Current operational status of infrastructure and the certificate authority.
Root certificates, service status, and material announcements.
Announcements
3 August 2026 — CPS v1.2 published (BeatQuantum incorporated). BeatQuantum Limited was incorporated on this date. Concurrently, the Certificate Practice Statement has been refreshed and published as version 1.2, effective 3 August 2026. The document is available at beatquantum.com/cps.
Certificates
The following root CA certificates are currently valid and have not been revoked. If any of these certificates are compromised or revoked, this section will be updated immediately with details of the affected certificate, the nature of the compromise, and the steps subscribers and relying parties should take.
BeatQuantum Labs Root CA R1 — Option A (Pure Post-Quantum)
Status: Valid
| Algorithm | ML-DSA-87 (FIPS 204) |
|---|---|
| Valid until | 4 May 2046 GMT |
| SHA-256 Fingerprint | AF:54:D7:15:0C:0A:4D:5A:4B:B7:A2:E3:7B:85:A5:7A:2E:DB:A9:02:01:FA:A2:A7:F1:87:07:87:F6:7E:41:22 |
| CRL | http://crl.beatquantum.com/root.crl |
| Download | beatquantum-root-r1.crt |
Verify the SHA-256 fingerprint before installing this certificate into any trust store. On Linux and macOS: openssl x509 -in beatquantum-root-r1.crt -noout -fingerprint -sha256
BeatQuantum Labs Root CA R2 — Option B (Hybrid Post-Quantum)
Status: Valid
| Algorithm | SLH-DSA-SHA2-256s (FIPS 205) |
|---|---|
| Valid until | 4 May 2046 GMT |
| SHA-256 Fingerprint | FA:59:7E:38:62:7C:95:E4:39:98:67:0F:5E:2B:2A:B6:9A:72:03:A3:F5:81:0F:73:88:FF:E1:E9:EC:D8:91:AC |
| CRL | http://crl.beatquantum.com/root-b.crl |
| Download | beatquantum-root-r2.crt |
Verify the SHA-256 fingerprint before installing this certificate into any trust store. On Linux and macOS: openssl x509 -in beatquantum-root-r2.crt -noout -fingerprint -sha256
Systems
Current operational status of BeatQuantum services. All TLS-based services negotiate post-quantum hybrid and pure post-quantum key exchange.
| Service | Description | Status |
|---|---|---|
| Web Server | beatquantum.com — HTTPS | Operational |
| SMTP | Inbound and outbound mail (STARTTLS and SMTPS) | Operational |
| IMAP / POP3 | Mailbox access (STARTTLS, IMAPS, POP3S) | Operational |
| VPN | Virtual private network (OpenVPN) | Operational |
| IKEv2 / IPsec | Hybrid post-quantum key exchange (RFC 9370, ML-KEM) | Operational |
| WireGuard | Virtual private network | Operational |
| DoH | DNS over HTTPS (RFC 8484) | Operational |
| DoT | DNS over TLS (RFC 7858) | Operational |
| DoQ | DNS over QUIC (RFC 9250) | Operational |
| NTS | Network Time Security (RFC 8915), post-quantum NTS-KE | Operational |
| LDAP | Directory service (STARTTLS and LDAPS) | Operational |
| PostgreSQL | Database over TLS | Operational |
| MariaDB | Database over TLS | Operational |
| Syslog | Log collection over TLS (RFC 5425) | Operational |
Status indicators are currently updated manually. Automated monitoring integration is planned for a future release.
Prove first, speak later.
For the full operational and legal framework, see the Certificate Practice Statement.
View the CPS →