Quantum Insights

EQCore: The Cryptographic Control Plane for Post-Quantum Migration

Written by Benjamin Nicoll | Sep 15, 2026, 12:08:11 AM

Sovereign encryption from discovery to full migration. Deployable in days across cloud, on-premise, or air-gapped environments.

Cryptography is no longer a background utility. It is a regulated risk system. Governments worldwide are mandating the adoption of post-quantum cryptography (PQC) before quantum computers render classical encryption obsolete, with CNSA 2.0 requiring compliance for new national security system acquisitions from January 2027 and the ASD ISM targeting PQC mandates by 2030.

The challenge for most organisations is not awareness. It is execution. Where does your cryptographic exposure actually sit? Which algorithms are in use across your APIs, certificates, key management systems, and source code? And once you know, how do you migrate without breaking production systems?

EQCore is ExeQuantum's answer to that challenge. It is not a single tool. It is a Cryptographic Control Plane: an integrated platform that connects discovery, remediation, and continuous governance into a single operational layer. Built on ExeQuantum's STAC doctrine (Sovereign, Transparent, Agile, Compliant), EQCore sits above existing security tools such as SIEM, GRC, CSPM, and IAM, governing cryptography as a first-class risk domain.

Three products power the platform: CipherScout for cryptographic discovery, CipherForge for formally verified PQC implementation, and CipherWatch for continuous compliance monitoring. Together, they deliver end-to-end post-quantum migration that is standards-aligned, sovereign by design, and deployable in days rather than months.

CipherScout: Know What You Are Actually Running

You cannot migrate what you cannot see. Most organisations significantly underestimate their cryptographic footprint. A single virtual machine can contain over 150 discrete cryptographic assets. Multiply that across an enterprise environment and the scale of exposure becomes clear.

CipherScout is ExeQuantum's cryptographic discovery engine. It scans across 10 distinct attack surfaces to produce a complete inventory of every cryptographic asset in your environment:

  • TLS and certificates across all endpoints
  • APIs and HTTP traffic
  • SSH configurations
  • JWT fleets, including fleet-level population analysis rather than point-in-time single-token inspection
  • Cloud KMS integrations (AWS, Azure, GCP)
  • Source code repositories
  • Email encryption configurations
  • Databases and data-at-rest encryption
  • Identity systems (JWT/JWKS)
  • IoT, OT and devices

The output is a Cryptographic Bill of Materials (CBOM) in CycloneDX 1.7 format: a machine-readable, standards-compliant inventory of every algorithm, key length, certificate, and cryptographic dependency across your stack. This is the foundation for any serious migration programme, and it is increasingly becoming a procurement requirement in regulated sectors.

CipherScout includes proprietary detection capabilities that go beyond standard tooling, providing a comprehensive view of cryptographic posture rather than a snapshot.

CipherForge: Formally Verified Post-Quantum Encryption

Discovery tells you where you are exposed. CipherForge closes the gap.

CipherForge is ExeQuantum's PQC implementation engine: a formally verified encryption platform supporting the full suite of NIST-standardised post-quantum algorithms alongside emerging standards. It is available as an embedded library with a centralised management dashboard, designed for integration into existing application stacks with minimal friction.

Supported Algorithms

CipherForge supports the complete set of NIST FIPS-standardised PQC algorithms and additional schemes for specific deployment requirements:

  • ML-KEM (FIPS 203): lattice-based key encapsulation
  • ML-DSA (FIPS 204): lattice-based digital signatures
  • SLH-DSA (FIPS 205): stateless hash-based signatures
  • Mceliece: code-based key encapsulation (ISO/IEC 18033-2 Amd 2:2026)
  • FrodoKEM: conservative lattice-based KEM (ISO/IEC 18033-2 Amd 2:2026)

Custom and national-standard algorithms can also be integrated for jurisdictions with specific cryptographic requirements.

The Jasmin Formal Verification Advantage

CipherForge's most significant technical differentiator is its implementation architecture. Every subroutine that handles secret values is written in Jasmin, a domain-specific language that enforces constant-time execution and enables formal verification at the assembly level by construction. Public-only operations remain in C where compiler optimisations are safe.

This hybrid Jasmin/C architecture closes what is known as the "last-mile compiler gap": the risk that compilers like GCC and Clang silently introduce timing side-channels into otherwise secure implementations. Even well-regarded implementations face this risk. ExeQuantum's approach eliminates it by construction, delivering provably secure execution without the performance trade-off that formal assurance typically requires.

The result is a PQC implementation layer that is both formally verified and production-performant, making it suitable for high-throughput enterprise environments where security assurance and operational speed are equally non-negotiable.

Deployment Flexibility

CipherForge supports multiple deployment models to meet the operational and compliance requirements of any environment:

  • Cloud: SaaS deployment with zero infrastructure overhead
  • On-premise: deployed within the organisation's own infrastructure, behind its own firewalls
  • Hybrid: split deployments where management resides in the cloud while encryption operations remain on-premise
  • Air-gapped: fully isolated deployments for classified or critical infrastructure environments with no external connectivity

Deployment timelines are measured in days, not months. CipherForge is designed to integrate with existing application stacks through a clean API interface, reducing the engineering effort typically associated with cryptographic migration projects. A working integration requires a single API call.

CipherWatch: Continuous Cryptographic Compliance

Migration is not a one-time event. New certificates are issued, configurations drift, dependencies update, and the threat landscape evolves. CipherWatch provides continuous monitoring to ensure your cryptographic posture remains compliant after the initial migration.

CipherWatch delivers:

  • Real-time compliance reporting against NIST, CNSA 2.0, ISM, and other frameworks
  • Audit trail generation for regulatory evidence and board reporting
  • Algorithm lifecycle management to track deprecation timelines and migration progress
  • Drift detection to identify when configurations move out of compliance
  • Automated alerting for quantum-vulnerable assets introduced into the environment

For CISOs and risk officers, CipherWatch transforms cryptographic compliance from a periodic audit exercise into a continuous governance function. For board-level reporting, it provides the evidence trail that regulators and auditors increasingly require.

BYOD Architecture: Your Data Never Leaves Your Control

ExeQuantum operates on a Bring Your Own Database (BYOD) architecture. All scan data, cryptographic inventories, and compliance reports are stored in the client's own provisioned database. ExeQuantum does not hold, retain, or have persistent access to client data at any point in the engagement lifecycle.

This is not a marketing claim. It is a structural architectural decision that eliminates an entire category of supply chain risk:

  • No data residency concerns: your data stays in your jurisdiction, on your infrastructure
  • No vendor lock-in on data: you own your CBOM, your compliance evidence, and your audit trails outright
  • No third-party breach exposure: ExeQuantum cannot leak what it does not hold
  • Simplified procurement: TPRM (Third-Party Risk Management) assessments are materially simpler when the vendor never touches your data

For organisations in regulated industries, particularly government, defence, banking, and critical infrastructure, BYOD architecture is not a feature. It is a prerequisite. ExeQuantum was built this way from the ground up.

Deploying On-Premise and in Air-Gapped Environments

Many organisations operating in defence, intelligence, and critical infrastructure cannot deploy cloud-based solutions. Their environments are physically isolated from external networks, and their procurement frameworks require vendors to demonstrate that no data traverses external boundaries.

EQCore and CipherForge are designed for these environments:

On-Premise Deployment

On-premise deployment places the full EQCore stack within the organisation's own infrastructure. The platform runs behind existing firewalls and security controls, integrating with internal authentication systems and existing tooling. Deployment is containerised and designed to operate within standard enterprise infrastructure without requiring specialised hardware or extensive configuration.

Air-Gapped Deployment

For fully isolated environments, CipherForge can be deployed with no external connectivity whatsoever. The platform operates entirely within the air-gapped network, performing all encryption, key generation, and signature operations locally. Updates and algorithm additions are delivered through secure offline transfer processes that maintain the integrity of the air gap.

Why Speed Matters

Traditional PQC migration projects are scoped in quarters or years. EQCore is designed to compress that timeline significantly. The combination of a clean API interface, containerised deployment, and a platform that handles both discovery and remediation in a single ecosystem means organisations can move from initial assessment to production-ready PQC in days rather than the months typically quoted by competitors.

This speed is particularly relevant as compliance deadlines approach. CNSA 2.0 requires new national security system acquisitions to use post-quantum algorithms from January 2027. The ASD ISM targets 2030 for broad PQC adoption. Organisations that begin migration now will have time to test, validate, and iterate. Those that wait will face compressed timelines and elevated risk.

Compliance Framework Alignment

EQCore is built to align with the regulatory frameworks that govern cryptographic standards across jurisdictions. The platform does not just perform cryptographic operations; it produces the evidence and reporting that compliance teams, auditors, and regulators require.

Standards and Frameworks

EQCore is designed to map to the cryptographic requirements of whatever regulatory framework governs your environment. CipherForge implements the full suite of NIST FIPS 203/204/205 algorithms (ML-KEM, ML-DSA, SLH-DSA) with formal verification, directly supporting CNSA 2.0 timelines for national security system compliance. CipherScout's discovery and CBOM output aligns with the ASD ISM cryptographic controls, NACSA Directive No. 9 (including Lampiran A Jadual compliance reporting), and APRA CPS 234 evidence requirements for regulated financial institutions. Across Europe, the platform supports the cryptographic governance expectations of DORA, NIS2, PCI DSS, eIDAS 2.0, and GDPR (Articles 5(1)(c) and 32), among others. 

Where a specific national or sector framework requires tailored reporting or algorithm support, EQCore's architecture is built to accommodate it. The platform already produces jurisdiction-specific outputs across multiple regions, and new framework mappings are added as client and regulatory requirements evolve.

Credential-Backed Trust

ExeQuantum's compliance position is validated by third-party certifications and independent market recognition:

  • ISO 27001 certified, with zero major or minor non-conformities at the most recent surveillance audit
  • AUKUS Authorised User, enabling technology transfer across Australia, the UK, and the US under the Licence Free Environment framework
  • CREST-accredited penetration testing completed with zero non-informational findings
  • Featured in the Wavestone 2026 Post-Quantum Migration Solution Radar
  • Named in the CIGI G7 Special Report on Quantum Technologies and Finance alongside JPMorgan Chase, HSBC, and the Bank of Canada
  • Classified as export-ready by Austrade in the Australian Quantum Technology Industry Capability Report
  • Named as a major player in the Business Research Company Quantum-Safe HSM Global Market Report alongside IBM, Thales, Infineon, and Entrust
  • RMIT University peer-reviewed research validating ExeQuantum's API-driven PQC approach

The Harvest Now, Decrypt Later Clock Is Running

The urgency driving PQC adoption is not theoretical. Adversaries are intercepting and storing encrypted data today, waiting to decrypt it once quantum computers reach sufficient capability. This is the Harvest Now, Decrypt Later (HNDL) threat, and it affects any data with a secrecy shelf life longer than the timeline to cryptographically relevant quantum computing.

For financial institutions holding decades of transaction records, for government agencies handling classified communications, and for healthcare organisations managing patient data with lifetime confidentiality requirements, the HNDL window is already open. The data being harvested today cannot be retroactively protected. The only defence is migrating to quantum-resistant algorithms before the decryption capability arrives.

EQCore provides the complete pathway: discover your exposure with CipherScout, migrate to formally verified post-quantum algorithms with CipherForge, and maintain continuous compliance with CipherWatch. Sovereign, standards-aligned, and deployable anywhere your data lives.

Get Started

The best time to begin your post-quantum migration was yesterday. The second-best time is now.

Request a demo to see EQCore in action across your environment.

Contact the ExeQuantum team at info@exequantum.com to discuss your specific deployment requirements.

ExeQuantum Pty Ltd | ISO 27001 Certified | AUKUS Authorised | NIST-Aligned