Self-hosted post-quantum infrastructure: TLS 1.3 gateway with X25519MLKEM768, hybrid KMS (ML-KEM-768/ML-DSA-65), ML-DSA private CA. Zero dependencies, Node.js 24.
Go to file
Aere Network 2293c1da86 agents/x402: an agent wallet that pays over x402 only what the agent's ledger records and its policy allows, run on the public testnet
The agent does not hold the payment key: the wallet holds it for the owner and signs an EIP-3009 authorization only for a payment the
agent wrote into its signed ledger, verified without trusting the agent under the policy the owner pinned and against the ledger heads
the wallet itself saw (a branch is refused with a proof of equivocation, a backdated entry is refused), naming exactly this purchase,
written now, and within the limit judged also against what the wallet itself has signed. The authorization nonce is sha256(entry hash),
so the on-chain payment names the ledger entry. The policy gains an optional `wallet` field. Also: an x402 v2 client, a minimal resource
server, a local facilitator for tests, and verifica-plati.mjs, which proves from outside that a wallet's on-chain payments were allowed
by the agent's policy (with --all-transfers, that no payment left the wallet without a ledger entry).

Tests: wallet 25/25 and payment verifier 10/10 without a network (the verifier on chain responses recorded on testnet 28001), negative
control 21/21; policy 27/27, agents control 26/26. On the public testnet 28001 through its x402 facilitator: 9/9, with the evidence in
agents/x402/dovezi-28001/. Needs ethers (npm install in agents/x402).
2026-09-30 00:01:34 +03:00
agents agents/x402: an agent wallet that pays over x402 only what the agent's ledger records and its policy allows, run on the public testnet 2026-09-30 00:01:34 +03:00
control-plane Add control-plane (plan, execution with consent per action, remediation recipes and proof, compliance report, console) and readiness (the post-quantum readiness scanner of a hostname) 2026-09-29 21:21:59 +03:00
crypto-inventory Add crypto-inventory: a cryptographic inventory of source code as a CycloneDX 1.6 CBOM, with linear cost on hostile input; PKI DER messages in English 2026-09-29 17:42:36 +03:00
pq-gateway Aere Quantum: a post-quantum TLS 1.3 gateway (X25519MLKEM768, optional ML-DSA client authentication), a hybrid KMS (X25519 + ML-KEM-768, Ed25519 + ML-DSA-65; root key from the environment or sealed by an HSM through PKCS#11) and an ML-DSA private CA (X.509 v3, RFC 9881). Zero dependencies, Node.js 24 with OpenSSL 3.5. Each with its test suite and a negative control. 2026-09-29 16:24:04 +03:00
pq-kms Add crypto-inventory: a cryptographic inventory of source code as a CycloneDX 1.6 CBOM, with linear cost on hostile input; PKI DER messages in English 2026-09-29 17:42:36 +03:00
pq-pki Add crypto-inventory: a cryptographic inventory of source code as a CycloneDX 1.6 CBOM, with linear cost on hostile input; PKI DER messages in English 2026-09-29 17:42:36 +03:00
proof-kinds Add verify-layer (an audit-log sidecar whose head can be notarized on Aere Network for post-quantum finality) and proof-kinds (the AIP-23 envelope builder it uses) 2026-09-29 18:09:34 +03:00
readiness Add control-plane (plan, execution with consent per action, remediation recipes and proof, compliance report, console) and readiness (the post-quantum readiness scanner of a hostname) 2026-09-29 21:21:59 +03:00
verify-layer verify-layer: signed heads. keygen makes the operator's ML-DSA-65 head key; attest-head --sign-key signs the head statement in the form the AIP-23 reference verifier checks at its signature level (outside the statement, so the statementHash and its notarization are unchanged); verify-log --attested --signer requires the expected key, and without it says who signed and that no expected signer was compared. A signature says who vouches for the head, not when and not that the history is true. Tests 44/44 with the reference verifier (39 run and 5 skipped without it); negative control 9/9 here. 2026-09-29 22:58:20 +03:00
LICENSE Aere Quantum: a post-quantum TLS 1.3 gateway (X25519MLKEM768, optional ML-DSA client authentication), a hybrid KMS (X25519 + ML-KEM-768, Ed25519 + ML-DSA-65; root key from the environment or sealed by an HSM through PKCS#11) and an ML-DSA private CA (X.509 v3, RFC 9881). Zero dependencies, Node.js 24 with OpenSSL 3.5. Each with its test suite and a negative control. 2026-09-29 16:24:04 +03:00
README.md agents/x402: an agent wallet that pays over x402 only what the agent's ledger records and its policy allows, run on the public testnet 2026-09-30 00:01:34 +03:00

Aere Quantum

Self-hosted post-quantum infrastructure from Aere Network. Each component is a few files with no dependencies: Node.js 24 and the OpenSSL 3.5 it ships with (node:crypto), nothing from a package registry. The two exceptions need ethers: the notarization command of the verification layer, and the agents' x402 wallet (EIP-712 and secp256k1).

component what it does
pq-gateway/ a TLS 1.3 terminating proxy in front of any HTTP service, with the hybrid key exchange X25519MLKEM768: hybrid-only refuses a classical client at the handshake, hybrid-preferred keeps it working; optional client authentication with ML-DSA certificates
pq-kms/ a transit-style key management service where every key is hybrid: X25519 + ML-KEM-768 for encryption, Ed25519 + ML-DSA-65 for signatures (both halves required); versions, rotation, rewrap, data keys, a chained audit log; the root key from the environment or sealed by an HSM through PKCS#11
pq-pki/ a private certificate authority for ML-DSA (X.509 v3, RFC 9881): root and issuing CAs, leaf certificates, revocation lists, and a strict chain verifier compared against OpenSSL
crypto-inventory/ a cryptographic inventory of source code (JavaScript/TypeScript, Python, Java, Go, PEM blocks, dependency manifests): every use classified by its exposure to a quantum computer, with a migration target, written as a CycloneDX 1.6 CBOM; nothing from the scanned tree is executed, and its cost stays linear on input built to be slow
verify-layer/ an audit-log sidecar for any deployment: entries are AIP-23 envelopes in a hash chain, the runtime adapter records every running Docker or Kubernetes container without any secret value, and the head of the chain can be signed by the operator (ML-DSA-65) and notarized on Aere Network for post-quantum finality; it says plainly what that proves (the history before a published head) and what it does not (that the host told the truth)
proof-kinds/ the AIP-23 envelope builder the verification layer uses: fourteen proof kinds, one envelope format, digests instead of raw content
readiness/ the post-quantum readiness scanner of a public hostname: real TLS handshakes (hybrid only, hybrid preferred, TLS 1.2), HSTS, the certificate; no connection to an address not proven public; a rate limit per client that X-Forwarded-For cannot bypass
control-plane/ from findings to a finished migration: a prioritized plan from the inventory and the scanner, its execution through the gateway, KMS and PKI with consent per action and a measured proof afterwards, recipes for the servers the products do not touch and a rescan that judges them, a compliance report against NIST IR 8547, the EU roadmap and optionally CNSA 2.0, and a console that checks it all again
agents/ limits an AI agent cannot break unseen: a post-quantum identity (ML-DSA-65), a policy (spending per time window, allowed tools and recipients, which actions need human approval), a signed ledger of every action judged against the policy, approvals and revocation signed by people, and a verifier that re-runs the policy over the whole ledger without trusting the agent; two branches of one ledger are a proof of equivocation anyone can check; and a wallet that pays over x402 only what the agent's ledger records and its policy allows, run on the public testnet with its evidence

Each component's README says what it is not and what is not measured. No third party has reviewed any of them.

How each is checked

Every component ships its test suite and a negative control: the control plants a real defect in a copy of the code, one at a time, and requires the named test to fail for the named reason; a planting that cannot be applied, or that breaks the build instead of the test, counts as a failure of the control. Results measured on 2026-09-29 (Node.js 24.14.1, OpenSSL 3.5.5):

component tests negative control
pq-gateway 33/33 (node proba-pq-gateway.mjs) 33/33 (bash proba-pq-gateway-control-negativ.sh)
pq-kms 62/62 (node test/proba.mjs); HSM root on SoftHSM2 + OpenSC 20/20 (test/proba-hsm.mjs, Linux); sealed-file trust rules 7/7 (test/proba-hsm-incredere.mjs) 16/16 (node test/control-negativ.mjs); sealed-file rules 2/2 in this repository (test/control-negativ-hsm-incredere.mjs)
pq-pki 27/27 (node test/proba.mjs), each verdict compared with OpenSSL 3.5 22/22 (node test/control-negativ.mjs)
crypto-inventory 37/37 (node test/proba.mjs); cost on hostile input 8/8 linear (node test/proba-timp.mjs) 18/18 (node test/control-negativ.mjs); cost 3/3 in this repository (node test/control-negativ-timp.mjs; its fourth case compares with version 0.1.0 from the development history and is skipped here)
verify-layer 44/44 with the AIP-23 reference verifier (AERE_VERIFY_PROOF=<verify-proof.mjs from aere-node> node proba-sidecar.mjs); without it 39 run, 5 are reported as skipped and the exit code is 2 9/9 in this repository (node control-negativ-sidecar.mjs; its tenth case compares with the version from the development history and is skipped here)
proof-kinds 24/24 with the same verifier (AERE_VERIFY_PROOF=... node proba-proof-kinds.mjs) six negative controls inside the test
readiness 6/6 (node proba-adrese-private.mjs: the private-address rules, and a local listener no scan may touch) the rate limit and the queue bound are tested where the service runs, not here (its README says so)
control-plane planner 30/30, command line 9/9, execution 30/30 on real products started locally, remediation 33/33 on real TLS servers, compliance report 27/27 (with the AIP-23 verifier), console 8/8 remediation 7/7, compliance report 3/3 in this repository
agents policy 27/27 with the AIP-23 verifier (without it 25 run, 2 are reported as skipped and the exit code is 2), ledger 51/51, approval and revocation 39/39, command line 23/23 through files and processes only (on Linux and macOS one more test checks the key file mode; not measured here); x402 wallet 25/25 and payment verifier 10/10 without a network; on the public testnet 28001, 9/9 (x402/proba-x402-testnet.mjs, needs a funded testnet key) 26/26 (node control-negativ-aprobare.mjs); x402 21/21 (node x402/control-negativ-wallet.mjs)

Code comments, most function and variable names (also many exported between the files of a component), test names and control messages are in Romanian, and so are the two command words of the KMS HSM tool (explained in its README). Error codes, error messages, the HTTP APIs, the inventory's module interface (scan, buildCbom, renderSummary, ...), the agents' module interface, command line and data (definePolicy, verifyLedger, approve, ...) and the documentation are in English.

Licence

MIT, see LICENSE. Files: 122 (pq-gateway 6, pq-kms 10, pq-pki 6, crypto-inventory 42, verify-layer 8, proof-kinds 3, control-plane 17, agents 24, readiness 4).