iPhone users: save your wallet keys before the next update
PQC Wallet for iPhone has moved to our company's new Apple developer account. The next iPhone update can't read the keys saved by earlier versions, so you'll need a copy of each wallet's keys to keep using it. Android isn't affected.
Before you update: In PQC Wallet, open the Wallet tab and, for each wallet, tap the wallet → "Export private key" → "Show key". Copy the private key, and for post-quantum wallets the public key too, and keep them offline and private. If automatic updates are on, do this today.
After the update: First remove the old entry: open the wallet → "Archive wallet", then Settings → "Archived Wallets" → "Delete". Then tap "New wallet" → "Import a wallet" and paste the keys. Before your next signature you'll also sign in again and re-verify your ID.
We will never ask for your private keys or recovery phrase.
ML-DSA-44 · FIPS 204
Electronic signatures today rest on RSA and ECDSA. A large enough quantum computer breaks both — and the contract you are signing may need to hold up for longer than that takes. We sign with ML-DSA-44, the NIST post-quantum standard.
By continuing you accept the Terms of Service. How we handle your data is explained in the Privacy Policy and, for users in Türkiye, in our KVKK Notice.
A lease runs five years, a title deed a lifetime, a patent twenty. A signature has to prove itself not on the day it is made but on the day it is disputed. Today's signature has to survive until then.
RSA-2048 and ECDSA are everywhere, fast, and secure right now.
A quantum computer running Shor's algorithm breaks both. When is unknown. That it happens is not.
Lattice-based signatures. ML-DSA-44 rests on a hardness no known quantum algorithm defeats.
You do not name the signatories in advance. The document carries a code; whoever reads it signs, and you decide what to accept.
Hold your phone against your ID card or passport. The app reads the chip, checks the issuing state's signature, and compares the portrait against your face. A separate key, used only for signing, is created at that moment.
A code appears on the document. Anyone in the room can scan it, and anyone who is not can be invited by national ID number.
Whoever scans the code reads the document on their own phone before signing. Signatories appear on the list as they sign, not before.
Every signature comes to you for a decision. The document completes with the ones you accept, and the signed PDF is produced.
What survives the process is a PDF. It has to be verifiable on its own even if this platform is gone, and it was built that way.
Who signed is printed at the foot of every page, not only the last one. Someone holding page four does not have to go looking to find out whose document it is.
The address printed on the document is fixed. Years later, someone holding the printout can scan it and check the signatures.
The document's hash is recorded on SciChain. Change one character and the hash no longer matches, and every signature fails.
The key used for signing is separate from your wallet and is created at the moment your identity is verified. It cannot be exported and cannot be imported — the app offers no way to do either. The server sees only the public half. The one thing that can produce your signature is that key, on that phone.
The key is used only after a biometric check.
These signatures are not a "güvenli elektronik imza" under Turkish law 5070. That requires a qualified certificate from a licensed provider, and the regulator's algorithm list does not yet include ML-DSA. Cryptographic strength is not a substitute for it.
What we do is put a signature built to withstand quantum computers alongside the one the law recognises today. If you hold a qualified certificate, both can be used together: one for the courtroom, one for the archive.
Identity verification takes a few minutes and is done once.
By continuing you accept the Terms of Service. How we handle your data is explained in the Privacy Policy and, for users in Türkiye, in our KVKK Notice.
Cookies
We use strictly necessary cookies to run the site and keep you signed in. With your permission we would also use Google Analytics to see how the site is used; that data goes to Google LLC (USA). It stays off unless you accept, and you can change your mind at any time. It is never used on pages that show your documents or signatures. How we use cookies · KVKK notice (Türkiye)