Qira Encryption Vault — Product preview v0.29

Seal work evidence.
Open it only with your keys.

QEV packages job records, messages, and handoffs into encrypted files with signed proof anyone can check. Start free in the browser in under a minute — or pilot a gateway your team controls.

No account required for the vault. Your phrase and plaintext stay on your device for the browser path.

Standard AEAD encryption
Signed packages you can re-verify
Customer-held keys
This site is integrity-signed
Team gateway in pilot
Get started
Three clear ways to use QEV
Pick the path that matches what you need. You do not need to understand the full stack to start.
1
Free · ready now

Send or store one secret

Type a message, choose a phrase, download an encrypted vault file. Send the file one way and the phrase another. No account, no server sees the plaintext.

  • Browser vault — works offline after load
  • Desktop apps for Mac / Windows
  • CLI for scripts and CI
Open browser vault Download apps
3
Reviewers · free

Verify trust yourself

Check that this site was not swapped after signing, inspect the public challenge bundle, and read what we claim — and what we do not.

  • Site integrity record
  • Public decryption challenge
  • Trust program & audit status
Verify this site Trust program
Product
What you get with QEV
One product family: portable vault files first; optional capture and verification for teams.
Core

Encrypted vault packages

Portable Vault V2 files. Phrase-based unlock. Built on standard authenticated encryption — not a custom cipher.

Vault format
Proof

Signed evidence bundles

Export a package with hashes and signatures so a third party can check integrity and authenticity without trusting your UI.

Evidence bundle
Teams

Capture gateway

Customer-controlled service that seals selected workflow events via API, SDK, or connectors. Pilot, not enterprise-certified.

Gateway docs
Integrate

SDK & CLI

Call capture from your app, or seal/verify from the command line in automation.

JS SDK CLI / apps
Honesty

Trust marks that mean something

Badges link to scoped certificates — never “this whole company is secure.” Preview status is stated up front.

Trust program
Site safety

This marketing site is signed

Every protected page is hashed and the manifest is Ed25519-signed. If the page bytes change after signing, you get a red warning.

How verification works
How it works
From plaintext to proof in four steps
Same idea for a one-off secret or a team workflow — only the capture step changes.
Step 01

Capture

You type a secret, or your systems send a workflow event (job done, photo, change order).

Step 02

Seal

QEV encrypts the content into a portable package. Keys stay with you — not with a QEV cloud that can read plaintext.

Step 03

Share or store

Send the file through normal channels. For team pilots, packages land in your controlled gateway storage.

Step 04

Verify

Open with the phrase or keys. Export a signed bundle when someone else must independently check that nothing was swapped.

Who it's for
Built for people who must prove what happened
Not a general chat app. Not a new cipher. A product for sealed records and checkable proof.
Operations

Field & service teams

Estimates, approvals, job photos, and completion records that need to stay intact for disputes or handoffs.

Field service evidence →
Security

Reviewers & auditors

Independent verification, public challenge, and an explicit list of what is hardened vs still limited.

Security posture →
Engineering

Builders integrating capture

SDK, gateway API, and connectors so evidence sealing is part of the workflow — not a manual afterthought.

Documentation →
See it
Watch it verify. Then watch it refuse.
Both clips are the real verifier run against this site, recorded from actual output — nothing re-enacted or typed for the camera. The second one matters more: a checker that never fails is not a checker.
Signature valid, 78/78 files match. It ends on what the check does not prove — that the key belongs to who you think, that the code is bug-free, that we are trustworthy. Run it yourself: /verify.
One hex character changed in one digest — and it fails. The signature check refuses, and it will not go on to hash files against a manifest it could not authenticate. Exit code 3.

No audio, no narration, no third-party player — these load from this server like everything else here. Prefer text? The same output is on /verify, and the verifier is in the public repository.

Security posture
What is solid today — and what is not
We document limits in public. That is part of the product.

Ready for evaluation

  • DoneStandard AEAD (ChaCha family) — not a home-rolled cipher
  • DonePortable vault packages with integrity binding
  • DoneSigned bundle verification with explicit trust verdicts
  • DoneThis site signed end-to-end (Ed25519 + per-file SHA-256)
  • DoneMultiple internal adversarial hardening passes

Not claimed yet

  • OpenNo formal third-party security audit
  • OpenNo KMS / HSM integration
  • OpenNo enterprise multi-tenant hardening
  • OpenNo formal key rotation / revocation product
  • OpenTeam gateway is pilot-grade, not certified

Trust program · Audit status · Threat model · Status & tests

FAQ
Common questions
What should I do first?
If you need a one-off sealed message: open the browser vault. If your team needs automated capture: request a pilot. If you are reviewing security: start at /verify.
Is this a new cryptographic algorithm?
No. QEV uses standard authenticated encryption. The product is packaging, verification semantics, and optional workflow capture — not a novel cipher.
Do I need an account?
No account for the free browser vault, desktop apps, or CLI. Team pilot uses your gateway and your access control — we are not a required cloud that holds your plaintext.
Is QEV ready for full production enterprise use?
It is a controlled-use product preview. Vault tools are usable today for evaluation and controlled workflows. The capture gateway is pilot. There is no third-party audit certificate yet. See Trust and Pricing.
What does verification actually prove?
For packages: file integrity (hashes match), signature validity, and metadata consistency — reported as separate checks, not a vague “secure” badge. For this website: every signed page’s bytes must match the Ed25519-signed manifest or you see a tamper warning.
How do I contact sales or security?
Email bryanleonard@imagineqira.com. Use subject “Team Pilot” or “Security Review” so we route it correctly. Or use /contact.
Optional · for crypto reviewers
Public decryption challenge
Not required to use the product. Posted so specialists can attack a real signed bundle on their own terms.

A real encrypted bundle is live on this site. Verify the manifest with standard tools. Master-key reveal follows a published commit-reveal schedule so plaintext cannot be swapped after the fact.

See the challenge Download bundle Site integrity
Loading challenge metadata…

Ready to use QEV?

Start free in the browser, download desktop tools, or talk to us about a team pilot.