Skip to main content

q-armor-proxy

The enterprise runtime of QArmor: a protection proxy that turns a silent harvest into an alert with a timestamp.

PyPI Python Licence

Prevention alone has a hole in it: if somebody copies your traffic today and decrypts it in 2032, nothing in your logs will ever say it happened. Canary tokens close that hole. They are bait that only a decrypted capture can lead anyone to, so the day one is visited you learn two things at once: that the capture existed, and roughly when it was read.

It sits in front of a validator and does three things:

  • Injects canary tokens into the traffic, to detect HNDL harvesting.
  • Blocks origins by list, at the door.
  • Fires the full alert when a canary is visited: SIEM notification, key rotation and blocking, in one path.

Run it

pip install 'q-armor-cli[proxy]'
q-armor proxy --host 0.0.0.0 --port 8080

The proxy extra pulls this package and uvicorn. It is an extra on purpose: an operator who only scans does not need FastAPI installed, and the import lives inside the command so that its absence cannot break scan or vqs.

From a checkout of the workspace:

pip install -e packages/q-armor-lib -e packages/q-armor-proxy

It does not implement cryptography

It consumes q-armor-lib, the same library the CLI and the dashboard consume. A second scanner here would be another surface producing the key_establishment_class axis and diverging in silence (see docs/layer-placement.md §8).

It stays in Python rather than TypeScript for a measured reason, not out of inertia: the proxy has no cryptographic tie of its own (it imports neither ML-KEM nor ML-DSA), but migrating it would force porting the whole of q-armor-lib and would leave three implementations of the same axis instead of two.

The QArmor family

Five packages, one version, published together from a single tag.

Package What it is
q-armor-lib Detection, scoring and the control-plane client
q-armor-cli q-armor, the operator's command line
q-armor-proxy This one: the enterprise runtime
q-armor-chain DVN worker and QArmorDVN.sol
q-armor-pqc Interim ML-DSA-65 primitive

Next

The proxy is the enterprise tier: real-time alerting, SLA and on-premise deployment. idenq.io

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

q_armor_proxy-0.1.0-cp313-none-any.whl (25.3 kB view details)

Uploaded CPython 3.13

q_armor_proxy-0.1.0-cp312-none-any.whl (25.2 kB view details)

Uploaded CPython 3.12

q_armor_proxy-0.1.0-cp311-none-any.whl (25.5 kB view details)

Uploaded CPython 3.11

File details

Details for the file q_armor_proxy-0.1.0-cp313-none-any.whl.

File metadata

  • Download URL: q_armor_proxy-0.1.0-cp313-none-any.whl
  • Upload date:
  • Size: 25.3 kB
  • Tags: CPython 3.13
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for q_armor_proxy-0.1.0-cp313-none-any.whl
Algorithm Hash digest
SHA256 58db0e41d7b8ab90460f44c77b5962cf66ff3c18fc1ede5b411f3921c9accb77
MD5 44539f7c57b92de45cf2f35f292f1c39
BLAKE2b-256 dc18f0c35b7286eee282b6b259db5446fd79fcae6f3f99b4bf321cf0a8aeff0e

See more details on using hashes here.

Provenance

The following attestation bundles were made for q_armor_proxy-0.1.0-cp313-none-any.whl:

Publisher: release.yml on iden-q/iden-q-quantum-armor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file q_armor_proxy-0.1.0-cp312-none-any.whl.

File metadata

  • Download URL: q_armor_proxy-0.1.0-cp312-none-any.whl
  • Upload date:
  • Size: 25.2 kB
  • Tags: CPython 3.12
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for q_armor_proxy-0.1.0-cp312-none-any.whl
Algorithm Hash digest
SHA256 c962a1f6911ca709d7d80714a889190ec8773f9954b95d76d817ba6a330d9d2e
MD5 18e517394d936dcd24d7cf335b2de2a2
BLAKE2b-256 2901212713ee89668597777bfdf75b4c54c96820ccb366bdf6c59c28af2224df

See more details on using hashes here.

Provenance

The following attestation bundles were made for q_armor_proxy-0.1.0-cp312-none-any.whl:

Publisher: release.yml on iden-q/iden-q-quantum-armor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file q_armor_proxy-0.1.0-cp311-none-any.whl.

File metadata

  • Download URL: q_armor_proxy-0.1.0-cp311-none-any.whl
  • Upload date:
  • Size: 25.5 kB
  • Tags: CPython 3.11
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for q_armor_proxy-0.1.0-cp311-none-any.whl
Algorithm Hash digest
SHA256 bbdb78298231d4446ea70c5586a470a8b57640311271af83653ddef01e909fee
MD5 544de078df118972c3d3594c4bd3d525
BLAKE2b-256 1728c9f4d5d17f1ddeac190deabb266098e019a1b38e1370b3d79dcee7717c9d

See more details on using hashes here.

Provenance

The following attestation bundles were made for q_armor_proxy-0.1.0-cp311-none-any.whl:

Publisher: release.yml on iden-q/iden-q-quantum-armor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.1.2

3 files

0.1.1

3 files

This release

0.1.0 This release

3 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page