MirCrypt
Post-quantum encryption for PostgreSQL, with dedicated annual support
A database is not safe forever: data encrypted today with classic algorithms (RSA, ECC) could be decrypted by tomorrow's quantum computers — this is the "Harvest Now, Decrypt Later" risk. MirCrypt is Miriade's annual support for Pg_vault, the PostgreSQL extension that encrypts data with keys designed to withstand quantum attacks. We guide you through installation, secure key management and long-term maintenance — with the key always and exclusively in your hands.
The product in a nutshell
- What it is
- Miriade's annual support for Pg_vault, the PostgreSQL extension that encrypts data with keys resistant to quantum computers.
- Type
- Product / Managed Service — annual coverage of a single database.
- Tiers
- Two: Base and Advanced.
- When you need it
- Confidential, long-lifecycle data on PostgreSQL, or the wish to get ahead of the post-quantum transition.
- Scope
- Post-quantum encryption, keystore, key management, table- or column-level granularity.
- Data sovereignty
- The key always remains exclusively the customer's: Miriade neither stores it nor accesses it.
Protecting data even from the quantum tomorrow
Many organisations store data on PostgreSQL that must stay confidential for years or decades — healthcare, financial, industrial, public-sector. MirCrypt addresses the concrete risks of this scenario.
From design to continuity
Assessment & design
Analysis of the PostgreSQL environment and architectural design of the Pg_vault installation, identifying critical tables and columns.
Installation & configuration
Installation and configuration of the extension and related architectures (e.g. keystore), validated by Miriade.
Key provisioning & management
Generation and secure management of the encryption key, owned exclusively by the customer. No key is stored by Miriade.
Selective activation
Encryption enabled at single-table level or, in the Advanced tier, single-column level, based on real criticality.
Support & updates
Direct bug support and extension updates planned and applied by Miriade.
Rotation & customisation
Periodic key rotation and on-request customisation: dedicated keystores, HSM, custom algorithms or formats.
Base or Advanced
Both delivered as active annual support on a single database. To protect multiple databases you need multiple subscriptions, one per database.
| Scope | MirCryptBase | MirCryptAdvanced |
|---|---|---|
| Coverage | A single database, annual support | A single database, annual support |
| Assessment and design | Performed by Miriade | Performed by Miriade |
| Installation | Performed and validated by Miriade | Performed and validated by Miriade |
| Supported keystores | HashiCorp Vault, OpenBao, local | On customer request, including HSM |
| Encryption granularity | Table | Table or column |
| Key management | Handled by the customer + Miriade best practices | Full governance with Miriade |
| Key rotation | Handled by the customer | Full governance with Miriade |
| Encryption algorithm | Standard post-quantum | Post-quantum, with a custom fork |
| Support and bugs | 8x5, via ticket | 8x5, via priority ticket |
| Updates | Planned and applied by Miriade | Planned and applied by Miriade |
| Long term support | Included in the annual renewal | Maintenance even beyond 5 years |
| Best suited for | Technical teams that want to adopt encryption safely | Enterprise contexts or highly critical data |
The path, step by step
Assessment and architectural design
Analysis of the PostgreSQL environment (on-premise, cloud or hybrid), identification of critical tables and columns, performance testing and definition of the most secure configuration.
Installation
Installation of the extension and supporting components (e.g. keystore), with correct key storage.
Key provisioning
Generation of the encryption key, owned exclusively by the customer. No key is stored by Miriade.
Selective activation
Encryption enabled at single-table level (Base) or single-column level (Advanced), according to real protection needs.
Transparent operation
Encrypted data is transparently readable and writable by whoever holds the key; unreadable to anyone else, including the system administrator.
Support, rotation and long term support
Direct bug assistance, periodic key rotation and updating of the extension over time; in the Advanced tier, maintenance even beyond 5 years.
The key always in your hands
The encryption key remains always and exclusively the customer's: Miriade neither stores it nor accesses it.
The extension is developed in-house by Miriade and released to the open-source community: no lock-in, no dependence on closed proprietary solutions. The cryptographic perimeter and the level of control over the key (up to a dedicated fork with HSM) are defined together with your security team during the assessment.
In the context of data security
Data Governance & Quality
Data Catalog, Lineage and Data Masking: knowing which data to protect, before encrypting it.
Service · ControlDevSecOps & DataSecOps
Security built into pipelines and data, of which encryption is one piece.
Service · ControlDatabase Managed Service (MirDB)
The continuous managed service for databases, MirCrypt's twin on the management side.
Not on PostgreSQL yet? With DBPorter, Miriade automatically converts your database's structure and code to PostgreSQL, as a first step towards adopting MirCrypt.
Frequently asked questions
Do I have to choose the Advanced tier to protect sensitive data?
No. The Base tier already covers table-level encryption with a standard keystore. The Advanced tier is for column-level granularity, a dedicated fork or custom configurations.
Can I protect multiple databases with a single subscription?
No: each subscription (Base or Advanced) covers a single database for one year. Multiple databases require multiple subscriptions.
Who owns the encryption key?
Always and exclusively the customer. Miriade never stores it or accesses it at any time.
Can I move from Base to Advanced later on?
Yes, at annual renewal or, in some cases, during the subscription, subject to a technical assessment.
What if I'm not on PostgreSQL yet?
Miriade provides DBPorter to automatically migrate your database's structure and code to PostgreSQL, as a first step towards MirCrypt.
What does "post-quantum" mean?
The keys are designed to withstand attacks from future quantum computers, anticipating the standards defined by NIST and protecting long-lifecycle data.
Want to protect your PostgreSQL data with post-quantum encryption?
Let's assess together which MirCrypt tier best fits your database and your security requirements.
Encrypt your data quantum-proof
Tell us which critical data you keep on PostgreSQL and your security requirements: together we'll assess which MirCrypt tier best fits your database.
We use the data you submit only to get back to you about this request.