PARAMANT
Post-Quantum Ghost Pipe · Press Kit
About
PARAMANT is a post-quantum encrypted file relay built for regulated industries. Files are encrypted client-side before upload, on the authenticated paths with an ML-KEM-768 and ECDH P-256 hybrid, stored in RAM only, and destroyed after the link's last read, the first on Community. Nothing is written to disk. EU/DE jurisdiction. Self-hostable. NIS2, NEN7510, and IEC 62443 ready.
PARAMANT Ghost Pipe is a post-quantum encrypted relay that makes secure file transfer genuinely simple. Data is encrypted in the browser or SDK using ML-KEM-768 + AES-256-GCM — before it leaves the device. The relay only ever sees fixed-size (5 MB) ciphertext blobs, never the original file, never a decryption key. Blobs are held in RAM and destroyed immediately after the recipient downloads them. There is no storage, no inbox, no user account. Every transfer is recorded in a public SHA3-256 Merkle tree — proving delivery without storing content. Five live sector relays cover healthcare (NEN 7510), legal (eIDAS), finance (DORA), industrial IoT (IEC 62443), and general use. Community Edition is free forever for up to 5 API keys. The relay runs on a Raspberry Pi, a VPS, or as a bootable USB — no cloud dependency required.
PARAMANT Ghost Pipe is a post-quantum secure file relay designed for healthcare providers, legal professionals, industrial operators, and financial institutions operating under strict data sovereignty requirements. It solves a specific problem: sending sensitive files between parties where neither party trusts the relay — and where the jurisdiction of storage matters.
The system is built around three hard guarantees. First, encryption is purely client-side: files are encrypted using ML-KEM-768 key encapsulation and AES-256-GCM symmetric encryption inside a Rust/WASM module that runs in the browser, before any data leaves the device. Second, the relay is RAM-only: encrypted blobs are never written to disk, making forensic recovery impossible. Third, burn-on-read: each blob is destroyed after the last read its link allows, which on the Community plan is the first successful download. The relay cannot be compelled to hand over content it no longer holds.
PARAMANT runs five sector relays, each tuned to its compliance domain: health (NEN 7510, HL7 FHIR, DICOM), legal (eIDAS, KNB), finance (NIS2, DORA, ISO 20022), industrial IoT (IEC 62443, EU CRA), and general. Each sector is a separate container — a breach in one does not expose another.
Deployment takes two minutes: one docker compose command on any Ubuntu 22.04+ server. A Raspberry Pi installer and a bootable NixOS image (paramantOS) are available for dedicated hardware. The community edition is permanently free for up to 5 API keys per relay instance.
PARAMANT was independently security-audited in April 2026 by Ryan Williams (Smart Cyber Solutions, AU) and R. Zwarts. Forty findings across three audits, including 4 critical. Every finding and its status is publicly documented.
Incorporated in the Netherlands. Infrastructure on Hetzner Nuremberg, DE. EU/GDPR jurisdiction only, no US CLOUD Act exposure.
Key facts
- Founded
- 2025
- HQ
- Netherlands / EU
- Infrastructure
- Hetzner Nuremberg, DE — EU only
- Jurisdiction
- EU/DE · GDPR · no US CLOUD Act
- Version
- v3.0.0 (May 2026)
- Live relays
- 5 (relay · health · finance · legal · iot)
- Encryption
- ML-KEM-768 + AES-256-GCM (NIST FIPS 203 / SP 800-38D)
- Audit
- April 2026 — findings and their status publicly documented
- License
- BUSL-1.1 — source available, free ≤ 5 keys
- Contact
- privacy@paramant.app
What makes PARAMANT different
- No plaintext, ever. Encryption happens on your own machine before upload, in Rust compiled to WASM on the hybrid path and in Web Crypto on the link path. The relay cannot read your file, not even under court order, because it never had it.
- Burn-on-read, and a ceiling. A blob is destroyed when the last read its link allows is spent, which on Community is the first one. It is destroyed on a timer too if that read never comes: one hour on Community, twenty-four hours on Firm, seven days on Enterprise. Whichever comes first, an attacker who compromises the relay afterwards finds nothing.
- EU jurisdiction by design. Infrastructure is on Hetzner Nuremberg DE, and no US entity ever holds ciphertext or a key. One sub-processor is American: Resend Inc. sends transactional email under Standard Contractual Clauses, as the DPA states. No CLOUD Act exposure for transfer content. GDPR-compliant by architecture, not by policy.
- Sector compartmentalisation. Five separate relay containers — healthcare, legal, finance, IoT, general. A breach or subpoena targeting the finance relay cannot reach health data.
- Post-quantum now, not later. ML-KEM-768 (NIST FIPS 203) protects against store-now-decrypt-later attacks. Healthcare data sent today cannot be decrypted by a quantum computer in 2030.
Logo & brand assets
Use PARAMANT brand assets only in editorial/press contexts. Do not modify the logo or use it to imply endorsement without written permission.
SVG available on request: privacy@paramant.app
Screenshots & product images
Press contact
Email: privacy@paramant.app
Response time: 24 hours (EU business hours)
Available for: product demos, technical briefings, compliance review calls, researcher access