Step 2 · Migrate

From exposure to executed migration

CipherForge turns your CBOM into a staged remediation plan, then does the swap with a formally verified PQC implementation built in-house, so the cryptography protecting your data is provably correct. Algorithm-agnostic: the full NIST suite by default, plus national and emerging standards as they land.

NIST-Aligned ISO 27001 AUKUS Authorised Formally Verified Air-Gapped Ready Available

How it works

CBOM in, migration out

Start from an inventory of the cryptography you run. EQCore turns it into a structured, prioritised migration plan, and CipherForge performs the move to post-quantum algorithms with its own formally verified implementation.

01 · Ingest

Upload or generate a CBOM

Upload a CycloneDX Cryptographic Bill of Materials or generate one automatically from a CipherScout™ scan, with no manual inventory required.

02 · Classify

KEM vs signature, per finding

Each finding is classified by the primitive it needs: a post-quantum key-encapsulation mechanism or a post-quantum signature.

03 · Prioritise

A plan, ranked and actionable

Findings are assembled into a prioritised remediation plan you can hand to your teams, sequenced by risk, effort and compliance impact.

04 · Execute

Perform the swap

CipherForge performs the migration with our own PQC implementation, built and formally verified in-house, so the cryptography replacing each algorithm is proven correct at the implementation level.

Guidance

Framework-filtered remediation

Your compliance framework drives the recommendations, so the plan reflects the regime you actually answer to rather than a generic swap list.

01

Framework to regime

Each governance framework you report against, from NIST CSF, FedRAMP and CMMC to ISO 27001, Essential Eight (ASD) and NACSA, is mapped to the algorithm regime it defers to.

02

Approved-algorithm intersect

Recommendations are intersected with the approved-algorithm list for that regime, so every suggestion is one your framework permits.

03

Regime-aware by default

As a regime’s approved algorithms change, the filter updates and the plan re-generates, so recommendations stay current with the standard you answer to.

Framework coverage

EQCore maps findings against compliance regimes across the US, Australia, the UAE, India, Malaysia and international standards. If the framework you report against isn’t covered yet, we can add it quickly.

Algorithm support

The full NIST suite, and beyond

CipherForge implements the full NIST post-quantum suite plus FRODO-KEM and HQC, with national or emerging algorithms mapped in as regulators require them.

ML-KEM (FIPS 203) ML-DSA (FIPS 204) SLH-DSA (FIPS 205) FRODO-KEM HQC

Architecture

Where the cryptography actually runs

EQCore is the planning and orchestration layer. The cryptographic operations themselves run via our dedicated CipherForge PQC service.

How the crypto runs

Key-encapsulation and sign/verify operations run in CipherForge, our own formally verified PQC implementation. EQCore plans and orchestrates the migration; CipherForge performs the operations. Crypto-agility means swapping algorithms through the registry, so your applications stay untouched.

Sovereignty

Runs entirely within your boundary

Deploy EQCore as a SaaS console or as a sovereign on-premises box, whether cloud, on-premises or air-gapped. A sovereign, data-residency-preserving architecture keeps your keys and data within your environment.

01

Signed-bundle install

The on-premises bundle is verified with ML-DSA-65 + minisign before it runs, with per-box TLS certificate issuance and auto-provisioned per-box subdomain auth.

02

On-premises discovery

Cryptographic discovery and topology mapping execute inside your network, so scanning never reaches out to us.

03

Bring your own database (BYOD)

Per-tenant database isolation, central egress guards on scanner sockets and target-bound, server-whitelisted scans keep your keys and findings within your environment.

Sovereign by deployment and isolation

EQCore is sovereign and data-residency-preserving: it runs on your infrastructure and keeps your keys and data within your boundary. This is a deployment and isolation guarantee, described precisely. It is distinct from a “zero-knowledge” cryptographic protocol, which is a different claim we don’t make.

Compliance

Frameworks you already report against

EQCore maps findings to the governance frameworks you report against, so cryptographic gaps land as control references your auditors recognise.

NIST CSF ISO 27001 FedRAMP CMMC Essential Eight (ASD) NACSA

If a framework you report against isn’t covered yet, we can add it quickly.

Next · Monitor

Keep the picture current

EQCore plans the migration and CipherForge performs it. Once it is underway, CipherWatch keeps watch, alerting on new or changed exposure on every scan, so your inventory stays current.

Move from exposure to quantum-safe

Talk to a cryptographic architect about your migration, or explore how EQCore ties discovery, migration and monitoring into one control plane.