Skip to content
8BraidCreators of
8DB

Journal series · 14 articles

Post-Quantum Databases

Read the complete sequence or enter at the question most relevant to your architecture.

Engineering note

Post-Quantum Databases

A Post-Quantum Handshake Protects One Journey. 8DB Seals the Record for Every Journey It Will Ever Take.

A database does not become post-quantum because its wire does. The records on disk, the indexes that find them, the backups that restore them and the keys that must hold for decades are the boundary that decides whether your data survives the transition. Here is how to draw that boundary, the questions to put to any vendor, and the measurements showing that the post-quantum cost lands at the boundary and not on every row.

6 min readEvidence-backed architectureRead article
Engineering note

Post-Quantum Databases

The 2035 Migration Is Already Scheduled. Is Yours?

NIST has published the dates: quantum-vulnerable public-key algorithms are deprecated in 2030 and disallowed in 2035. That makes the post-quantum transition the first algorithm migration in history with a known successor already on the calendar. Organisations treating it as a one-time project will run it twice. Here is what it takes to run it once and then flip a switch.

6 min readStandards timeline · Registry mechanism tested · Store transition on mainRead article
Benchmark

Post-Quantum Databases

We Are Racing Oracle's Online Rekey, and Publishing the Rules Before the Race

The strongest incumbent answer to 'change the algorithm on stored data without an outage' is Oracle's online tablespace rekey and conversion, and it is the comparison that matters. We are measuring 8DB's record-level migration against it on the same records, under a steady live workload, on hardware you can name. The method, the fixtures, the disclosure rules and the pass criteria are here, fixed before a single number is, so that nobody has to trust the winner's account of the race.

6 min readPre-registered protocol · Results to follow · No numbers claimed yetRead article
Engineering note

Post-Quantum Databases

Your Backups Are the Quantum Attack Surface Nobody Inventoried. 8DB Inventories Them From the Record and Migrates Them With the Data.

The scanner says your database is fine. Your 2019 backup disagrees. Every snapshot, replica and archive is a copy of the cryptographic envelope as it stood the day it was taken, and it will still be readable the day that envelope's algorithm falls. Migration programmes that inventory the live system and stop have found the front door and left the warehouse open. Here is what a data system has to do so the copies migrate with the data.

6 min readMeasured on four hosts · Recovery under current authority on main · Evidence folders namedRead article
Engineering note

Post-Quantum Databases

Your Migration Plan Encrypts One Copy of Each Record. Your Stack Holds Eleven.

Derived data is data. The index, the embedding, the cache, the replica and the warehouse row are the same record wearing different structures, each with its own envelope and its own owner. Here is how to count the copies, why the other ten are the exposed ones, and what changes when the copies stop existing.

8 min readArchitecture · Measured at 4.28 million recordsRead article
Engineering note

Post-Quantum Databases

Your Post-Quantum Migration Has 21 Questions. The Algorithm Answers One.

Swapping the algorithm is the easy part. A post-quantum migration is an operating commitment across seven surfaces and three tenses, twenty-one cells in all, and most of the products on a 2026 shortlist fill one of them. 8DB fills the grid from one place. Here is the grid, what lives in the seams between the cells, and why the seams are the part to be afraid of.

19 min readBuyer's grid · Measured components · Reproducible harnessRead article
Engineering note

Post-Quantum Databases

The Next RFP Question Is About Your Stored Records. Build the Answer, or Embed It

Every product that stores sensitive data for years will be asked the same question by federal, defence and regulated buyers: when an algorithm retires, how do the records already written move, and how do we prove it? 8DB is an embedded engine that makes the answer a property of your product instead of a project for each customer. Your interface, your customer relationship, our substrate doing the cryptographic, governance and provenance work you would otherwise have to build.

9 min readMeasured components · Embedded engine · Two 8Braid products built on itRead article
Engineering note

Post-Quantum Databases

Category 5 Keys in Software, on the Hardware You Already Have, No HSM Required

Deployed systems, vehicles, sensors, field kits and disconnected sites hold sensitive data for years and cannot call a cloud key service or carry a hardware security module. The post-quantum transition still applies to them. 8DB establishes Category 5 keys in software, in process, on the hardware you already have, leaves no key database on the device, and pays the post-quantum signature once per batch instead of once per row.

8 min readMeasured components · Software-only, in process · Known-answer suite runs on your hardwareRead article
Engineering note

Post-Quantum Databases

Your Archive Is the First Quantum Target: Running the G7 Roadmap on Thirty-Year Records

Financial institutions hold decades of records that an adversary can copy today and read later. The G7 Cyber Expert Group roadmap names six activities for the transition; the two in the middle, execution and testing, are where stored data becomes the hard problem and where tooling built for network migration runs out. 8DB performs both as database operations and hands the examiner evidence that checks without trusting the operator.

8 min readMeasured on four hosts · Audit-oriented design · Transition on mainRead article
Benchmark

Post-Quantum Databases

Post-Quantum Cryptography for Stored Data: The Per-Record Cost Is Zero Bytes

With the record cipher held constant, post-quantum key establishment adds zero per-record bytes. In the latest four-CPU evaluation, a 100,000-record migration met its one-second deadline for eligible reads and recovered from a halfway process kill. The evidence retains the passing run and earlier deadline failures.

14 min readMeasured · Live 100k migration · Two-host recoveryRead article
Engineering note

Post-Quantum Databases

M-26-15's Hardest Instruction Is a Database Operation. Here Is How It Runs.

Inventory tooling tells an agency what is exposed. It does not move a decade of stored records under post-quantum keys, prove the move finished, or do it again when the next algorithm retires. 8DB is designed to run that transition as a database operation: an algorithm version on every record, two versions live at once, completion accounted per record, recovery under current authority, and a post-quantum envelope whose per-record cost is measured at parity with the classical one.

9 min readMeasured on four hosts · Reproducible harness · Transition on mainRead article
Idea

Post-Quantum Databases

The Database That Reports Its Own Cryptography, Per Dataset, On Demand

Executive Order 14412 asks for a cryptographic bill of materials, and every tool that produces one today scans from the outside. 8DB holds the answer on the inside: an algorithm version on every ciphertext, keys derived from each record's governance state, one post-quantum signature over every batch. The self-report turns that state into a CycloneDX 1.6 artifact a compliance team can file, per dataset, on demand, generated where the data lives. Early access is open to the teams who have to file it, to shape the fields that come next.

5 min readCycloneDX 1.6 export on main · Schema-validated · Early-access program shapes the next fieldsRead article
Benchmark

Post-Quantum Databases

The Category 5 Bill Is Paid Once or Paid Per Record. Architecture Decides Which

Hold bulk encryption constant and the real economics of post-quantum storage appear. Moving key establishment to ML-KEM-1024 added zero bytes per record and no measurable per-record latency. Integrity is where the money goes: whether a post-quantum signature is repeated on every record or applied once to a native dataset boundary is the difference between 13.1 MB and 579.4 MB for the same 100,000 records.

6 min readRelease-executed benchmarkRead article