QuantumVault™ GDPR Compliance
QuantumVault™ is BlackVoice's post-quantum encrypted file vault. This page explains how its architecture supports GDPR compliance requirements.
Encryption and access control
Files stored in QuantumVault™ are encrypted client-side using a hybrid ML-KEM-768 + AES-256-GCM scheme. The server stores only ciphertext. Access requires possession of the private key material, which never leaves the user's device.
Data minimization (Article 5(1)(c))
QuantumVault stores only encrypted file data, access logs (anonymized), and metadata necessary for retrieval. No plaintext content or key material is retained server-side.
Right to erasure (Article 17)
Vault contents can be deleted by the account holder at any time. Account deletion triggers permanent removal of all vault data within 30 days. After deletion, the ciphertext is permanently destroyed — recovery is not possible.
Data portability (Article 20)
Vault contents can be exported by the authenticated user at any time.