Privacy laws and export rules we follow
We map our data handling to privacy laws in 8 jurisdictions, classify our software under ECCN 5D002 for export, and build privacy controls into the architecture from the start.
Privacy laws in 8 jurisdictions
How SwiftQuantum's data handling lines up with each law.
GDPR
European Union
General Data Protection Regulation
CCPA
United States
California Consumer Privacy Act
APPI
Japan
Act on Protection of Personal Information
PIPA
South Korea
Personal Information Protection Act
PIPEDA
Canada
Personal Information Protection and Electronic Documents Act
UK GDPR
United Kingdom
UK General Data Protection Regulation
BDSG
Germany
Federal Data Protection Act
LGPD
Brazil
Lei Geral de Proteção de Dados
Export controls (ECCN 5D002)
How SwiftQuantum software is classified under dual-use export rules
SwiftQuantum is classified under ECCN 5D002 as information security software with cryptographic functions. We follow the Wassenaar Arrangement and the national export control rules of each jurisdiction we distribute in.
Dual-Use Technology Classification
Cryptographic Capabilities
HTTPS (TLS 1.2 or later), plus ML-KEM-768 and AES-256-GCM sealing of Q-Bio web compound inputs, classified under Wassenaar Category 5
Quantum Computing Algorithms
Proprietary quantum algorithms subject to new export controls on dual-use quantum technology
Export Control Regions
Sign-up and payments are blocked from US-sanctioned (OFAC) countries. We do not screen against restricted-party lists.
Compliance Documentation
Our ECCN 5D002 self-classification is documented and available on request.
Privacy by Design
The privacy controls built into each layer of SwiftQuantum
Data Minimization
We collect only the data a feature needs. Expiry rules and purpose limits are enforced at the API layer
Encryption
HTTPS on every public connection (TLS 1.2 or later). On the Q-Bio web app, compound inputs are sealed with ML-KEM-768 (NIST FIPS 203) and AES-256-GCM before they are sent
Consent Management
Per-purpose consent that follows the rules of each jurisdiction, applied across all services
Right to Deletion
Deleting your account removes your sign-in data immediately. Data held by individual apps is removed separately; contact support to confirm
Data Sovereignty
Data protection under GDPR and CCPA
Data Sovereignty
SwiftQuantum infrastructure is designed to meet GDPR and CCPA data protection requirements. We do not collect personally identifiable financial data or plaintext encryption keys.
Simulation Disclaimer
Quantitative Data Tool Notice
Simulation Disclaimer
Our intelligence and security audit tools run mathematical models and simulations on classical hardware. They are quantitative tools that support decisions. They are not a legal guarantee, not investment advice, and not a promise of complete security. You remain responsible for your infrastructure and financial decisions.
For compliance questions, read our policies or contact the team.
Post-quantum compliance deadlines in 2026
Post-quantum migration now has published deadlines.
NIST post-quantum standards are final
Example: e.g. ML-KEM / ML-DSA / SLH-DSA are the approved algorithms to migrate to today.
Europe sets PQC migration timelines
Example: e.g. the EU PQC roadmap puts high-risk systems first, so an inventory is the first step.
“Harvest now, decrypt later” is live
Example: e.g. as fault-tolerance nears (448-qubit FT, 2025), data stolen today is at future risk.