q-armor-proxy
The enterprise runtime of QArmor: a protection proxy that turns a silent harvest into an alert with a timestamp.
Prevention alone has a hole in it: if somebody copies your traffic today and decrypts it in 2032, nothing in your logs will ever say it happened. Canary tokens close that hole. They are bait that only a decrypted capture can lead anyone to, so the day one is visited you learn two things at once: that the capture existed, and roughly when it was read.
It sits in front of a validator and does three things:
- Injects canary tokens into the traffic, to detect HNDL harvesting.
- Blocks origins by list, at the door.
- Fires the full alert when a canary is visited: SIEM notification, key rotation and blocking, in one path.
Run it
pip install 'q-armor-cli[proxy]'
q-armor proxy --host 0.0.0.0 --port 8080
The proxy extra pulls this package and uvicorn. It is an extra on purpose:
an operator who only scans does not need FastAPI installed, and the import
lives inside the command so that its absence cannot break scan or vqs.
From a checkout of the workspace:
pip install -e packages/q-armor-lib -e packages/q-armor-proxy
It does not implement cryptography
It consumes q-armor-lib, the same
library the CLI and the dashboard consume. A second scanner here would be
another surface producing the key_establishment_class axis and diverging in
silence (see docs/layer-placement.md §8).
It stays in Python rather than TypeScript for a measured reason, not out of
inertia: the proxy has no cryptographic tie of its own (it imports neither
ML-KEM nor ML-DSA), but migrating it would force porting the whole of
q-armor-lib and would leave three implementations of the same axis
instead of two.
The QArmor family
Five packages, one version, published together from a single tag.
| Package | What it is |
|---|---|
q-armor-lib |
Detection, scoring and the control-plane client |
q-armor-cli |
q-armor, the operator's command line |
q-armor-proxy |
This one: the enterprise runtime |
q-armor-chain |
DVN worker and QArmorDVN.sol |
q-armor-pqc |
Interim ML-DSA-65 primitive |
Next
The proxy is the enterprise tier: real-time alerting, SLA and on-premise deployment. idenq.io
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distributions
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file q_armor_proxy-0.1.1-cp313-none-any.whl.
File metadata
- Download URL: q_armor_proxy-0.1.1-cp313-none-any.whl
- Upload date:
- Size: 25.4 kB
- Tags: CPython 3.13
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e4791b8913adf927ecaf9865b48ded40df6c0affd3111e7a9c83c9f061a60614
|
|
| MD5 |
57bd19310b6f6e9205e1a4cf6d1f21f5
|
|
| BLAKE2b-256 |
f6261a7234498d9a91b41412bf2e82fe5c78cafc00ca7a26b840d4d437ab9bf6
|
Provenance
The following attestation bundles were made for q_armor_proxy-0.1.1-cp313-none-any.whl:
Publisher:
release.yml on iden-q/iden-q-quantum-armor
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
q_armor_proxy-0.1.1-cp313-none-any.whl -
Subject digest:
e4791b8913adf927ecaf9865b48ded40df6c0affd3111e7a9c83c9f061a60614 - Sigstore transparency entry: 2704189546
- Sigstore integration time:
-
Permalink:
iden-q/iden-q-quantum-armor@281ef8e2be3426abdeb923d70b2fe46c817cf890 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/iden-q
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@281ef8e2be3426abdeb923d70b2fe46c817cf890 -
Trigger Event:
push
-
Statement type:
File details
Details for the file q_armor_proxy-0.1.1-cp312-none-any.whl.
File metadata
- Download URL: q_armor_proxy-0.1.1-cp312-none-any.whl
- Upload date:
- Size: 25.3 kB
- Tags: CPython 3.12
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1b04f82aa275229c4b002de493c9dc2500714735ee4191e8876d0cf0cbb4617f
|
|
| MD5 |
15eb26e7a02705ac1aa2cef08789bf10
|
|
| BLAKE2b-256 |
da1c4e7ab4035ca3ba0e88f4263bef9507cbf590ae6728d9b0428fe07d69fa22
|
Provenance
The following attestation bundles were made for q_armor_proxy-0.1.1-cp312-none-any.whl:
Publisher:
release.yml on iden-q/iden-q-quantum-armor
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
q_armor_proxy-0.1.1-cp312-none-any.whl -
Subject digest:
1b04f82aa275229c4b002de493c9dc2500714735ee4191e8876d0cf0cbb4617f - Sigstore transparency entry: 2704190124
- Sigstore integration time:
-
Permalink:
iden-q/iden-q-quantum-armor@281ef8e2be3426abdeb923d70b2fe46c817cf890 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/iden-q
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@281ef8e2be3426abdeb923d70b2fe46c817cf890 -
Trigger Event:
push
-
Statement type:
File details
Details for the file q_armor_proxy-0.1.1-cp311-none-any.whl.
File metadata
- Download URL: q_armor_proxy-0.1.1-cp311-none-any.whl
- Upload date:
- Size: 25.5 kB
- Tags: CPython 3.11
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
024342bcf5b4fde2ecaee2d157cd3dda8e28eed5ef0b393fecb24d7d622792a1
|
|
| MD5 |
d5efc1b99ab58b31510952409d2f9404
|
|
| BLAKE2b-256 |
c950320d1ffebad8f7d548a7e33cdf6b74276ecf234461fec1257d6f25c78475
|
Provenance
The following attestation bundles were made for q_armor_proxy-0.1.1-cp311-none-any.whl:
Publisher:
release.yml on iden-q/iden-q-quantum-armor
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
q_armor_proxy-0.1.1-cp311-none-any.whl -
Subject digest:
024342bcf5b4fde2ecaee2d157cd3dda8e28eed5ef0b393fecb24d7d622792a1 - Sigstore transparency entry: 2704191085
- Sigstore integration time:
-
Permalink:
iden-q/iden-q-quantum-armor@281ef8e2be3426abdeb923d70b2fe46c817cf890 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/iden-q
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@281ef8e2be3426abdeb923d70b2fe46c817cf890 -
Trigger Event:
push
-
Statement type: