LinkSquares Post-Quantum Cryptography (PQC) & Cryptographic Agility Statement

Status: Active Security & Engineering Roadmap

At LinkSquares, our mission is to empower legal, finance, and procurement teams with intelligent contract management while providing uncompromised security. As quantum computing advances, the cryptographic algorithms that safeguard today's digital infrastructure such as RSA and Elliptic Curve Cryptography (ECC) will eventually become vulnerable to quantum-based decryption algorithms.

Because enterprise contracts often contain long-term commitments, intellectual property rights, non-disclosure obligations, and strategic trade secrets spanning 10, 20, or 30+ years, contractual data is inherently vulnerable to "Harvest Now, Decrypt Later" (HNDL) risks.

LinkSquares is committed to maintaining a future-proof, quantum-resilient security posture that protects customer contract data throughout its entire operational lifecycle.

Our Core PQC Strategy & Commitments

1. Cloud Infrastructure & Hybrid TLS Integration

LinkSquares leverages world-class cloud provider Amazon Web Services (AWS) and monitors the AWS security roadmap to align our hosting environment with emerging post-quantum standards:

  • Monitoring Cloud Roadmaps: We continuously track the deployment of NIST-standardized Post-Quantum Cryptography across AWS KMS and AWS CloudFront.
  • Hybrid Post-Quantum TLS: As cloud partners roll out hybrid key exchange protocols (combining classical algorithms with NIST-approved lattice algorithms like ML-KEM/Kyber), LinkSquares actively aligns its edge networks and internal API endpoints to ensure encrypted data in transit remains safe from interception and future decryption. We are committing to TLS 1.3 with hybrid key exchange as the transit migration path.

2. Symmetric Encryption & Data at Rest

  • AES-256 Baseline: All customer contracts, metadata, and extracted AI insights stored within the LinkSquares repository are encrypted at rest using AES-256.
  • Quantum Resistance: According to NIST guidelines, AES-256 provides a robust 128-bit security level against Grover's quantum algorithm, ensuring that contract data stored today remains mathematically secure against future quantum attacks.

3. Application-Level Crypto Agility

Crypto agility is the ability to swap underlying cryptographic mechanisms, certificates, and libraries without disrupting platform availability or application logic. LinkSquares maintains application-level crypto agility by:

  • Maintaining a continuous inventory of cryptographic dependencies across our web application, microservices, and agentic AI pipelines.
  • Abstracting key exchange and signature libraries so that as post-quantum digital signature standards (such as ML-DSA and SLH-DSA) mature across public key infrastructure (PKI), they can be introduced seamlessly into our eSignature and audit logging frameworks.

Post-Quantum Cryptography (PQC) Migration & Assurance

LinkSquares maintains an evolving approach regarding Post-Quantum Cryptography (PQC), ensuring our platform remains resilient as cryptographic standards emerge. Our approach is built on transparency, industry alignment, and continuous technical validation.

  • Strategic Intent & NIST Alignment: We prioritize a security-first approach that aligns with evolving industry guidelines. As new standards are finalized, LinkSquares integrates these updates into our core security engineering roadmap to prevent long-term "Harvest Now, Decrypt Later" risks.
  • Migration Roadmap & Adoption: Our roadmap involves the continuous assessment and exploration of quantum-resistant algorithms, such as ML-KEM and ML-DSA, as industry standards and cloud provider support mature. These deployments are synchronized with cloud infrastructure advancements and the publication of industry standards to ensure stability and compatibility. Our migration roadmap targets hybrid post-quantum key exchange (ML-KEM) for all data in transit ahead of the CNSA 2.0 / NIST IR 8547 milestones (2030–2033), synchronized with AWS’s PQC rollout across KMS and CloudFront.
  • Assurance & Transparency: We maintain transparency with our customers through ongoing updates on our Security Hub. While we transition to PQC standards, our existing foundation leveraging AES-256 and established cryptographic agility provides immediate and robust protection for all contract data.
  • Regulatory Frameworks: LinkSquares ensures alignment with emerging frameworks to help guarantee that our enterprise customers remain compliant with security mandates throughout the quantum transition.

How LinkSquares Helps Enterprise Customers Manage PQC Risk

Beyond protecting our own platform infrastructure, LinkSquares empowers enterprise legal and security teams to manage PQC compliance across their third-party vendor portfolios:

  • PQC & Security Clause Intelligence: Using LinkSquares AI, legal teams can automatically scan historical contract repositories to identify vendor agreements that lack modern cybersecurity obligations, data breach notification windows, or crypto-compliance mandates.
  • Third-Party Vendor Risk Monitoring: Identify contracts with long retention requirements or sensitive IP provisions to prioritize vendor risk reviews ahead of regulatory post-quantum deadlines.

Continuous Verification & Compliance

LinkSquares enforces continuous third-party testing and compliance frameworks to validate our security architecture:

  • SOC 2 Type II & ISO 27001: Audited annually to verify our access controls, encryption implementation, and operational safety.
  • Continuous Vulnerability Scanning: Ongoing automated scanning of cloud infrastructure and third-party code dependencies to detect cryptographic deprecations early.

For specific questions regarding LinkSquares' security posture, compliance certifications, or custom encryption options (such as Customer Managed Encryption Keys), please visit our Security Hub or contact [email protected].