Compliance & Security Standards
Security by Design
Quasar was engineered to bypass traditional cloud vulnerabilities by returning full data sovereignty to the user. This page outlines the cryptographic standards deployed within the software.
1. Cryptographic Standards
Data at Rest (SQLcipher): All local SQLite databases are encrypted at rest using SQLcipher, ensuring physical device compromise does not result in a data breach.
Data in Transit (XChaCha20-Poly1305): Cloud syncing utilizes strict end-to-end encryption. Payloads are encrypted client-side using XChaCha20-Poly1305 authenticated encryption, rendering intercepted data or server-side breaches mathematically useless to attackers.
Key Derivation (Argon2id): Quasar utilizes Argon2id, the industry-leading memory-hard key derivation function, to secure local databases against brute-force attacks.
License Signing (Ed25519): Software authorization is verified via mathematically signed, airgapped Ed25519 public-key cryptography, eliminating the need for constant "phone-home" DRM authentication.
2. Privacy by Design (GDPR/CCPA Alignment)
While Noria Ltd (BRN: I12010154) operates from Mauritius, Quasar inherently complies with the strictest global data protection frameworks through its architecture:
- Data Minimization: We collect zero telemetry and hold zero encryption keys.
- Right to be Forgotten: You maintain absolute digital control over your database. Deleting the application and its local directory permanently wipes your records.