smshPQTM brings ML-DSA-65 signed statements to pilot inference integrations. Retained operator envelopes pass local lattice-signature checks. That authenticates signed bytes, not model execution or every call in a workload. Validate the selected endpoint, trusted key and capture path before relying on a deployment.
A sufficiently capable quantum computer could undermine Ed25519 and ECDSA authenticity by enabling forgery. Existing signatures do not universally stop verifying in a particular year. ML-DSA is designed for post-quantum authenticity, not encryption. Harvest-now-decrypt-later concerns encrypted content and key establishment, which a signature alone does not protect. NIST FIPS 204 defines ML-DSA.
afir.attestation / 1.0.0-typed-pq artifacts measured 11,532, 76,325 and 22,232 bytes as stored complete JSON bundles. Their compact envelope objects were 8,057, 8,057 and 10,865 UTF-8 bytes; compact {envelope, fragments} verification bodies were 8,495, 8,495 and 13,950 bytes, including encoded signatures and keys but excluding HTTP/TLS overhead. These are sample-specific measurements, not a fixed product receipt size. The former 384-byte claim had no matching wrapper, digest-only object or amortized artifact in the reviewed implementation.
Estimate cache and routing effects using your assumptions, not guaranteed savings. Routing applies only to traffic left after caching. The model assumes uniform tokens and cost per call, full inference-cost avoidance on cache hits, and one receipt per original call. Add cache serving, selection, retries, storage and other monthly operating costs below. One-time implementation cost, taxes and quality changes are excluded. Confirm pricing and workload quality in a pilot.
A signature authenticates the statement the signer made. Cache eligibility, routing quality, payment status and model execution need their own evidence. A receipt helps preserve those assertions without making them true by itself.
A matching digest can bind the exact inputs defined by your cache key. Safe reuse also depends on model version, parameters, freshness and authorization. Payment requires a separately bound settlement record.
A signed model identifier is the signer's assertion about the model. Stronger execution claims require an identified provider or hardware attestation and verification of its binding to the call. Compare answer quality and full routing costs separately.
Signed receipts can support an audit alongside access controls, capture monitoring, retention and recovery evidence. A digest can limit content disclosure but does not encrypt data or establish regulatory approval.
The reviewed typed signer places a full base64 signature in envelope.envelope_signature. It signs a 32-byte digest binding base envelope fields, the selected-fragment aggregate root and policy digest. The retained artifacts use linear aggregation within each envelope, not a detached or shared signature across inference calls. Verification needs the envelope, canonical fragment inputs, exact digest framing, ML-DSA-65 implementation and an independently trusted public key. See endpoint capabilities.
Bring call volume, model mix and non-sensitive workload requirements. Scope capture coverage, cache eligibility, routing quality, storage and verification tests before sending production data.
Book the pilot scoping callThe cards distinguish live service records from bundled fallback data. A metric that rewards signature presence against an unsigned baseline demonstrates a feature, not competitive performance. This display does not authenticate the issuer or reproduce the run. Read the methodology and limitations.