Skip to content
FIPS 140-3 LEVEL 2 · CERTIFIED NIST PQC ALIGNED
POST-QUANTUM CRYPTOGRAPHY

Your adversaries are already harvesting your ciphertext. Q6of migrates every primitive to NIST-approved post-quantum standards in days.

A drop-in cryptographic agility platform that inventories every key, certificate, and algorithm across your estate and rotates them to ML-KEM, ML-DSA, and SLH-DSA — without recompilation, without downtime, without a multi-quarter program.

  • FIPS 140-3 LEVEL 2Certified Mar 2024
  • NSTISSI NO. 4009Aligned by default
  • CNSA 2.0Migration roadmap

Verified performance, not marketing claims.

Every figure below is reproducible from a published benchmark, a filed certification, or a deployable reference deployment.

  • BENCHMARK / TLS-TERM 84 Gbps ML-KEM-768 hybrid termination on a single 32-core node, line-rate sustained.
  • DEPLOYMENTS / ENTERPRISE 312 Enterprises on the Q6of control plane, including 14 Fortune 500 financials and three Tier-1 European central banks.
  • CERTIFICATION / FIPS-140-3 Level 2 Achieved March 2024 — nine months ahead of the closest post-quantum competitor.
  • CBOM.SCAN / REPOSITORY 6 min Crypto-Bill-of-Materials engine profiles 47 language ecosystems and 1,200+ library fingerprints.
PLATFORM ARCHITECTURE

One platform, four deterministic layers.

Each layer maps cleanly onto a CISO's existing controls: you get a discovery feed on day one, a policy plane by week two, and a hot-swappable agility mesh by month two.

  1. LAYER 01 — DISCOVERY

    CBOM Engine & Cryptographic Inventory

    A passive scanner that ingests source repositories, container images, HSM exports, and PKI chains to emit a signed Crypto-Bill-of-Materials. Every RSA, ECDSA, DH, and AES-CBC primitive is tagged with its location, call frequency, and quantum-vulnerability status.

    • 47 language ecosystems
    • 1,200+ library fingerprints
    • 6-minute repo scan
    • SPDX / CycloneDX export
  2. LAYER 02 — POLICY

    NIST-Aligned Policy Engine

    Codifies CNSA 2.0, FIPS 140-3, and your internal crypto standards into declarative guardrails enforced at every handshake.

  3. LAYER 03 — MESH

    Crypto Agility Mesh

    Patent-pending hot-swap plane that rotates suites without recompilation. Six issued US patents cover the runtime.

  4. LAYER 04 — MANAGED MIGRATION

    Zero-Downtime Migration Playbooks

    Battle-tested runbooks refined across 2.1 million cryptographic assets rotated since 2022. Each asset gets a phased migration ticket with rollback gates, executive reporting, and a deterministic cutover window — typically a Friday evening, never a quarter.

    • 2.1M assets rotated
    • Zero-downtime cutover
    • Rollback gates per phase
    • Executive reporting built-in
PEDIGREE

Built by the team that wrote the standard.

Q6of was founded in 2021 by former NSA cryptographers and Google Brain security researchers. Our team co-authored four of the seven algorithms selected in the NIST PQC standardization round, and contributed 18 staff with prior service on CNSS and NIST working groups.

Founded
2021, Reston, Virginia · engineering offices in Tel Aviv and Waterloo, Ontario
Team
142 employees · 31 PhD-level cryptographers · 18 former CNSS / NIST contributors
Backed by
Andreessen Horowitz (lead), Bessemer Venture Partners, In-Q-Tel
Series B
$74M closed October 2024
RECOGNITION

Gartner Cool Vendor · 2024

Named a "Cool Vendor in Post-Quantum Security" by Gartner in Q2 2024.

RECOGNITION

Forbes Cloud 100 Rising Stars · 2024

Featured on the Forbes Cloud 100 Rising Stars list for 2024.

INDUSTRY AWARD

RSA Conference 2024 Innovation Sandbox

Earned the "Most Likely to Succeed" designation at RSAC 2024 Innovation Sandbox.

OPEN SOURCE

OWASP Reference Tool

Our PQC migration cost calculator was the first in the industry to publish as open source — now adopted by OWASP as a reference tool.

CUSTOMER SEGMENTS UNDER ACTIVE CONTRACT
  • 14 Fortune 500 financial institutions
  • 3 Tier-1 European central banks
  • Federal systems integrators
  • Healthcare & life sciences
  • Telecommunications carriers
  • Critical infrastructure operators
PEER BRIEFING

Questions we hear from every CISO before scoping an audit.

A working transcript of the objections raised in the last 90 days of audit scoping calls — answered the way we would answer them in person.

How does Q6of align with CNSA 2.0 and the NSA's quantum-resistant timeline?

Our policy engine ships with a CNSA 2.0 baseline pre-loaded: ML-KEM-768 for key encapsulation, ML-DSA-65 for signatures, and AES-256 / SHA-384 as the symmetric defaults. Customers can tighten the floor to CNSS-recommended curves per asset class, and the control plane exports an evidence trail for every handshake that satisfies a reviewer without a follow-up audit.

What exactly does the FIPS 140-3 Level 2 certificate cover?

The certificate covers our cryptographic module — the HSM-backed key store, the policy enforcement boundary, and the random-bit generator — not the entire SaaS control plane. That boundary is exactly what your auditor will care about; we will share the certificate number and the security policy document on the audit call.

Will a hybrid TLS termination break our existing clients?

No. The agility mesh negotiates hybrid suites (X25519 + ML-KEM-768) by default, so legacy clients continue to negotiate against the classical half. Once the asset hits a "shadow" window of 100% post-quantum negotiation for 14 consecutive days, the classical fallback can be retired on your schedule.

What is the realistic harvest-now-decrypt-later exposure window?

Long-lived data with multi-decade confidentiality value — legal records, genomic data, defense IP, certain financial instruments — is the priority. Our modeling suite, used by the NSA's CSfC program as reference tooling, scores your assets against an adversary-collection probability curve so you can sequence migrations by exposure rather than by alphabet.

What does a migration actually cost, and how do I budget for it?

Our open-source PQC migration cost calculator — now an OWASP reference tool — returns a defensible cost band per asset class within minutes. During the 30-minute audit we walk you through a populated version against your CBOM, with confidence intervals your CFO will accept.

PROTOCOL

What happens in the 30-minute PQC Readiness Audit.

A working session, not a sales call. Walk away with a CBOM export, a NIST gap matrix, a cost-band estimate, and an executive briefing packet — regardless of whether you ever become a customer.

  1. STEP 01 / 04

    Estate Scoping

    You share the top three business-critical applications. We confirm the inventory coverage and identify which of your 47 supported language ecosystems are in play. Fifteen minutes, no NDA required.

    → CBOM export, scoped
  2. STEP 02 / 04

    NIST Gap Matrix

    We map every discovered primitive against the CNSA 2.0 and FIPS 140-3 baselines, then flag the 10–15 assets that account for the majority of your quantum exposure.

    → Gap matrix, prioritized
  3. STEP 03 / 04

    Cost-Band Estimate

    Our migration cost calculator — adopted by OWASP as a reference tool — returns a defensible engineering-effort band per asset, with a confidence interval your procurement team can hold to.

    → Cost band, with confidence interval
  4. STEP 04 / 04

    Executive Briefing Packet

    A PDF you can forward to your CIO and board audit committee: one-page threat narrative, the gap matrix, the cost band, and a recommended 90-day migration order. Yours to keep.

    Request a PQC Readiness Audit
Operated by Q6of, Inc. · 1750 Tysons Boulevard, Suite 1800, Tysons, VA 22102 · +1 (703) 555-0142 · [email protected]