KXCO Nexus

Signatures and data rooms that stay valid after today's cryptography is broken.

Two tools on one plan: quantum-safe e-signatures and NDA-gated data rooms, with a full record of who saw what, every signature and every page-view anchored on-chain.

Nexus puts e-signatures and secure data rooms on one plan. Sign contracts that are legally binding under ESIGN and eIDAS, share documents in NDA-gated view-only rooms with a full audit trail, and prove all of it on the KXCO Armature ledger. Verify seals and Identity credentials are included. It runs on NIST's post-quantum standard, so what you sign today still holds up decades from now.

Anyone can verify a signature or record without a KXCO account. The proof sits on Armature L1.

Live ML-DSA-65 · NIST FIPS 204 Anchored on Armature L1
issues authorizes logs produces anchors logs anchors resolves Identity Authority Audit log Record Signature Proof
In Practice

A private equity raise, start to finish.

The firm loads a data room and shares one link.

Each investor accepts the NDA before any document loads, then views the files.

The firm sees who opened what, page by page.

Terms are signed with signatures that stay valid for the life of the deal.

Every step is independently verifiable later, by anyone, with no KXCO account.

The Problem

Signing and sharing live in different tools, and none of it is quantum-safe.

Most teams sign in one product and share documents in another. The e-signature vendor holds the signature, a separate data room holds the files, and neither can prove much about the other. When you need to show a contract was signed by the right person and never altered, you are trusting whichever vendor happened to record it, and hoping they are still around when the proof is needed.

The cryptography under all of it is the cryptography quantum computers are expected to break. A signature that is valid today can be forged retroactively once that capability arrives, and adversaries are archiving signed documents now to do exactly that.

Nexus puts signing and data rooms on one trust model. Every signature and every document view is sealed with post-quantum cryptography and anchored on a public ledger, so anyone can check it directly, with no vendor in the middle.

Why It Matters

Built for the age of AI and quantum.

Quantum
Proof that outlives the algorithm
Every signature and seal uses ML-DSA-65 (NIST FIPS 204), so it stays valid after the deadlines that will retire today's cryptography. NIST published FIPS 203 and 204 in August 2024, new ECC and RSA procurement is restricted from 2026, RSA-2048 and ECC-256 are deprecated across US federal infrastructure by 2030, and CNSS Policy 15 requires full migration by 2035.
AI
Credentials for agents
Give an AI agent a scoped credential and it signs its own actions with its own key, every action tracing back to a human-accountable root identity. Authority is explicit, bounded, and can be revoked instantly and in isolation without disturbing anything else. Identity and permission only, never a black box acting on nobody's behalf.
Blockchain
A permanent, public anchor
Every seal and credential event is anchored on Armature L1, a permanent and independently verifiable record. Any counterparty, regulator or court can confirm a document existed, unaltered, at a point in time, with no KXCO account, no fee, and no dependency on KXCO continuing to operate.
The Tech

A hierarchy of trust, verifiable offline.

From an institution's root key to every credential, signature and audit entry it produces, verifiable without a network call or vendor dependency.

01
Root identity
The institution holds an ML-DSA-65 root key in its HSM. It never leaves the hardware. Every credential traces back to it.
02
KYC-gated credential issuance
After a user passes KYC, the institution issues a credential encoding role, authority, jurisdiction and expiry, a signed and logged institutional act.
03
Credentialed signing
The user, or an authorised agent, signs documents and transactions, producing a portable, self-contained ML-DSA-65 envelope tied to their credential.
04
Offline counterparty verification
Any counterparty verifies the full chain, from signature to credential to root, with no API, no vendor server, and no SLA dependency.
05
Tamper-evident audit log
Every issuance, signing, rotation and revocation appends to a hash-chained, signed log. Nothing can be altered or reordered without detection.
2024
NIST publishes FIPS 203 and 204. The standards are final. Migration begins.
2026
NSA mandates PQC for all new US national security systems. ECC and RSA forbidden for classified government procurement from this point.
2030
NIST deadline to deprecate RSA-2048 and ECC-256 across US federal infrastructure.
2035
NSA CNSS Policy 15: full migration of all classified systems without exception.
How A Data Room Works

Share confidential documents, and know exactly who saw what.

The same trust model, applied to sharing. Every room is view-only, gated by an NDA, and logged page by page on the ledger.

01
Create a private room
Name the room, upload your files, and set an optional access code. Documents are rendered to secure page images with download, copy, print and text selection disabled.
02
Invite by email, no account needed
Invite viewers individually or in bulk. Each gets a unique secure link, with nothing to install and no account to create. Rooms and invitations expire after seven days by default.
03
NDA gate before anything loads
Each viewer accepts a click-to-agree NDA addressed to you before a single document appears. Acceptance is captured with their typed name, email, time and an ML-DSA-65 proof, and a signed NDA certificate is emailed to both parties.
04
Engagement intelligence, page by page
See who opened the document, which pages they read and when. This is distribution intelligence, not just an audit trail: you know who is engaged before you follow up. The viewer stays locked, the page blurs when the tab loses focus, idle sessions time out, and any invitation can be revoked instantly.
05
Anchored on-chain
Every view and every NDA acceptance is anchored on Armature L1, a permanent, independently verifiable record of who accessed what, provable long after the deal closes.
What's Included

What you get with Nexus.

Two modules on one plan, with proof and identity built in. Use one, or use them together.

Module · Signing
Quantum-safe e-signatures
Sign any PDF or Word document with ML-DSA-65 (FIPS 204) signatures, sealed with on-chain attestation and public verification. Templates, multi-party signing, voiding and expiry are included. Legally binding under ESIGN and eIDAS.
Open Nexus →
Module · Data Rooms
Private rooms with engagement intelligence
View-only rooms with no download, copy or print. The page blurs when the tab loses focus and idle sessions time out. Invitees sign a post-quantum NDA before anything loads, you see who opened the document, which pages each viewer read and when, and the full trail is anchored on-chain.
Open a data room →
Data Rooms · Enterprise
One forwardable link, every viewer on record
Share a room with a single link people can forward. Everyone who opens it enters their name and email and signs the NDA before anything loads, each acceptance sealed with ML-DSA-65 and a certificate emailed to both parties. Every view and forward becomes a connected map of your deal, so you can see who is engaged and decide with better information.
Explore Master Data Room →
Included · Verify
Prove something is what it claims to be
A KXCO Verified seal is an ML-DSA-65 signature anchored on Armature L1, binding a domain, a document's hash, or an article to its author and publication. Included in every plan.
See verification →
Included · Identity
Institutional identity, verifiable by anyone
A hierarchy of trust from an institution's root key to every credential it issues, a permanent ID for people, businesses and AI that anyone can check offline, with no central database to hack or switch off. It is also the foundation AI agents use to act under authority.
Explore identity →
Who It's For

Anywhere the proof has to last.

Nexus serves anyone who needs signing and document sharing that hold up to scrutiny, today and after the cryptographic deadlines.

Banks & custodians Law firms Hedge funds Regulated institutions Businesses signing contracts Publishers & authors AI agents acting under authority

Put quantum-safe proof under everything you sign and share.

Start with a pilot. Open one data room, or run one signing workflow, and see it hold up before rolling it out across the institution.