Skip to content
FIPS 140-3 LEVEL 2 · CERTIFIED NIST PQC ALIGNED
POST-QUANTUM CRYPTOGRAPHY  //  SPEC.SHEET 01

A drop-in cryptographic agility stack that moves every key, certificate, and algorithm to NIST-approved post-quantum standards in days.

Q6of inventories your estate, maps it to FIPS 203 and FIPS 204, and rotates 2.1 million quantum-vulnerable assets to ML-KEM and ML-DSA without downtime. Built by former NSA cryptographers and Google Brain security researchers.

30-minute session  ·  Delivered by a Q6of solutions engineer  ·  NDA available on request

STACK ARCHITECTURE  //  SPEC.SHEET 02

Five functional layers, one deterministic migration path.

Every layer in the Q6of stack corresponds to a concrete protocol artifact a security architect can audit, benchmark, and roll back independently.

  1. L1

    Crypto-Bill-of-Materials (CBOM) engine

    Scans 47 language ecosystems and 1,200+ library fingerprints. Exposes every quantum-vulnerable primitive in under 6 minutes per repository and emits a CycloneDX-compatible bill of materials with a NIST risk score per asset.

    PROTOCOL · CYCLONEDX 1.5 + SPDX 2.3
  2. L2

    Crypto Agility Mesh

    Patent-pending control plane that hot-swaps cipher suites, signature schemes, and key-exchange primitives at runtime — no recompilation, no service restart. Covered by 6 issued US patents and tested across the OWASP PQC reference corpus.

    PROTOCOL · IETF TLS 1.3 + RFC 8446bis drafts
  3. L3

    ML-KEM and ML-DSA hybrid TLS termination

    Production-grade Kyber and Dilithium termination at line rate. Hybrid X25519 + ML-KEM-768 handshakes benchmarked at 84 Gbps on a single 32-core node, with per-cipher latency overhead published in the benchmark matrix below.

    PROTOCOL · FIPS 203 + FIPS 204
  4. L4

    Harvest-now-decrypt-later threat modeling

    Quantifies the confidentiality horizon of every data class against a configurable cryptographically-relevant quantum computer profile. Adopted by the NSA Commercial Solutions for Classified (CSfC) program as reference tooling.

    PROTOCOL · CNSA 2.0 alignment
  5. L5

    Zero-downtime rotation playbooks

    Replay-tested playbooks refined across 2.1 million rotated assets since 2022. Covers certificate re-issuance, KMS re-keying, HSM rotation, and SSH/PGP estate migration with rollback checkpoints at every stage.

    PROTOCOL · PKCS#11 + ACME v2 + SSH CERT
DEPLOYMENT TOPOLOGY  //  SPEC.SHEET 03

Three deployment modes, zero recompilation.

Pick the integration shape that matches your existing service mesh, Kubernetes operator strategy, or air-gapped enclave posture. Every mode ships the same CBOM output, the same agility mesh, and the same SLA.

MODE A · SIDECAR PROXY

Drop-in sidecar for any service mesh

Attach the Q6of Envoy/Istio-compatible sidecar to existing pods. Terminate hybrid TLS at the mesh edge, inspect upstream cipher suites, and emit per-request CBOM events to the managed control plane. Ideal for brownfield Kubernetes estates.

  • Compatible with Istio, Linkerd, Consul Connect
  • No application code changes
  • CBOM events stream to the control plane over mTLS
MODE B · IN-PROCESS SDK

In-process SDK for latency-critical paths

Embed the Q6of runtime in Go, Rust, Java, and Node.js services where a sidecar hop is unacceptable. The SDK exposes the same agility mesh API as the sidecar and is used by 14 Fortune 500 financial institutions for FIX-gateway and card-authorization paths.

  • Sub-50µs overhead on hot path
  • Native FFI for Rust and Go
  • JCA / OpenSSL provider for Java and C
MODE C · MANAGED CONTROL PLANE

Air-gapped managed control plane

Run the Q6of control plane as an on-prem cluster in your air-gapped enclave. The control plane owns inventory, policy, rotation scheduling, and audit export — your workloads only see a local gRPC endpoint. Trusted by three Tier-1 European central banks.

  • 99.997% availability SLA
  • STIX/TAXII export for SIEM ingestion
  • Hardware-backed key wrapping via PKCS#11
BENCHMARK MATRIX  //  SPEC.SHEET 04

Line-rate and latency you can verify.

Benchmarked on identical 32-core nodes (AMD EPYC 9354, 128GB RAM, kernel 6.6, OpenSSL 3.3) under sustained 10-second soak. Reproducible harness published under the Q6of Open Benchmark License.

Handshake profile Throughput (handshakes/sec) Line rate (Gbps, 1.5KB record) p99 latency (ms) Resident memory (MB / connection) Standard alignment
TLS 1.3 · RSA-2048 + ECDHE-P256 (baseline) 118,400 14.2 1.8 2.1 NIST SP 800-131A (legacy)
TLS 1.3 · X25519 + Ed25519 (classical) 214,800 25.7 1.1 2.0 NIST SP 800-186
TLS 1.3 · Generic Kyber-768 reference impl. 412,600 49.5 2.4 3.6 Pre-FIPS 203 reference
TLS 1.3 · Q6of X25519 + ML-KEM-768 hybrid 701,200 84.0 2.1 3.4 FIPS 203 (ML-KEM)
TLS 1.3 · Q6of ML-KEM-1024 + ML-DSA-65 498,300 59.7 2.7 4.8 FIPS 203 + FIPS 204

All Q6of rows reflect production build q6of-mesh 4.7.2 with AVX-512 vectorized Kyber NTT. Generic Kyber-768 row uses the liboqs 0.11 reference implementation, unmodified.

NIST & CNSA 2.0 MAPPING  //  COMPLIANCE MEMO

Drop the mapping straight into your compliance memo.

Every Q6of primitive is aligned to a specific FIPS final, a specific CNSA 2.0 timeline, and a specific advisory. The table below is the artifact your standards officer needs to file the variance.

Capability Q6of primitive FIPS final CNSA 2.0 deadline
Key establishment (TLS / IKE) ML-KEM-768 hybrid, ML-KEM-1024 FIPS 203 2031 (software), 2033 (firmware)
Digital signatures (cert, code, JWT) ML-DSA-65, ML-DSA-87 FIPS 204 2030 (software), 2033 (firmware)
Module certification Q6of Cryptographic Module v4.7 FIPS 140-3 Level 2 (Mar 2024) Required for federal procurement
Stateful hash-based signatures (firmware) SLH-DSA-SHA2-128s via agility mesh FIPS 205 2033 (firmware signing)
Symmetric primitives (unchanged) AES-256-GCM, SHA-384, HMAC-SHA-384 FIPS 197 / FIPS 180-4 No deadline change

Q6of is a defensive vendor. We do not model or publish cryptanalytic claims against RSA-2048 or ECDSA-P256. Migration urgency is driven by the harvest-now-decrypt-later threat profile, not by a claimed quantum computing arrival date.

NEXT ENGINEERING ACTION

Book a 30-minute PQC Readiness Audit.

A Q6of solutions engineer runs a one-time CBOM scan against the repositories and infrastructure you nominate, then walks you through the output on a live call.

01 A CycloneDX CBOM listing every quantum-vulnerable primitive, with NIST risk score per asset.
02 A migration cost estimate built on the open-source Q6of PQC migration cost calculator (OWASP reference).
03 A quantum-risk heat map showing which data classes are exposed under a configurable CRQC horizon.

Or reach the solutions team directly: [email protected]  ·  +1 (703) 555-0142  ·  Q6of, Inc., 1750 Tysons Boulevard, Suite 1800, Tysons, VA 22102