Step 2 · Migrate

From exposure to executed migration

CipherForge turns your CBOM into a staged remediation plan, then performs the swap with a formally verified PQC implementation built in-house. Algorithm-agnostic: the full NIST suite by default, plus national and emerging standards as they land.

NIST-Aligned ISO 27001 AUKUS Authorised Formally Verified Air-Gapped Ready Available

How it works

CBOM in, migration out

Start from an inventory of the cryptography you run. EQCore turns it into a structured, prioritised migration plan, and CipherForge performs the move to post-quantum algorithms with its own formally verified implementation.

01 · Ingest

Upload or generate a CBOM

Upload a CycloneDX Cryptographic Bill of Materials or generate one automatically from a CipherScout™ scan, with no manual inventory required.

02 · Classify

KEM vs signature, per finding

Each finding is classified by the primitive it needs: a post-quantum key-encapsulation mechanism or a post-quantum signature.

03 · Prioritise

A plan, ranked and actionable

Findings are assembled into a prioritised remediation plan you can hand to your teams, sequenced by risk, effort and compliance impact.

04 · Execute

Perform the swap

CipherForge performs the migration with our own PQC implementation, built and formally verified in-house, so the cryptography replacing each algorithm is proven correct at the implementation level.

Implementation

Why it matters who wrote the cryptography

Most PQC libraries wrap a C reference implementation and trust the compiler to preserve security properties. That trust is misplaced. Optimisers such as GCC and Clang can silently introduce timing side-channels into constant-time code, and once that happens, the implementation leaks secrets regardless of how strong the algorithm is.

01

The compiler gap

Standard C compilers optimise for speed, not for security. They can reorder branches, eliminate stores, and introduce variable-time instructions into code that was written to be constant-time. Even well-regarded implementations are subject to this risk.

02

Assembly-level verification

CipherForge’s core subroutines are written in Jasmin, a language that compiles directly to verified assembly. Constant-time execution is enforced by construction, not by convention, closing the last-mile compiler gap entirely.

03

No performance trade-off

The assumption that formal assurance costs throughput is wrong. CipherForge’s hardened ML-DSA implementation meets or exceeds the C reference across every parameter set, including key generation, signing and verification.

Why this is rare

Building a formally verified PQC implementation requires a combination of cryptographic engineering depth and formal methods expertise that is globally scarce. This is not a wrapper around a third-party library. ExeQuantum built the implementation from the ground up, and it is the single most defensible technical asset in the platform.

Performance

Formally verified. Faster than the reference.

CipherForge’s Jasmin ML-DSA implementation outperforms the standard C reference across every parameter set. These are throughput comparisons against the NIST reference implementation, measured in operations per second.

ML-DSA-44

> 115%

vs. C reference (all ops)

ML-DSA-65

> 129%

vs. C reference (all ops)

ML-DSA-87

> 112%

vs. C reference (all ops)

51

Algorithms across KEM, hybrid KEM and signature groups

4

Standards covered: FIPS, ISO, RFC, NIST SP

3

Deployment models: SaaS, on-premises, air-gapped

0

Access to your keys. BYOD architecture: your data stays yours.

Algorithm support

51 algorithms across three groups

The full NIST post-quantum suite plus FrodoKEM, Classic McEliece, and hybrid KEMs. National and emerging algorithms are mapped in as regulators require them.

Group Algorithms Standard
kem ML-KEM-512, ML-KEM-768, ML-KEM-1024 FIPS 203
kem FrodoKEM, eFrodoKEM (8 parameter sets) ISO/IEC 18033-2 Amd. 2:2026
kem Classic McEliece (16 parameter sets) ISO/IEC 18033-2 Amd. 2:2026
hybrid_kem X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024 RFC 10024
sign ML-DSA-44, ML-DSA-65, ML-DSA-87 FIPS 204
sign SLH-DSA (SHA2/SHAKE × 128/192/256 × s/f) (12 parameter sets) FIPS 205
sign SLH-DSA (SHA2/SHAKE × 128/192/256 × -24) (6 parameter sets) NIST SP 800-230

Developer experience

Shipping software, not a whitepaper

CipherForge exposes every algorithm through a clean API. Query the registry, generate keys, encapsulate, sign. Each algorithm returns full metadata including key sizes, security levels and the standard it implements.

from exequantum_pqc import algorithms

# all 51 algorithms
algorithms()

# filter by group
algorithms("sign")

# each entry returns full metadata
{
  "algorithm": "ML-KEM-768",
  "group": "kem",
  "standard": "FIPS 203",
  "nist_level": 3,
  "encapsulation_key_size": 1184,
  "decapsulation_key_size": 2400,
  "ciphertext_size": 1088,
  "shared_secret_size": 32
}

REST and native

Available as a REST API at eqcore.io and as a native SDK. Sandbox access at eqcore.io for evaluation and training.

Guidance

Framework-filtered remediation

Your compliance framework drives the recommendations, so the plan reflects the regime you actually answer to rather than a generic swap list.

01

Framework to regime

Each governance framework you report against, from NIST CSF to ISO 27001 and others, is mapped to the algorithm regime it defers to.

02

Approved-algorithm intersect

Recommendations are intersected with the approved-algorithm list for that regime, so every suggestion is one your framework permits.

03

Regime-aware by default

As a regime’s approved algorithms change, the filter updates and the plan re-generates, so recommendations stay current with the standard you answer to.

Framework coverage

EQCore maps findings against compliance regimes across the US, Australia, the UAE, India, Malaysia and international standards. If the framework you report against isn’t covered yet, we can add it quickly.

Architecture

Where the cryptography actually runs

EQCore is the planning and orchestration layer. The cryptographic operations themselves run via our dedicated CipherForge PQC service.

How the crypto runs

Key-encapsulation and sign/verify operations run in CipherForge, our own formally verified PQC implementation. EQCore plans and orchestrates the migration; CipherForge performs the operations. Crypto-agility means swapping algorithms through the registry, so your applications stay untouched.

Sovereignty

Runs entirely within your boundary

Deploy EQCore as a SaaS console or as a sovereign on-premises box, whether cloud, on-premises or air-gapped. A sovereign, data-residency-preserving architecture keeps your keys and data within your environment.

01

Signed-bundle install

The on-premises bundle is verified with ML-DSA-65 + minisign before it runs, with per-box TLS certificate issuance and auto-provisioned per-box subdomain auth.

02

On-premises discovery

Cryptographic discovery and topology mapping execute inside your network, so scanning never reaches out to us.

03

Bring your own database (BYOD)

Per-tenant database isolation, central egress guards on scanner sockets and target-bound, server-whitelisted scans keep your keys and findings within your environment.

Sovereign by deployment and isolation

EQCore is sovereign and data-residency-preserving: it runs on your infrastructure and keeps your keys and data within your boundary. This is a deployment and isolation guarantee, described precisely. It is distinct from a “zero-knowledge” cryptographic protocol, which is a different claim we don’t make.

Compliance

Frameworks you already report against

EQCore maps findings to the governance frameworks you report against, so cryptographic gaps land as control references your auditors recognise.

NIST CSF ISO 27001 FedRAMP CMMC Essential Eight (ASD) NACSA Others

If a framework you report against isn’t covered yet, we can add it quickly.

Next · Monitor

Keep the picture current

EQCore plans the migration and CipherForge performs it. Once it is underway, CipherWatch keeps watch, alerting on new or changed exposure on every scan, so your inventory stays current.

Move from exposure to quantum-safe

Talk to a cryptographic architect about your migration, or explore how EQCore ties discovery, migration and monitoring into one control plane.