Security policy, vulnerability disclosure, and bug bounty for Quantova, the post-quantum Layer 1 for institutional settlement — how to report, what's in scope, and how disclosure is coordinated.
-
Updated
May 31, 2026
Security policy, vulnerability disclosure, and bug bounty for Quantova, the post-quantum Layer 1 for institutional settlement — how to report, what's in scope, and how disclosure is coordinated.
Public REST API for the Quantova network — read on-chain state, submit signed transactions, estimate fees, and bridge across 36 blockchains and 68 assets. A single zero-dependency gateway in front of a live Quantova node.
Quantova's post-quantum security contribution to the Polkadot SDK: a NIST post-quantum signature layer (Dilithium, Falcon, SPHINCS+) and SHA3-256 brought to the Substrate/FRAME tech stack. Reference repository showing the work — to build on Quantova, use the qweb4.js and qweb4.py client libraries.
Quantova's public security archive — advisories (QSA), incident reports (QIR), and post-mortems (QPM), published after a fix is live. To report a vulnerability, use the bug bounty channels, not this repo.
Quantova governance spec — referendum classes, participation bonds, vote lock-ups, post-quantum signing, and a read-only security check for auditors.
Verification labs for Quantova consensus over the q_ JSON-RPC API — post-quantum signature checks, no-ecrecover, deterministic no-VRF slot leadership, and SHA3-256. Evidence the node behaves as specified; not a substitute for audit.
Formal specifications for Quantova's consensus — a post-quantum NPoS Layer 1 that separates block production from finality and removes quantum-vulnerable randomness.
Build and run oracles on Quantova, the post-quantum Layer 1. Guides and runnable examples for price aggregators, fee/gas feeds, supply metrics, and DEX price feeds — built on the q_ JSON-RPC API, publishing on finality.
Minimal starter template for building on Quantova — scaffold a project that reads chain state, deploys QRC20 contracts to the QVM, and sends signed transactions via the q_ JSON-RPC API. Testnet today, mainnet with a config change.
Post-quantum client library for the Quantova network — query state, subscribe, and sign/submit transactions with Dilithium, Falcon & SPHINCS+ keys, via fully-typed Promise and RxJS APIs.
Curated index of post-quantum cryptography libraries and quantum-resistant blockchain projects, maintained for the Quantova ecosystem.
A browser portal into the Quantova network — explorer, accounts, signing, staking, and governance — adapted from the Polkadot-JS apps portal and made post-quantum end to end. Connects to any Quantova node over the q_ JSON-RPC API.
Practical, rigorous checklists for building, securing, and shipping applications and infrastructure on Quantova, the post-quantum Layer 1 for institutional settlement — written to be copied straight into a pull request, launch ticket, or audit scope.
Everything required to run a validator on the Quantova network — the consensus rules you enforce, hardware and stake requirements, build and run commands, the JSON-RPC operating surface, fee and reward economics, and the slashing rules. Validators secure Quantova by staking QTOV, authoring blocks, and voting in finality.
The Quantova Grants Program, funding for open-source software and research that strengthens the post-quantum Layer-1 ecosystem. Apply by opening a pull request with the application template, or through quantova.org/grants. Grants are non-dilutive and paid in QTOV against delivered milestones.
Runnable Quantova examples in qweb4.js and qweb4.py — transfer, QVM contract call, QNS resolution, and a post-quantum governance vote. Runs against a local node or the testnet.
QMask is the native Quantova wallet — a browser extension for Chrome, Firefox, and Brave that creates quantum-resistant Quantova accounts and signs transactions with post-quantum keys (Dilithium, Falcon, SPHINCS+). It injects a post-quantum signer so any compatible dapp can request signatures from your accounts.
Quantova's post-quantum interoperability layer — proof-based bridge across 36 blockchains and 68 assets. Trustless verification via ETH sync-committee / BSC Parlia light clients, Cosmos Tendermint+ICS-23, Substrate GRANDPA, and Bitcoin SPV; Quantova side secured by Falcon/Dilithium/SPHINCS+.
Developer documentation and tutorials for Quantova, the post-quantum Layer 1 for institutional settlement — the Markdown/MDX content that powers the docs on the Quantova website.
Add a description, image, and links to the quantova topic page so that developers can more easily learn about it.
To associate your repository with the quantova topic, visit your repo's landing page and select "manage topics."