQC: Re-encrypt columns, tablespaces, backups, and replication streams with hybrid PQC. Zero data loss commitment, rollback plan, and verification against your existing application layer.
- Cold storage PQC migration: Batch re-encrypt long-retention archives (tape, object storage, air-gapped vaults) with ML-KEM hybrid. Intended for records with 10+ year confidentiality requirements that are most exposed to harvest-now-decrypt-later.
- Migration-as-a-Service (MaaS): Ongoing migration operations with defined SLAs. Scans, migrations, verification, and reporting run on your schedule, with audit artifacts handed back to your compliance team.
- Implementation support: Deployment, integration with KMS, HSM, SSO, and SIEM, and engineer-to-engineer help for Business-tier customers.
None of these services create an attestation or certification. They produce working PQC coverage of your data, and artifacts your own auditor can review.
Complete Feature Comparison
| Feature | Free | Pro | Business |
|---|---|---|---|
| Usage & Limits | |||
| Credits/month | 0 (ML-KEM-512 + ML-DSA-44 unlimited) | 1,200 | Unlimited |
| PAYG after credits | $0.05/credit | $0.05/credit | N/A (unlimited) |
| Max per-file size | 100 MB | 25 GB | Unlimited |
| Core Encryption | |||
| Encrypt & Decrypt | |||
| Compression (zstd) | |||
| Secure file deletion | |||
| GUI + CLI | |||
| Network blocking (Linux CLI)* | |||
| Works offline** | |||
|
* Kernel-level network blocking via seccomp-bpf is Linux CLI only. Windows/macOS: manually disconnect from network for air-gapped security. ** Operations require a brief server check-in for subscription validation before the seccomp sandbox activates. Works offline for up to 7 days with cached subscription. |
|||
| KEM Algorithms (Encryption) | |||
| ML-KEM + X25519 hybrid (FIPS 203) | ML-KEM-512 | ML-KEM-512/768/1024 | ML-KEM-512/768/1024 |
| HQC + X25519 hybrid (code-based KEM) | HQC-128/192/256 | ||
| Pure KEM mode (no classical hybrid) | |||
| Signature Algorithms | |||
| ML-DSA (FIPS 204) | ML-DSA-44 | ML-DSA-44/65/87 | ML-DSA-44/65/87 |
| SLH-DSA (FIPS 205) | |||
| Hybrid signatures (ML-DSA + Ed25519) | |||
| FN-DSA (Falcon) - FIPS 206 (draft) | FN-DSA-512/1024 | ||
| FN-DSA + Ed25519 hybrid | |||
| LMS stateful signatures (SP 800-208) | |||
| Symmetric & KDF | |||
| AES-256-GCM | |||
| XChaCha20-Poly1305 | |||
| Password strength (Argon2id) | 128 MB, 3 iter | Up to 256 MB (customizable) | Up to 512 MB (customizable) |
| Integrity verification (BLAKE3) | |||
| M-of-N secret sharing (Shamir) | |||
| Capabilities | |||
| Batch operations | |||
| Memory protection | |||
| Audit logging | Hash chain | Hash chain | |
| Password change (rekey) | |||
| Password vault | |||
| Key import/export | |||
| Time-lock encryption | |||
| Steganography | |||
| Deniable encryption | |||
| Polyglot files | |||
| R74 Advanced (Pro & Business) | |||
| Triple-polyglot (JPEG + ZIP + PDF) | |||
| Self-extracting polyglot (.sh / .bat) | |||
| Tripwire URL (canary in PNG) | |||
| Keyfile-from-any-file (BLAKE3) | |||
| ABE (Attribute-Based Encryption, PQC-safe) | |||
| Capabilities (continued) | |||
| Threshold encryption (M-of-N) | |||
| PQ Migration Scanner + tools | |||
| Recipient groups & encryption policy | |||
| Key escrow & recovery | |||
| SIEM export (CEF/JSON/Syslog) | |||
| BLAKE3/SHA3 hashing | |||
| Base64 encode/decode | |||
| Support & License | |||
| Personal use | |||
| Commercial use | |||
| License type | Individual | Subscription | Subscription |
| Custom company watermark | |||
| Email support | 24h response | ||
| Compliance documentation package | On request | ||
| Services | |||
| PQC readiness assessments | |||
| Implementation support | |||
API Plans (Developers)
Building PQC encryption into your product? Our API plans offer higher credit allocations and lower overage rates for automated/scripted operations. All plans (App and API) use the same credit system: ML-KEM-512 + ML-DSA-44 operations are always free.
| Plan | Price | Credits/month | Overage |
|---|---|---|---|
| Starter | $29/mo | 10,000 | $0.005/credit |
| Growth | $99/mo | 100,000 | $0.003/credit |
| Scale | $499/mo | 1,000,000 | $0.001/credit |
Credit formula: max(1, ceil(file_size / 1 GB)) for credit-costing algorithms only. ML-KEM-512 + ML-DSA-44 are always free on all tiers. Pro adds ML-KEM-768 + ML-DSA-65 as free. Business: everything unlimited. Decrypt, verify, hash, and keygen are always free.
Pricing Questions
Business Solutions
Need to deploy QNSQY across your organization? Our Business tier is designed for teams of all sizes with flexible options.
Shared credit pool coming Q4 2026. Currently each team member requires their own subscription.
- Unlimited usage: No per-operation limits. Encrypt as much as you need.
- No size cap: Encrypt data of any size. No cap.
- Full algorithm access: Every supported PQC family including FN-DSA (FIPS 206 draft), HQC (NIST-selected), and LMS (SP 800-208).
- Advanced features: Threshold encryption, key escrow, SIEM export, migration tools, and more.
- Custom company watermark: Binaries branded with your organization's unique identifier for tracking and compliance.
- Priority support: 24-hour response time with dedicated account manager.
- Compliance documentation: Control mapping packages for your own auditor, covering algorithm usage, data flow, and platform configuration. QNSQY itself is not FIPS-validated, SOC 2-certified, or HIPAA-audited, and we do not sign a HIPAA Business Associate Agreement. Documentation is a starting point for your internal or third-party audit.
$149/month ($1,490/year). Self-serve; cancel anytime with a single email, no questions asked. Unlimited credits/month, every algorithm included, no per-file size limit. ML-KEM-512 always free. For custom seat counts, a signed SLA, or dedicated engineering, see the Enterprise tier.
Need a signed SLA, custom seat counts, or dedicated engineering? Contact our sales team about Enterprise:
PQC by industry
How post-quantum cryptography applies to specific regulated sectors. Each guide covers the data at risk, the relevant compliance frame, and the QNSQY configuration that fits.
Healthcare
Protected health information has a multi-decade confidentiality requirement, well past most Q-Day estimates. PQC for HIPAA-covered data.
Financial Services
Transaction integrity, long-retention records, and inter-bank messaging facing harvest-now-decrypt-later exposure.
Government & Defense
CNSA 2.0 timelines, air-gapped operation, and the cryptographic agility that classified workflows require.
Legal
Privileged communications must remain confidential indefinitely. Why classical encryption is no longer sufficient for case files.
Pharmaceuticals
Clinical trial data and unpublished research IP face decade-long exposure windows where PQC migration is now urgent.
Journalism
Source identities and unpublished material need to survive adversaries with future quantum capability and current bulk-collection programs.
Education
FERPA-protected academic records, transcripts, and disciplinary files that follow a student for life require long-horizon confidentiality.
Insurance
Liability and life policies with claim horizons spanning 30+ years are squarely in the harvest-now-decrypt-later threat model.
Start encrypting with post-quantum today
Free: ML-KEM-512 + ML-DSA-44 unlimited forever. Pro: ML-KEM-512/768 + ML-DSA-44/65 unlimited, 1,200 credits/mo for advanced. Business: everything unlimited plus professional services on request. All tiers: decrypt/verify/hash always free.