OrcaRouter Encrypts Request Logs With Post-Quantum Cryptography at No Extra Cost
Encrypting request log bodies before storage means a leaked database replica, snapshot, or backup yields ciphertext rather than prompts and credentials, which is the point of naming the harvest now, decrypt later threat explicitly.
Reporting from 1 source: ASCII.jp.
FlashLabs says its Japanese-market AI inference gateway OrcaRouter now encrypts the body of request logs with post-quantum cryptography as standard, with no opt-in and no extra charge, and not limited to the Enterprise plan. The companion implementation, scuttle, was released as open source under the Apache-2.0 license. The stated threat is harvest now, decrypt later.
Log bodies are encrypted before they are written to storage, so a leaked replica, snapshot, or backup does not expose their contents. Data encryption uses AES-256-GCM with a separate key generated for each item, and long-term stored keys are protected by a hybrid of post-quantum ML-KEM-768 and the existing X25519. The application that writes logs receives only a public capture key that can encrypt new logs but cannot use that key to decrypt past logs.
The encryption layer scuttle was released as open source under the Apache-2.0 license, with its code, specification, threat model, attack surface, and fuzzing targets public. FlashLabs says nine types of automated fuzzing tests ran tens of millions of executions before release and that the two defects found were fixed before release. Two internal reviews took place; no third-party audit has been conducted. Reports are accepted via GitHub's private channel and email.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.