Practice statement for the RFC 3161 timestamping service.
Version 1.0 · Effective 1 September 2026 · Governed by the laws of England and Wales
Nature of this document
This is the Time-Stamp Authority Practice Statement for the service described in the TSA disclosure statement. The disclosure is the short public notice. This file is the longer account of how that service is run.
The section order follows the topics a practice statement would need if a separate legal person later sought qualified electronic time-stamps under Regulation (EU) No 910/2014 and ETSI EN 319 401 / EN 319 421. Using that order now means the operational facts are already written down. It is not a claim that the present service is qualified, assessed, or listed.
BeatQuantum Limited is the operator of the current service. A qualified service, if ever established, would be a different legal person with its own practice statement, its own TSU certificates, and its own entry on a trusted list. This document would be a template, not that statement.
Document Information
| Document title | BeatQuantum Time-Stamp Authority Practice Statement |
|---|---|
| Version | 1.0 |
| Effective date | 1 September 2026 |
| Issuing organisation | BeatQuantum Limited (trading as “BeatQuantum”) |
| Governing law | The laws of England and Wales |
| Jurisdiction | The courts of England and Wales |
| This document's URL | https://beatquantum.com/tsa-ps |
| Disclosure statement | https://beatquantum.com/tsa |
| Status page | https://beatquantum.com/status |
| Contact | contact@beatquantum.com |
1. Relationship to other documents
The Certificate Practice Statement governs X.509 certificate issuance under roots R1 and R2. It does not govern this TSA. Root R3 and every certificate under it exist only for timestamping.
Where this statement and the disclosure disagree, the disclosure controls what is promised to subscribers and relying parties. This statement adds operational detail. It does not add warranty or liability.
2. Identification
Two policies are supported. Each has its own OID under BeatQuantum's IANA Private Enterprise Number 66626. These are BeatQuantum policies. They are not the ETSI best-practices time-stamp policy (BTSP).
| Profile | Policy OID | TSU algorithm | Endpoint |
|---|---|---|---|
| CNSA 2.0 | 1.3.6.1.4.1.66626.1.1 |
ML-DSA-87 | https://tsa.beatquantum.com/cnsa |
| SLH-DSA | 1.3.6.1.4.1.66626.1.2 |
SLH-DSA-SHA2-256f | https://tsa.beatquantum.com/eu |
The path /eu is a stable identifier for the SLH-DSA profile. It does not denote an EU qualified service.
3. Service practices
- Protocol: RFC 3161 over HTTPS. Request
application/timestamp-query, responseapplication/timestamp-reply. - Accepted hash algorithms: SHA-256, SHA-384, SHA-512. SHA-1 and MD5 are rejected.
- A nonce in the request is echoed unchanged.
- The token does not name the requester. The service does not require an account.
- If the clock is outside policy offset, or the primary time source is older than policy age, the responder refuses the request rather than sign.
A qualified service under EN 319 421 would keep this list and add the accuracy figure printed in every token, the expected lifetime of the TSU signature, and any restriction on use (for example, signatures only). Those extras are not asserted here beyond what the disclosure already says: declared accuracy is tighter than one second relative to the time sources in Section 4.
4. Time source
Primary time comes from BeatQuantum's post-quantum-authenticated NTS source. It is cross-checked against at least two independent external NTS or NTP sources. A fault in the primary source is detected rather than silently trusted.
Clock offset, loss of synchronisation, and recovery are written to the issuance log. A qualified practice statement would name the UTC reference, the measurement method, and the audited accuracy bound. This service records offset per token and fails closed. It does not publish a laboratory calibration report.
5. Certificates and keys
R3 is an SLH-DSA-SHA2-256s root used only for this TSA. Each profile has its own intermediate, issuing CA, and TSU. Validity periods are in the disclosure statement. TSU certificates carry critical EKU id-kp-timeStamping only and are issued for three years.
R3's private key is offline, encrypted, and not resident on a BeatQuantum server. Intermediate and issuing keys are encrypted at rest under dual control and are held off the network-facing responder. TSU keys are generated and used under dual control and are used only to sign time-stamp tokens. No key in this hierarchy is sent over a network in unencrypted form.
RFC 3161 does not require a certified hardware module. This service does not claim one. A qualified service would state the module, the certification, and the dual-control procedure against EN 319 401.
6. Revocation and certificate status
Status for TSU, issuing-CA, and intermediate certificates is published as CRLs on HTTP port 80. This TSA does not run OCSP on the R3 hierarchy. A root is not revoked by CRL; untrusting R3 means removing it from the verifier's trust store. Compromise or revocation of R3 is announced at beatquantum.com/status.
| Issuer | CRL |
|---|---|
| R3 | http://crl.beatquantum.com/tsa-root.crl |
| CNSA 2.0 intermediate | http://crl.beatquantum.com/tsa-intermediate-cnsa.crl |
| SLH-DSA intermediate | http://crl.beatquantum.com/tsa-intermediate-eu.crl |
| CNSA 2.0 issuing CA | http://crl.beatquantum.com/tsa-issuing-cnsa.crl |
| SLH-DSA issuing CA | http://crl.beatquantum.com/tsa-issuing-eu.crl |
If a TSU private key is compromised, that TSU certificate is revoked with reason keyCompromise. Tokens after the revocation time should be rejected. Tokens before it may still be accepted where the relying party treats revocation time as the cut-off, which is the RFC 3161 model when a reason code is present.
A qualified practice statement would also say how long CRLs remain available after a TSU certificate expires, because long-term verification needs status history, not only a live endpoint.
7. Logging and privacy
Per token the service records serial number, asserted time, policy OID, hash algorithm, message imprint, nonce presence, token size, and measured clock offset. Each responder start records the TSU subject, SHA-256 fingerprint, and expiry. Rejected requests are logged with the reason. Requester identity and IP address are not recorded.
The record is flushed to disk before the token is returned. The log is append-only at the filesystem. Retention is seven years beyond expiry of the signing certificate that produced the record. Within that period records may move to offline storage and remain available on legitimate legal demand.
8. Verification by relying parties
Published chains and the openssl cms -verify recipe are in the disclosure statement. That command checks the signature, the chain to R3, and id-kp-timeStamping. It does not fetch a CRL. A party that wants current status applies the CRLs in Section 6 at the time they care about.
Verification of a token is against validity at the time asserted in the token, not against whether the TSU certificate is still in its validity period today.
9. Termination
If this TSA is withdrawn, BeatQuantum will revoke unexpired TSU certificates, publish the fact at beatquantum.com/status, and keep already-issued tokens and the issuance log for the retention period in Section 7. TSU private keys used by the withdrawn service will not be used to issue new tokens.
A qualified practice statement would add destruction of key material, notice to the supervisory body, and the period for which CRLs stay downloadable after termination.
10. Liability and law
Liability, the "as is" terms, governing law, and the amendment rules are those in the TSA disclosure statement. This practice statement does not vary them.
11. Amendments
The version number and effective date in the Document Information table change with each amendment. Material amendments are announced at beatquantum.com/status with at least seven days' notice, except security amendments, which take effect on publication.
Questions
Contact contact@beatquantum.com. Service status: beatquantum.com/status. Public disclosure: beatquantum.com/tsa. Certificate issuance under R1 and R2: Certificate Practice Statement.
Prove first, speak later.
The short public notice is the disclosure statement. This file is how the service is actually run.
TSA disclosure →