MirCrypt — Product · Annual managed service

MirCrypt

Post-quantum encryption for PostgreSQL, with dedicated annual support

A database is not safe forever: data encrypted today with classic algorithms (RSA, ECC) could be decrypted by tomorrow's quantum computers — this is the "Harvest Now, Decrypt Later" risk. MirCrypt is Miriade's annual support for Pg_vault, the PostgreSQL extension that encrypts data with keys designed to withstand quantum attacks. We guide you through installation, secure key management and long-term maintenance — with the key always and exclusively in your hands.

At a glance

The product in a nutshell

What it is
Miriade's annual support for Pg_vault, the PostgreSQL extension that encrypts data with keys resistant to quantum computers.
Type
Product / Managed Service — annual coverage of a single database.
Tiers
Two: Base and Advanced.
When you need it
Confidential, long-lifecycle data on PostgreSQL, or the wish to get ahead of the post-quantum transition.
Scope
Post-quantum encryption, keystore, key management, table- or column-level granularity.
Data sovereignty
The key always remains exclusively the customer's: Miriade neither stores it nor accesses it.
What it solves

Protecting data even from the quantum tomorrow

Many organisations store data on PostgreSQL that must stay confidential for years or decades — healthcare, financial, industrial, public-sector. MirCrypt addresses the concrete risks of this scenario.

"Harvest Now, Decrypt Later": data encrypted today with classic algorithms, intercepted and decrypted tomorrow with quantum computers.
Non-granular encryption: encrypting the whole database is expensive; MirCrypt encrypts the individual table (or column) based on real criticality.
Keys and sovereignty: entrusting the key to third parties creates risk; here it stays with the customer alone — on Vault, OpenBao, local or HSM.
Installation prone to error: a misconfigured extension can lose the key or degrade performance.
Long-term maintenance: it is not "install and forget"; it needs updates, bug support and evolution over the years.
No in-house skills: managing keystore, key rotation and updates requires dedicated expertise.
What's included

From design to continuity

Assessment & design

Analysis of the PostgreSQL environment and architectural design of the Pg_vault installation, identifying critical tables and columns.

Installation & configuration

Installation and configuration of the extension and related architectures (e.g. keystore), validated by Miriade.

Key provisioning & management

Generation and secure management of the encryption key, owned exclusively by the customer. No key is stored by Miriade.

Selective activation

Encryption enabled at single-table level or, in the Advanced tier, single-column level, based on real criticality.

Support & updates

Direct bug support and extension updates planned and applied by Miriade.

Rotation & customisation

Periodic key rotation and on-request customisation: dedicated keystores, HSM, custom algorithms or formats.

The two tiers

Base or Advanced

Both delivered as active annual support on a single database. To protect multiple databases you need multiple subscriptions, one per database.

Comparison of the two support tiers
Scope MirCryptBase MirCryptAdvanced
Coverage A single database, annual support A single database, annual support
Assessment and design Performed by Miriade Performed by Miriade
Installation Performed and validated by Miriade Performed and validated by Miriade
Supported keystores HashiCorp Vault, OpenBao, local On customer request, including HSM
Encryption granularity Table Table or column
Key management Handled by the customer + Miriade best practices Full governance with Miriade
Key rotation Handled by the customer Full governance with Miriade
Encryption algorithm Standard post-quantum Post-quantum, with a custom fork
Support and bugs 8x5, via ticket 8x5, via priority ticket
Updates Planned and applied by Miriade Planned and applied by Miriade
Long term support Included in the annual renewal Maintenance even beyond 5 years
Best suited for Technical teams that want to adopt encryption safely Enterprise contexts or highly critical data
How it works

The path, step by step

1

Assessment and architectural design

Analysis of the PostgreSQL environment (on-premise, cloud or hybrid), identification of critical tables and columns, performance testing and definition of the most secure configuration.

2

Installation

Installation of the extension and supporting components (e.g. keystore), with correct key storage.

3

Key provisioning

Generation of the encryption key, owned exclusively by the customer. No key is stored by Miriade.

4

Selective activation

Encryption enabled at single-table level (Base) or single-column level (Advanced), according to real protection needs.

5

Transparent operation

Encrypted data is transparently readable and writable by whoever holds the key; unreadable to anyone else, including the system administrator.

6

Support, rotation and long term support

Direct bug assistance, periodic key rotation and updating of the extension over time; in the Advanced tier, maintenance even beyond 5 years.

The one certainty

The key always in your hands

The encryption key remains always and exclusively the customer's: Miriade neither stores it nor accesses it.

The extension is developed in-house by Miriade and released to the open-source community: no lock-in, no dependence on closed proprietary solutions. The cryptographic perimeter and the level of control over the key (up to a dedicated fork with HSM) are defined together with your security team during the assessment.

Related to

In the context of data security

Not on PostgreSQL yet? With DBPorter, Miriade automatically converts your database's structure and code to PostgreSQL, as a first step towards adopting MirCrypt.

FAQ

Frequently asked questions

Do I have to choose the Advanced tier to protect sensitive data?

No. The Base tier already covers table-level encryption with a standard keystore. The Advanced tier is for column-level granularity, a dedicated fork or custom configurations.

Can I protect multiple databases with a single subscription?

No: each subscription (Base or Advanced) covers a single database for one year. Multiple databases require multiple subscriptions.

Who owns the encryption key?

Always and exclusively the customer. Miriade never stores it or accesses it at any time.

Can I move from Base to Advanced later on?

Yes, at annual renewal or, in some cases, during the subscription, subject to a technical assessment.

What if I'm not on PostgreSQL yet?

Miriade provides DBPorter to automatically migrate your database's structure and code to PostgreSQL, as a first step towards MirCrypt.

What does "post-quantum" mean?

The keys are designed to withstand attacks from future quantum computers, anticipating the standards defined by NIST and protecting long-lifecycle data.

Want to protect your PostgreSQL data with post-quantum encryption?

Let's assess together which MirCrypt tier best fits your database and your security requirements.

Request a MirCrypt assessment

Encrypt your data quantum-proof

Tell us which critical data you keep on PostgreSQL and your security requirements: together we'll assess which MirCrypt tier best fits your database.

Post-quantum encryption at table or column level.
The key always and only yours: Vault, OpenBao, local or HSM.
Annual support: installation, updates, rotation.

We use the data you submit only to get back to you about this request.