oursly.io's whole premise is memory that belongs to you for a decade or more. That horizon makes post-quantum non-optional. This page publishes the real ML-KEM-768 + ML-DSA-65 keys we will use, a cryptographically-signed genesis attestation, and verifier recipes — honest about what is live tonight and what is still roadmap.
Four artifacts a third party can validate without trusting our word: the TLS edge, the ML-DSA-65 application key, the ML-KEM-768 application key, and the signed genesis attestation declaring all of the above.
oursly.io is served from Cloudflare Pages. Cloudflare enabled the X25519MLKEM768 post-quantum hybrid key exchange across its edge during 2024 and it is on by default for Pages projects. Clients with Chrome 124+, Firefox 132+, or curl ≥ 8.10 negotiate the hybrid automatically; older clients fall back to classical X25519.
Self-attestation from this server: TLS 1.3 is live and the connection upgrades to the PQ hybrid when the client supports it. The build-time probe in this session used curl 7.81 / OpenSSL 3.0.2, which is below the PQ-capable threshold and therefore reports only classical X25519 — that is an artifact of the probe client, not of the server. Run a modern client to observe the hybrid negotiation directly.
{
"algorithms": {
"hash": "SHA3-256 / SHA-256 for fingerprints",
"kem": "ML-KEM-768 (NIST FIPS 203)",
"signature": "ML-DSA-65 (NIST FIPS 204)"
},
"attestation_version": "1.1",
"canonicalization_rule": "JSON canonicalization: sorted keys, no whitespace, UTF-8; sign the canonical bytes directly",
"custody": "Genesis private keys held by TOHID NAEEM personally as founder of MNNR LLC; stored on a non-synced local path (C:\ProgramData\mnnr_oursly_pq_keys\) with NTFS ACL restricting read/write to TOHID NAEEM + SYSTEM only. HSM custody migration remains on the roadmap.",
"issued_at_utc": "2026-06-10T06:37:25+00:00",
"issuer": {
"ein": "33-3678186",
"formation_date": "2025-02-26",
"founder": "TOHID NAEEM",
"jurisdiction": "Wyoming, USA (domestic)",
"legal_entity": "MNNR LLC",
"principal_place_of_business": "Silicon Hills, California, USA",
"veteran_status": "Decorated disabled veteran-owned"
},
"key_id": "oursly-genesis-2026-06-09",
"library": "pqcrypto 0.4.0 (Python)",
"product": "oursly.io",
"public_keys": {
"ml_dsa_65_b64": "CJCO/YS2x7lMccLHlUw7sV3WsGTPQKcQ66pQ0zwj7pWa7naA9VZUmLAYfH9OyfBwb0hy36eyD+ng5+4ixkWvwohMIjh64Zth+bznKYBmamDNRomJ9UH/7ZABJz7nipoN5GtqfBbYyzzMoPrUdMGD+zSdA5WAQMSM7/ZzOkxAiykSBuxhABXsrQ+m5n8qj5dx7Kk0nD4uG392WwojnO3PdL1ZK0go9RV/2bBsbyo3j7Olia4tBIzXBmD7jYame/jgdKHIsuvDCvPOO0+M2feI7PNt+qzykS8kdaP7qNhBGwtj5axDc/jGa6Oe9DfHPc+8Hdmccc2AZEdD8scWvWJQMoGBKxnShexJ8hUcLZ808mx7yAEp6MmMUBouPcMruIU5M3fim9l8ATHfHAZ8ga8G8stYDU4ZG0LuIoSLIBal33rrWDQZv+GBhDvdbYu/j58xPNk0gugVilunMppTxr3XdaGsIvPAZYZTSfvWJSgvu/73usl/xfhu45OmqVyoHh70DJtbLOJtkANifkG++GHugYn869gJ5ue/wjRRyOalHiwwzUeDBw3diavFM8IibeYQFso2OYYRfNmKNJvIODXcjuS7YmV9OrnU32qSdQmtkjbHXCgld1QARn1pvUcozZGt5+ReYVjFx2wX6c5nLxgd/T83FTAvtVtB3jl8QFUlWi9/rCR57WUDOqbZGnMIQJGnfOsf7K0bn2BOOXcoZhJN7+Z9meEb479j9k4fPS6v/oycyY8nRPxJVA8LgUAz1oSc9ITPK+LcoeOYiSULdVo8aOuhXg+nEfkz6u1n7iaU5VJ3/2PQnc6J5TRsmpzahJOK3jBGtMBlEV1U0vzo/LpI9tv6LktRuMGwcnPy8KJ4XHtpRH4wo60nhY2oa+vWNcx8ST1L+Z1+lgEs9p0SDzpCF/SvOdodyCqKsAFY3z055ZaDNB0oGSMfMCXZJxuFSM+V2lno7c8gBguxiZ1o2FR8+hf11yarLQI1bg8k49FmkhHRsbxn+lZ2trMFWyy/xqavmOsQeFq4k8UByJOG60eFzT+Mme25+zLFZZimr2el7kkz7O4Z65cl1OkQmxzAwgrhcdtsIWKBoR5A2EjeqAE34fJXpx4FRMK8bT2c1sROm+WD2ubqPklrXXMTtNURRtPZdgZEONNxxZdsgjVj4YLH4Kq2qoAdsfjkGvxp3YQKeXEVWTkNl9KbRHvCH9+GN3nYgl0fxVon1GYi3iVOwYDvlKHzhg7psHDsUAyvegWxVGY8Ac5cDfe8+T1Zqi+qCdFriWrGam+XqnL/zUoQK3E9nmeEsHYxiEPDjkLcgI0ZFD3896B42oiMwb+B16v/vt5jdv2r0TFBeRKfarKGqKu+MwsxkdzlMuPlcpT2BZ0LhG+ilHdKU9sgDcR+sZLZuyX6GcAvEZPfOukX7c3KK4YegMWkfrUmc/yafjrYDF7zIzj7Z83iR5/EIWM4IbsjigrNvbvPhXJ8O3sL2aKO1iWwES981oxmXE+9TzGcS59kfoG+9s72myFqMswTUNAotyPAE64ctSRxFgnC6BURum76TOE4RfAUCTArxq6+pZlU0TzLOtdz9qxSKa4yoPxE50G27Nb+r08xNAxHakWm3rHwVlBGbU+sCyJJVpYrEQjqew+L5ql0O+Iao4x+gMio7G1wALdmukYYbhI20TS6mC2qaXv6MSv8aCYGOhK7K5TPekvcz+i3nnxw4txseu2iDrqGyqpX/1CorDvPaduAwKCcE4hz34Yz4rGAXkGxv2nHgIDQBoMxaDswPLmznlP9YjXMYk2mrEHhav+w6ZVdbPpo84zXPPEJZDWXnBeJku8dkb+gH2TK2MyPweJmZYGbaP7vM37bhKRihcI5K8S5vu0SqAZGLIRZJBFhXcOaMhp5IMuNzE5SS5CSWAxi7mynjY5w8MoW38tOCBy+CXhkTX5m2IvKhsLLlTyUG7Qu20Kn6bO19JTg6m6hRsw5I16mG2qi1f3gS2Cbehine/fF/LNuEwlHswmjDCqzB6nyDHw5es5cEHvpWPYiIduJGV4oeYcEUHr+EyAWmb2LNocu9cNj7LThvlbix4sENmq95mL5OfIaVJA/ZlscI0mXOkKZHQ8RAQfzsPd7RMXRyfLMbCZStQR/ppjxNkUEAkbiDWfoYcPvI8Us75rC/YM+ddspbp9xZS78Tx/l6o5UXitjGjwMZgQPy2ShpwtDnbYyEY65nfyGoQRH6v4788O2+TesCHcabE2RstTT8LJrwwbL11AWsrbFtqJ1Ad6UV1w3OV7++LB6PjTVxJL+5o1kJtomlqmx2+qWWFmLqvXK/85CIjyemk6HxWZ64YWUEY1zAAaX+2ZyVaId9POqjDxMI3rvTxgjkqdH5SEjkCUpSeAkMQb9D4quHclJozbk72ZTNKP9a+SWEVCrmFHG9BNSimHVbT9oL4CiSTC2x7TOKf+VCbycqY8InEnc77MlfQdsvS44jhhPgaqROXSEA1ryhEgKeZU5TqLmYxWc0x7TPNzZI2BeU7jT16c4/86G2qVr0WZ4T/ymQb8iRN+u2tYcRLETefhlH98fGXuLImVyU84I/BCa8GjXC3KmGMugBkCBDK/iA8w=",
"ml_dsa_65_sha256": "4c954ff453b913e229f75dfb012ccfa178f01a03b26ac9c04659cbbf2dcbaa1c",
"ml_kem_768_b64": "ciZQRdF+FhuIxWxMZGWYmrmuQIGiZJesaohc1kINHMxxvqkjowIoI8GTcsko4caN+CaHUkUMfcAflMMRjjqIrKckWMaFLJqyJgMJY7qwxqQQhcDNs6JPpTCokbCAPIcupVegTbskinaFLiWVksc5iSBXORRnlfCdH6OOo1w1R1EV4HgH9gujDCAicKlqQuue+YsegIt/t7W33oYp7WKXsBM/8CRBcohySqe+UVOYIhoIfTuYlZGi6JWsWOOVqIBmkhXKysqoe7cK5AAjdoiwl+jDB7u6lQiG7IuAo8MLmjDGgoAn4aGupqMsy4V7VmByeuFQH5lMMsaWLTNfd4ELoACrGoUsANov6gSnuVZ6l1lso/zDMBZQZaHOQpEjH7KVKooUAZMagsTJgUkp3mVlBHh25kmuthGuOgdEpQJA5Ec6k3t8BIW/Ddw99jUbAzI4X8s5z3ECsQwbdCPCYOJfMKZ80TN63IYe5NW77PyLWftNG0EJJAKAzswsN9LMkJgvyMUH2WG769qTVFcvKFRd22lC9MZk1ZMcZnKyEdiwKjeL++J53gh/jOdXLxeovAMWGwGw4HAVWtQr/dCwGQi4Yks2t1ZeKOlXV8MftACa4kiypBuuzklP2Nk63UAVZblgQhMWvyvDsVCVinaeDuxRm5GqLnKJR9CnXHtfv4LA3zJHFcGjD9iDKrs7QenF+tagcVMxPsgAFzpMGdUe1esMiAoRtoQ8WvRswNQ6IzKm+6WGeqtBTSMCs+DBl3s+MzWcywhOIZyNexpL/1Ox1aFG/UGEzkpDSCADBVZKEyOemuCWNuhuQUUo3VehA0LDaFVehQh/3oB/8kLNwbA2PdeJrbVXRfcV5DF7itp27MvI+hdVutu8gseprvnHcgxVQhCgcAuUroQNTcMYEPoV7iPL0RaiCbpSPjcF4WXKMvNSo9oVs1FUAXd3T+W7k5agH2J3k/QCbbiW51Z6qNS36nQSTTEwBWBqV+gxysN/OawYFSetloGudcCGv7uTSmmvkcO+EqC3JOmAE9YZ3qChYNgQA4cafttdF8ZedGBdtOBMrjEWEGqKUlsn0OZqq8UCCok3nSW/3QenTCd+DhRvDwFGoeA6S9AxDna4CxYvr6hRkIRXkDM1g9CTIheujqkYzsQbX7qa3FQPZLKiRUkzsTFjHQNdH3CoocB4W2yBAVNQktIunQCV9xfL/SwtRPE0nuyUQSWl6yoU7neuMboHDPdpQpC5rKlet6QalnLG2FyI8PtfavYTfGXBRbUScoVcUHeaT0OeJJfAx/SUvXFZXIhNWRwT/uYSD4O66Zp1DexzIxMbtbeabCMP3SFkXFQRYXEh0FBT1uqh4mwYJ8xo5zagU3yYyqeqLLOUAbMBlQWq+bdT4JahBteKVkPOKzCfKZxmmLnAt0XEpvghkBdaHvSAaLVgXGZAloYPO5qBDCTEKRk+DrckhDxHIrJUOKC9H0pGCkPGCMl5lrIwXARa9eC8LuxiOXSv38EfPpwZZtJp5QuKrOGEC6VTctuDIlK4eQUMWfOYgtdJEaokPlJHM9XF5k4YbPOdbWYTKXJso2RnPgI=",
"ml_kem_768_sha256": "f9b25dc59ed39066d1f3978ed0ba9d0e312644320d5427f0d73de00ef5c2cf31"
},
"purpose": "Envelope encryption for memory blobs, signed citation events, per-user key derivation root.",
"rotation": {
"deprecated_artifacts_preserved_at": "/crypto/oursly_mldsa65_public.key_DEPRECATED_20260608.* and /crypto/oursly_mlkem768_public.key_DEPRECATED_20260608.* (audit-trail preservation; verifiers may still reproduce the prior fingerprints from these files to confirm the rotation).",
"deprecated_fingerprints": {
"ml_dsa_65_sha256": "98a1cbe6e62750193c7db2bcb22134f99f4b443b1a28f32a39c80722c6315ed7",
"ml_kem_768_sha256": "d09c7eeaebc1169d52f0aafc1816f2dadff630bee20539dd4e92167f99caea6c"
},
"rotated_on_utc": "2026-06-10T06:37:25+00:00",
"rotation_reason": "The initial 2026-06-08 genesis keys were generated into a cloud-synced OneDrive folder, creating a custody mismatch: the root-of-trust private keys were exposed to Microsoft OneDrive cloud storage rather than held exclusively on a local non-synced path. Treating the 2026-06-08 keys as compromised and rotating to fresh keypairs.",
"supersedes_key_id": "oursly-genesis-2026-06-08"
},
"scope_live_tonight": [
"Public ML-KEM-768 key published with SHA-256 fingerprint",
"Public ML-DSA-65 key published with SHA-256 fingerprint",
"This genesis attestation, signed with the ML-DSA-65 private key",
"TLS edge: Cloudflare X25519MLKEM768 hybrid (per Cloudflare default for Pages)"
],
"scope_roadmap_not_live_tonight": [
"Per-user ML-KEM-768 HD-derived keypairs (Q3 2026)",
"ML-KEM-768 envelope encryption for memory blobs (Q3 2026)",
"Citation Watch events signed with ML-DSA-65 (Q3 2026)"
]
}
Three reproducible recipes. All three operate on the public artifacts above; none of them require trusting this page.
pip install pqcrypto
python3 - <<'PY'
import base64, json, urllib.request
from pqcrypto.sign import ml_dsa_65
attest = json.loads(urllib.request.urlopen(
"https://oursly.io/crypto/oursly_genesis_attestation.canonical.json"
).read())
canon = json.dumps(attest, sort_keys=True, separators=(",", ":")).encode()
pk = base64.b64decode(urllib.request.urlopen(
"https://oursly.io/crypto/oursly_mldsa65_public.key.b64.txt").read())
sig = base64.b64decode(urllib.request.urlopen(
"https://oursly.io/crypto/oursly_genesis_attestation.sig.b64").read())
ml_dsa_65.verify(pk, canon, sig)
print("oursly genesis attestation: VERIFIED")
PY
Library version pin: pqcrypto 0.4.0. Other liboqs / PQClean bindings expose the same FIPS-204 primitives under different module names.
# confirm the published ML-DSA-65 public key matches the fingerprint curl -sS https://oursly.io/crypto/oursly_mldsa65_public.key | sha256sum # expected: 4c954ff453b913e229f75dfb012ccfa178f01a03b26ac9c04659cbbf2dcbaa1c # confirm the ML-KEM-768 public key matches the fingerprint curl -sS https://oursly.io/crypto/oursly_mlkem768_public.key | sha256sum # expected: f9b25dc59ed39066d1f3978ed0ba9d0e312644320d5427f0d73de00ef5c2cf31
If either fingerprint diverges from the value above, the keys have been rotated or tampered with — verify against the canonical genesis attestation before trusting the new value.
# curl 8.10+ with a recent OpenSSL/wolfSSL/BoringSSL build, or use Chrome 124+ curl --verbose --tls13-ciphers TLS_AES_256_GCM_SHA384 https://oursly.io 2>&1 \ | grep -iE "named_group|key_share|MLKEM"
In Chrome: chrome://flags#enable-tls13-kyber must be Enabled (default true since 124). Inspect a request in DevTools → Security → Connection — look for "X25519MLKEM768" in the key exchange.
The bullets below are deliberately not on the "live" list above. The oursly.io marketing pages will not claim them as live until the artifacts are publishable here and verifiable by a third party.
Memory is the longest-lived data you own. An AI memory store holds journal entries, voice notes, files, the graph of who-knows-what — content with a privacy horizon measured in decades. An adversary who records ciphertext today only needs to decrypt it once, ever, to extract the same value. Quantum-safe key exchange now closes that window retroactively.
Q-day is uncertain — harvest-now-decrypt-later is certain. The post-quantum migration is not a forecast of when the relevant quantum computer arrives; it is a defense against the recording that is happening today. The shorter the privacy horizon, the more defensible classical crypto is. Memory has the opposite shape — long horizon, high private value — so it gets quantum-safe first.
The audit trail you sign today must still be unforgeable in 2035. Citation Watch events, equity ledger entries, custody attestations — all of these need to be cryptographically verifiable for the full retention window. Signing them on classical ECDSA in 2026 is the premature decision.
Wyoming domestic LLC · EIN 33-3678186 · formed 2025-02-26.
Founder: TOHID NAEEM. Principal place of business: Silicon Hills, California.
Genesis key custody: The four private keys backing the published public keys are held by TOHID NAEEM personally as founder of MNNR LLC. HSM-custody migration is on the roadmap; the rotation plan will be published on this page under a versioned anchor (a supersession note) at the moment of cutover.
Library used to generate the genesis keys: pqcrypto 0.4.0 (Python). ML-KEM-768 is implemented per NIST FIPS 203; ML-DSA-65 per NIST FIPS 204. Canonical JSON for the attestation: sorted keys, no whitespace, UTF-8.
Decorated disabled veteran-owned