AutomaticModulo website and admin
modulocms.com and admin.modulocms.sk run behind Cloudflare, which offers a hybrid post-quantum key exchange. A modern browser — Chrome and Edge on desktop from version 131, Firefox on desktop from 132, Safari from iOS and macOS 26 — uses it on its own, nothing to configure. An older browser still connects encrypted as before, just without the post-quantum part.
Post-quantum onlyApps ↔ our servers
The apps connect to our servers with a post-quantum key exchange only: Veredar for sync, updates and the Modulo link (from version 0.18.0, 24 September 2026), Veredaria for the Modulo link, where its connections and passwords come from, and Kioskbase for Mac, iPad and iPhone for the Kioskbase server (both from their upcoming versions, now in testing). A server that cannot do it is refused — no silent fallback to weaker encryption.
End to endMoving a sign-in between tablets
When you replace a tablet in Kioskbase, the saved sign-in moves from the old one to the new one encrypted end to end with a post-quantum hybrid. The server only carries an encrypted package it cannot open itself, valid for 10 minutes. Since Kioskbase 1.25.0 for Android.
PreferredWhere the other side decides
With third-party servers the apps prefer the post-quantum exchange and use the classic one only when the server does not know it: Veredaria for SFTP (the ML-KEM-768 + X25519 hybrid, the same as in OpenSSH 10), Veredar for mail (IMAP, SMTP — with Gmail it already negotiates it) and for calendars and contacts (CalDAV, CardDAV) from version 0.18.0 on desktop, and Kioskbase for Apple when pairing with attendance systems — with dochadzka.online it does negotiate it (from the upcoming version). Veredar in Settings → Security and Veredaria with a badge next to the connection show what was actually negotiated with the server.
AES-256Stored passwords
Connection passwords in Modulo sit in a vault encrypted with AES-256-GCM. 256-bit symmetric encryption is considered resistant to quantum computers too: the best-known quantum attack (Grover’s algorithm) reduces it to roughly 128-bit strength, which is considered sufficient.
Verified domains
On each of these addresses we verified on 24 September 2026 that the server negotiates the X25519MLKEM768 post-quantum key exchange:
modulocms.skmodulocms.comadmin.modulocms.skkioskbase.skkioskbase.comportal.kioskbase.skapi.kioskbase.comveredar.comsync.veredar.comveredaria.com