QuodArca ZKS Conformance Statement
| Field | Value |
|---|---|
| Product | QuodArca |
| Vendor | EISST International |
| Profile | ZKS-Core |
| Additional Properties | PSDA (Provider-Side Data Absence) |
| Statement Date | January 2026 |
| Assessment Type | Self-Attestation |
Executive Summary
QuodArca is ZKS-Core compliant.
The QuodArca architecture ensures that no third party - including EISST International - possesses the technical capability to:
- Access or decrypt user information
- Obtain the complete set of components required to decrypt user information
- Revoke a user's ability to decrypt their own data
Beyond ZKS: Provider-Side Data Absence (PSDA)
QuodArca additionally satisfies Provider-Side Data Absence: no QuodArca-operated service stores user ciphertext at any time. This provides security properties beyond ZKS requirements:
- Zero data exposure: QuodArca infrastructure contains no user data to breach, exfiltrate, or compel
- User-controlled storage: All ciphertext resides on user devices and user-controlled CLinks
- Minimized legal exposure: QuodArca cannot be compelled to produce data it does not possess
Orthogonal Properties
| Property | Question Answered | QuodArca Status |
|---|---|---|
| ZKS Compliance | "Who can ever decrypt?" | ✅ Only the user |
| PSDA | "Who ever possesses the encrypted data?" | ✅ Only user-controlled systems |
Assertion Compliance Summary
| Assertion | Description | Status |
|---|---|---|
| A1 | CSD-Only Decryption | ✅ Conforms |
| A2 | Exclusive Key Material Possession | ✅ Conforms |
| A3 | No Third-Party Decryptability Assembly | ✅ Conforms |
| A4 | No Third-Party Revocation of Decryptability | ✅ Conforms |
| A5 | Plane Separation and OP Blindness | ✅ Conforms |
| A6 | User-Governed Topology and Relocation | ✅ Conforms |
| A7 | Metadata Minimization and Non-Correlation | ✅ Conforms |
| A8 | Recovery and Reset Safety | ✅ Conforms |
| A9 | UKRS / Key Separation Mode | ✅ Conforms (with sovereign restoration) |
| A10 | Cross-Domain Collaboration | ✅ Conforms |
Architecture Overview
QuodArca implements a four-layer architecture with strict vertical-only communication:
- app-ui - User interface (within CSD)
- app-mngr - Application logic (within CSD)
- app-svs - Services including cryptographic engine (within CSD)
- app-ext - External services (QKEYS, QCLOUD, QP2P, QMSVC, QBEND)
All external services are cryptographically blind - they handle only opaque encrypted blobs and cannot decrypt user data.
Update Transparency
QuodArca implements Sigsum binary transparency with:
- Blake3 cryptographic hashes
- Ed25519 signature of manifest
- Public, append-only transparency log
This exceeds ZKS-Core requirements and satisfies ZKS-Enterprise update transparency.
This attestation was prepared by EISST International in accordance with ZKS-1.0-CR1 Section 7 evidence requirements.