
Technology
Trust begins in silicon
The SEALCOIN platform combines secure hardware, PKI, post-quantum cryptography and a distributed ledger so machines can transact autonomously, without a central authority or human intervention. Together they form the foundation for Quantum AI Transactions (QAIT).
SEALCOIN ecosystem
Six core technologies working together
Post-quantum cryptography sits at the centre, because every other layer relies on identities that must stay trustworthy for a device’s whole service life.
Quantum-safe
Post-Quantum Cryptography (PQC)
Quantum-resistant algorithms protect device identities, signatures and key exchange, so what SEALCOIN issues today is not exposed when large quantum computers arrive.
Hardware Root of Trust
SEALSQ secure elements generate and store private keys inside the chip. Keys never leave the hardware, which makes device identities impossible to copy in software.
Public Key Infrastructure (PKI)
WISeKey PKI creates and assigns a unique digital identity, a certificate, to every connected device or agent, and manages it through its whole lifecycle.
Elliptic Curve Cryptography (ECC)
Efficient authentication of devices and transactions for resource-constrained IoT hardware, used alongside PQC.
Distributed Ledger (Hedera)
Hedera provides fast, low-cost and tamper-proof records of every transaction, with enterprise-grade security and energy-efficient consensus.
Non-Custodial Wallets
Owners keep full control of their QAIT and private keys. No third party can move a device’s funds.
Why post-quantum, why now
Machine identities outlive today’s cryptography
A smart meter, a vehicle or an industrial controller can stay in service for ten to twenty years. Attackers can record signed traffic and certificates today and wait until a quantum computer can break classical keys. This is called “harvest now, decrypt later”.
SEALCOIN protects identities with post-quantum cryptography from the moment a device is provisioned, so a device shipped this year does not become a liability later in its life.
Illustrative timeline. When classical keys become breakable is uncertain; the exposure window is shown as a range, not a date.
Security stack
A hardware-rooted stack from silicon to autonomous transactions
Click a layer to see what it does and which part of the WISeKey Group provides it.
Autonomous Transactions
Machines negotiate, execute and settle service-for-payment exchanges on their own, within the rules their owners set, with QAIT as the settlement token on Hedera.
SEALCOIN transaction engine · Hedera · QAIT
Service Discovery
Authenticated machines find trusted services, prices and counterparties through broker nodes, even from behind firewalls and carrier networks.
SEALCOIN broker nodes
Machine Authentication
Before any exchange, machines prove who they are to each other with their certificates. Unknown or revoked devices are refused automatically.
SEALCOIN platform
PQC Identity
Each device and agent receives a certificate-based identity protected with post-quantum cryptography, so identities issued today stay trustworthy through the device’s whole service life.
WISeKey PKI + post-quantum cryptography
Hardware Root of Trust
Keys are generated and stored inside a secure element at manufacturing. They never leave the chip, so a device cannot be cloned or impersonated in software.
SEALSQ secure hardware
Platform architecture & key features
Three layers, one connected infrastructure
Industries bring their own logic. SEALCOIN supplies the platform and the trust infrastructure underneath. Click any module to see what it does.
Industry Applications
SEALCOIN Platform
Trust Infrastructure

Platform walkthrough: devices, certificates, wallet and transactions
See it working
From enrolment to first payment in the SEALCOIN platform
The walkthrough shows how an operator enrols devices, assigns certificates, funds a wallet and follows transaction operations in real time.
Streamlined user onboarding
KYC through the WISeID platform, with role-based access for professional and individual users. Phased activation: B2B first, then B2C.
Device onboarding & management
Secure enrolment with PKI and PQC certificates and a unique identity per device, backed by secure elements and on-chip cryptographic operations.
Advanced security
End-to-end encryption and hardware security modules protect transaction integrity and device authenticity.
Device lifecycle
From device to economic actor in ten steps
Every authenticated device can securely discover, negotiate, purchase and provide services autonomously. Click a step, or use the arrows, to follow one from the factory to its first transaction.
-
Manufacturing
The device is built with a SEALSQ secure element on board.
Hardware root of trust
-
Secure Element Provisioning
Keys are generated inside the secure element in a trusted provisioning process. Private keys never leave the chip.
Hardware root of trust
-
PKI / PQC Certificates
WISeKey PKI issues the device’s certificate, protected with post-quantum cryptography. This is the device’s identity for life.
PQC Secure Identity
-
Wallet
A non-custodial wallet is bound to the device identity so it can hold and spend QAIT.
PQC Secure Identity
-
SEALCOIN Agent
The SEALCOIN agent software runs on the device and acts for it within the rules its owner sets.
Trusted Coordination
-
Network Registration
The device joins the SEALCOIN network and appears in the device registry.
Trusted Coordination
-
Authentication
Each session starts with certificate-based mutual authentication between machines.
Trusted Coordination
-
Service Discovery
Through broker nodes, the device finds trusted services and counterparties.
Trusted Coordination
-
Negotiation
Machines agree price and terms automatically, within owner-defined policy.
Autonomous Transactions
-
Transaction Execution
The exchange is executed and settled in QAIT, with a tamper-proof record on Hedera.
Autonomous Transactions
Connectivity
Why broker nodes matter
Broker nodes facilitate communication. They never become trusted transaction intermediaries. Machines remain in control.
Devices operate behind
- Firewalls
- Carrier networks
- Private networks
- Enterprise gateways
- Cloud isolation

Broker node
Trustless layer that routes and translates messages, keeps them private and gives devices global reach.
Broker nodes enable
- Secure discovery
- Encrypted negotiation
- Authenticated peer connections
- Scalable global connectivity
- Secure communication channel

Security features
Built into the device, enforced by the network
- Secure Elements (SE). SEALSQ hardware that performs cryptographic operations and protects private keys inside the chip.
- Role-Based Access Control (RBAC). Only authorised users and devices can access and act in the SEALCOIN ecosystem.
- Certificate of Authenticity. SEALCOIN issues and manages the certificates that identify a device as part of the trusted ecosystem, for security, interoperability and ease of use.
- Post-quantum protection. Identities and signatures are protected against future quantum attacks.
Proof of concept
Secure, real-time IoT transactions, demonstrated in July 2024
Each IoT device registered on the SEALCOIN platform with a unique digital ID secured by encrypted authentication. Devices then initiated transactions, shared data and completed service-for-payment exchanges on their own, without intermediaries.
The proof of concept confirmed SEALCOIN’s foundational role in a decentralised IoT ecosystem and shaped the platform now running on Hedera with QAIT settlement.

Two devices authenticate, agree a price and settle on Hedera