RANNTA PQ Cloud — Security Report Release: RANNTA-PQ-CLOUD-PHASE2-20260911-01 Evidence date: 2026-09-11 UTC Security model - Algorithm: ML-DSA-65 (NIST FIPS 204) - Policy mode: HybridRequired - Failure mode: fail-closed - PQ private-key custody: customer-side - RANNTA role: verify canonical payload, registered public key, ML-DSA-65 evidence and policy - Customer role: classical authorization and final business decision Crypto / policy evidence - Unit/integration tests: 11 passed, 0 failed - Runtime used for core tests: Rust 1.98.1, OpenSSL 3.5.7 - ML-DSA-65 public key size observed: 1952 bytes - ML-DSA-65 signature size observed: 3309 bytes Production end-to-end evidence - Customer-side TypeScript SDK build: PASS - Customer-side ML-DSA-65 valid verification: PASS - Local one-byte mutation rejection: PASS - Public-key registration: PASS - HybridRequired policy activation: PASS - Production HybridRequired valid request: PASS - Production replay rejection: PASS - Production one-byte mutation rejection: PASS - Production classical_verified=false rejection: PASS - Verification usage metering: PASS - Hybrid verification audit logging: PASS Production /v1/hybrid/verify benchmark - Valid signed requests: 100/100 successful - Average: 663.34 ms - p50: 619.28 ms - p95: 777.14 ms - p99: 1067.85 ms - Method: sequential HTTPS requests from operator Windows client using curl --resolve against pq.rannta.com Public health sample - Public health requests: 100/100 successful - Average health latency: 639.12 ms - p50 health latency: 614.96 ms - p95 health latency: 757.43 ms - p99 health latency: 1202.69 ms Evidence identity - Release build ID: RANNTA-PQ-CLOUD-PHASE2-20260911-01 - Build ID endpoint: https://pq.rannta.com/build-id.txt - Final E2E test harness source commit: 0ddce50395b6b9ffd6e03d4aa882e1fe50d5d4b4 - Customer-side cross-check implementation: @noble/post-quantum 0.7.1 Published evidence - https://pq.rannta.com/docs/operator-self-test - https://pq.rannta.com/docs/canonical-payload - https://pq.rannta.com/docs/independent-verify - https://pq.rannta.com/docs/acvp - https://pq.rannta.com/docs/threat-model - https://pq.rannta.com/status - https://pq.rannta.com/docs/integration-examples - https://pq.rannta.com/build-id.txt