Managed SaaS (default)
QuantumLock is consumed as a managed service:
There is nothing to install server-side. Clients install the Python package or call the REST API directly.
Key custody options (BYOC)
Even on SaaS, where your signing keys live is your choice. The KMS provider registry supports custody in the customer’s own Azure Key Vault, AWS KMS, or GCP Cloud KMS, or in a customer-provided PKCS#11 HSM — in which case SoftQuantus never holds the private key and cryptographic operations execute inside your KMS/HSM boundary. You own the cloud account and pay the cloud provider directly. See Key Management. Use the operator endpoints to validate a custody configuration before relying on it:Enterprise: on-premises and air-gapped
Per the QuantumLock security whitepaper, fully offline deployments are supported for enterprise agreements:- Delivered as an offline package (container image, keys, documentation)
- License validation via the offline SDK, with the revocation list synced at delivery time
- Local key custody, with PKCS#11 HSM optional (and required under the
defensetrust profile) - No external API calls or cloud dependency at runtime
Shared responsibility
The short version of the QuantumLock responsibility model:
Service levels (support hours, response times) are defined per plan in your agreement — this documentation does not state SLA figures.