Skip to content

8DB | The embeddable, post-quantum database

Post-quantum security.
At rest. In transit.
Built in.

Keep control of your data as it moves from your application through infrastructure you don’t control.

Protected local storage. Recipient-protected exchange. A path for changing cryptography. Together in an embeddable, omnimodal database.

Your data. Your authority.
Your applicationWorks with protected local data
Authorized
Recipient-protected message
Cloud or network relayCarries the message. Has no payload keys.
Protection travels with the message
Your recipientVerifies, opens and stores locally
Authorized

Illustrated with the reviewed lexical exchange profile. Explore the protection →

Protection is qualified by workload and deployment. The reviewed integrated exchange supports canonical lexical records. See data and device fit →

The buying decision

Bring more of the protected
data lifecycle into one engine.

Your team needs the whole path to work: local data, trusted recipients, protected exchange and recoverable change. The difference is how much you have to connect and maintain.

A composed application stack

Strong components.
Integration your team owns.

Server databasePQ transportDevice storeIdentity & sharingRecovery policyUpgrade workflow

Each component can do its job well. Your application connects their keys, permissions, data copies and change procedures.

Explore Oracle, Db2, PostgreSQL and embedded alternatives →
The 8DB approach

A shared engine.
A connected protection lifecycle.

8DBEmbeddable · Omnimodal
Local storageRecipient exchangeVersions & migrationManaged recovery

Supported paths bring storage, exchange and cryptographic change together. Your application has fewer separate boundaries to coordinate.

Map the supported path for your application →
Your authority stays explicit.

You control enrollment, root-secret custody and deployment policy. Compare the exact workload and configuration you plan to run.

The questions worth asking before you chooseFour Illusions of Post-Quantum Database Security

01 / Keep control along the route

Let infrastructure carry your data.
You decide who can read it.

A quantum-safe connection protects a link. Your application needs protection to survive forwarding, local storage and later recovery. Start by identifying every place that receives plaintext.

Who can open the message?

Authorized sender

Seal for the recipient

The node protects the message before it enters the network.

Can read its data
Forwarding intermediary

Carry encrypted bytes

Receives no payload keys. Inner protection survives an outer connection ending here.

Cannot open the payload
Authorized recipient

Verify. Open. Store locally.

The node reseals its local records under independent storage keys.

Can read authorized data

8DB example: reviewed lexical node profile. Secure endpoints, trusted enrollment and key custody are required. Relays can observe routing metadata and disrupt delivery.

Act before a copy is captured.

Attackers can retain vulnerable encrypted exchanges today for decryption by a future quantum computer. Protecting the inner message lets participating 8DB nodes establish PQ protection without waiting for every network intermediary to upgrade.

NIST on the quantum threat ↗

Keep local work local.

Provisioned 8DB core storage operates in process with the network disabled. Its tested local operations require no online external key-management or identity service. Your deployment still protects root secrets, enrolls endpoints and defines authority.

Read the disconnected-store evidence ↗
Inspect the cryptographic profile and trust boundaries

The reviewed node exchange uses ML-KEM-1024 key establishment, ML-DSA-87 frame authentication and AES-256 payload protection. Recipients verify and open messages, then reseal local records under independent storage keys. The stored-record comparison uses AES-256-GCM-SIV. Endpoint compromise, enrollment and key custody remain part of the security model. Relays can still observe routing metadata or interrupt service.

Inspect the implementation and lexical admission profile ↗

02 / Bring more of your application together

Different data. Different devices.
A common engine.

A service record, a sensor stream and a relationship can belong to the same application. A shared information architecture helps you connect them without making every data shape a separate system to govern.

Omnimodal / what you work with

Keep the shape the question needs.

Records & documentsGraphs & hypergraphsDense & sparse vectorsTime seriesSpatial structuresMedia

Connect a service record, a sensor trend, a relationship and a similarity query through shared typed information. Supported projections can reuse its governance and provenance.

Explore data models and operations ↗
Embeddable / where you work

Bring the database to the application.

WatchPhone & tabletDesktopServer

iOS · watchOS · macOS · Windows · Linux · Android

Run in process on the platforms your application uses, with work sized to the device. A field team can use its provisioned local store while a connection is unavailable.

Explore embedded deployment ↗

03 / Protect the useful life of your data

Algorithms will change.
Build in a way forward.

The cost of a cryptographic change reaches into applications, old data and restored backups. 8DB connects version awareness, controlled migration and recovery so your team can manage the transition as a lifecycle.

  1. 01

    Identify

    Inspect record versions and dataset cryptographic posture.

  2. 02

    Control

    Select the active write version and govern supported legacy reads.

  3. 03

    Transform

    Prepare and verify a replacement generation before activation.

  4. 04

    Recover

    Resume interrupted work and apply current authority to managed recovery.

  5. 05

    Account

    Report migration status and remaining managed-copy obligations.

Keep the transition connected.

8DB’s versioned ciphertext and registered implementations let supported old and new versions coexist. Applications share a dispatch path while stored information moves forward. Configured controls, managed recovery and posture reports connect the change to evidence of what happened.

Compare the work around the migration.

Oracle offers online tablespace rekeying, with auxiliary storage and master-key coordination. SQLCipher supplies migration tools; non-default legacy settings can require manual export, and applications handle upgrade detection. Separate stores and exports still need coordinated plans.

What the migration evidence demonstrates

The published vendor-run lexical test migrates 100,000 records from HKDF-SHA-256 to HKDF-SHA-384 with AES-256-GCM-SIV unchanged, including interruption and recovery. Retained runs include read-deadline failures; process outages are recorded separately. New algorithms need implemented and validated providers. Migration consumes resources and is not a zero-downtime guarantee.

04 / Make efficiency part of the design

Keep the compact record.
Keep the fast AES path.

Large public-key objects needn’t be repeated on every small record. 8DB separates key establishment, record encryption and shared integrity boundaries, so each layer pays for the work it needs.

Choose the measurement boundary.

Same-cipher component comparison0 extra bytes

Additional PQ ciphertext bytes per record,
before database framing and metadata.

Classically established key115-byte payload + 16-byte tag131 B
PQ-established key115-byte payload + 16-byte tag131 B
Same AES-256-GCM-SIV operation

Keep the fast
AES record path.

PQ key establishment prepares the key. The record still uses AES-256-GCM-SIV, keeping large public-key operations outside this encryption step.

Key establishment, envelopes and signatures retain their separate costs.

See the measured timings

Four historical host pairs recorded encryption medians within 0.55%, with keys already established. Later paired measurements used 2,000 samples per arm on x86_64 and ARM. These vendor-run component observations exclude setup and do not measure a complete database write or transfer.

Latest paired results and methodology ↗Historical host results ↗

PostgreSQL and MongoDB applications can also amortize key establishment and signatures. 8DB provides an integrated implementation; these component results establish the record-path behavior, not a whole-system speed or storage ranking.

Explore the measurements and full cost accounting ↗

05 / Compare the complete application

Compare the work
behind the capabilities.

Oracle, Db2, PostgreSQL, MongoDB and embedded databases give teams useful building blocks. Look at what each approach provides, then at the work needed to deliver your complete application.

Oracle / IBM Db2PQC connections + server-side encrypted storage
What it provides

Protect database connections and encrypt stored data, with local or centralized keystores depending on configuration.

Work to plan around it

Identify every endpoint that sees plaintext. Add inner payload protection where a gateway or service must forward data without reading it. Coordinate separate device stores and their recovery policies.

Why evaluate 8DB

8DB combines recipient-protected exchange, local admission and resealing inside the embedded node. Your relay can carry the message without its payload keys.

PostgreSQL + OpenSSLA configurable PQ transport foundation
What it provides

PostgreSQL 18 exposes TLS groups supplied by its OpenSSL build. A compatible OpenSSL 3.5 configuration and client can enable hybrid PQ key establishment; successful negotiation must be verified.

Work to plan around it

Compose endpoint storage, identity, recipient protection, sharing and recovery around the server. Check the negotiated profile and authentication separately from key exchange.

Why evaluate 8DB

8DB brings protected local storage and authenticated PQ message exchange into the engine's supported node path, reducing the interfaces the application has to assemble.

MongoDB client-side field encryptionKeep protected fields unreadable to the server
What it provides

Encrypt selected fields in the client before the server receives them. This already addresses a real trust boundary.

Work to plan around it

Select fields and query behavior, provision keys, and connect protection to any local device database, sharing protocol and recovery workflow. Validate the complete cryptographic profile.

Why evaluate 8DB

8DB is a fit to examine when the application also needs a protected local database, recipient exchange and a common lifecycle for multiple data shapes.

SQLCipher / Couchbase LiteEmbedded storage or direct peer synchronization
What it provides

SQLCipher encrypts an embedded SQLite database. Couchbase Lite provides peer replication, conflict management and resilient synchronization. These are distinct products with different roles.

Work to plan around it

For a SQLCipher design, supply sharing and identity. For a Couchbase Lite design, check required PQ algorithms and intermediary trust. In either case, map migration and restored copies across the complete application.

Why evaluate 8DB

8DB's proposition combines protected storage, local authority and PQ exchange within one engine's supported paths. Compare the integration work and measured behavior of the actual deployment.

SurrealDBEmbedded deployment with multiple data models
What it provides

Combines multiple data models and an embedded deployment option. Model breadth and embeddability are established buying options.

Work to plan around it

Check which useful operations share the required protection, authority, exchange and recovery behavior in the chosen configuration.

Why evaluate 8DB

8DB connects its omnimodal architecture to its protected data lifecycle. The useful comparison is the supported workload your team can keep within that common foundation.

Architectural comparisons, reviewed September 2026. Capabilities depend on versions and configuration. This is a comparison of documented approaches, not an exhaustive PQC market ranking or matched performance benchmark.

06 / Follow the claim to its evidence

Inspect the path.
Define your evaluation.

Use the published work to choose a starting point. Then measure your data, devices and required guarantees together.

Questions that change the decision

Start with the practical questions.

Does this replace TLS?

Recipient-protected messages add protection inside the transport. TLS still has a useful role for the outer connection. A fair evaluation counts actual handshakes, connection reuse, encapsulation, signatures, payload bytes and durable receipt on both sides.

Does post-quantum protection have zero cost?

The measured same-cipher record has zero additional PQ ciphertext bytes before framing and metadata. Key establishment, signatures, envelopes and complete transfers have costs. Same-cipher timing observations do not establish zero overhead for an entire database or device.

Can it run across every data type and device today?

8DB publishes broad data representations and six operating-system targets. Qualification depends on the combination of operation, data schema, resource budget and protection profile. The reviewed integrated exchange currently admits canonical lexical records. Start an application evaluation with the actual workflow.

What about battery life, latency and operating cost?

Compare energy per completed job, peak memory, total stored and transmitted bytes, cold-start latency and sustained throughput under the same guarantees. Reducing separate services and copies can reduce operating work; no universal battery-life or total-cost saving is established by the current component measurements.

Does cryptographic inventory mean automatic compliance?

Dataset reports make cryptographic versions and managed-copy obligations inspectable. They support assessment. Certification, application controls and unmanaged historical copies require their own evidence.

From architecture to your application

Plan your
8DB evaluation.

Bring a workflow you need to protect. We’ll map a supported starting point and propose the tests that matter to your team.

Discuss your evaluation ↗Start with a non-sensitive description. No production data needed.
What we’ll work through with you
  1. Your protected routeData, devices, authorized readers and intermediaries.
  2. The fit and the gapsSupported combinations and what still needs qualification.
  3. A practical test planProtection, performance and recovery under your requirements.
Explore current qualification first ↗