Why ExeQuantum
We build the cryptography, not just the dashboard around it
Our team brings together award-winning cryptographic researchers from CSIRO Data61, enterprise security leaders from PayPal and Braintree, and high-growth operators who have scaled platforms across APAC and globally. That depth is why we own the full stack: a formally verified PQC implementation, a native cryptographic discovery engine and the sovereign control plane that governs both.
Technical moat
Constant-time by construction, not by convention
CipherForge uses a Jasmin/C hybrid architecture. Every subroutine that handles secret values is written in Jasmin, a domain-specific language that enforces constant-time execution and enables formal verification at the assembly level. Public-only operations remain in C where compiler optimisations are safe. This closes the last-mile compiler gap that affects even well-regarded implementations.
Samuel Tseitkin presenting the timing side-channel vulnerability in ML-KEM's division operation that CipherForge's Jasmin architecture eliminates by construction.
The compiler gap
Optimisers and compilers cannot guarantee constant-time
Standard C compilers can silently introduce timing side-channels through branch prediction, instruction reordering and dead-code elimination. Even audited implementations are vulnerable to this. Jasmin prevents it by construction: the compiled output is verifiably constant-time regardless of the compiler.
Performance
Formal assurance without a performance trade-off
The Jasmin ML-DSA signing implementation matches or exceeds the throughput of the C reference, disproving the common assumption that verified implementations must be slower. ML-KEM runs at parity with formal verification guarantees the reference cannot provide.
Scarcity
A ground-up rearchitecture to replicate
Rebuilding this architecture requires a combination of cryptographic engineering and formal methods expertise that is globally scarce. The Jasmin implementation is not a wrapper around an open-source library. It is a purpose-built, formally verified cryptographic engine.
End-to-end
One platform, not five vendors
Splitting cryptographic discovery, implementation and monitoring across multiple vendors creates gaps at every handoff: inconsistent data models, duplicated onboarding, competing priorities. EQCore governs the full lifecycle in one control plane, with one API, one data model and one chain of accountability.
Multi-vendor approach
Certificate discovery from one vendor. Key management from another. Implementation consulting from a third. Each with its own data format, dashboard and support contract. Gaps between tools become gaps in coverage.
ExeQuantum
CipherScout discovers. CipherForge migrates. CipherWatch monitors. All three share a common data model inside EQCore, with a single CBOM that travels from inventory through remediation to ongoing posture. One vendor, one chain of accountability.
Library-only vendors
Provide PQC algorithms as a library or SDK. No native discovery of what cryptography your estate actually runs. No continuous monitoring. You still need separate tools to find the problem and verify the fix.
ExeQuantum
Owns the discovery engine and the formally verified implementation layer. The same platform that finds your RSA-2048 certificate also executes the ML-KEM swap and alerts you if the certificate reappears in a future scan.
Hyperscaler PQC
Cloud providers are shipping PQC at the edges of their own infrastructure. They are structurally incentivised to confirm their environment is safe, not to surface cryptographic exposure in your on-premises or multi-cloud estate.
ExeQuantum
Vendor-neutral discovery across cloud, on-premises and air-gapped environments. No conflict of interest. CipherScout scans your actual estate, not just the parts inside one provider's boundary.
Sovereignty
Zero access by architecture, not by policy
ExeQuantum's BYOD (Bring Your Own Database) architecture means all scan data is stored in your own provisioned database. We never hold, retain or have persistent access to client data. This is not a policy commitment that could be reversed. It is a structural impossibility built into the platform.
Data residency
Your data stays in your jurisdiction
Scan results, cryptographic inventories and CBOM outputs never cross jurisdictional boundaries. The database is yours, provisioned and controlled within your own infrastructure boundary.
Air-gapped
Deployable without an internet connection
The full platform runs on-premises or in air-gapped environments. The on-premises bundle is verified at install with ML-DSA-65 and minisign, so you can prove the software you run is the software we signed.
Compliance
Audit-ready from day one
BYOD architecture satisfies data sovereignty requirements across GDPR Article 32, NIS2, DORA and sector-specific frameworks. The audit conversation is straightforward: we never had the data.
Why this matters
A policy can be changed. An architecture cannot. When a regulator or auditor asks where your cryptographic inventory data is stored, the answer is simple: in your own database, inside your own boundary, under your own access controls. ExeQuantum never sees it.
Industry engagement
Shaping the standards, not just following them
ExeQuantum contributes to the global PQC conversation through standards bodies, government-backed research partnerships and industry roundtables. We are trusted for technical input, not just as a vendor selling into the space.
PKI Consortium Post-Quantum Cryptography Conference roundtable. ExeQuantum alongside Scott Rea (eMudhra / DirectTrust), Anestis Bechtsoudis (CENSUS Labs) and Setiaji (Senior Advisor to the Minister of Health, Republic of Indonesia)
Standards
PKI Consortium
Active participant and roundtable contributor at the PKI Consortium's Post-Quantum Cryptography Conference, the highest-profile global PQC standards event.
Government
AUKUS and ASD
Confirmed AUKUS Authorised User with Licence Free Environment permit for technology transfer across Australia, the UK and the US. Direct engagement with the Australian Signals Directorate.
Research
University partnerships
Peer-reviewed research with RMIT University. Guest lecture partnerships with Swinburne University and Deakin University. Our CTO was a Postdoctoral Fellow at CSIRO Data61.
Third-party recognition
Featured in the Wavestone 2026 PQC Migration Radar, the CIGI G7 Special Report on Quantum Technologies and Finance, and the Austrade Quantum Technology Capability Report. Named as a major player alongside IBM, Thales and Entrust in The Business Research Company's Quantum-Safe HSM Global Market Report. See our full credentials →
See what you actually run
Book a discovery scan and receive a Cryptographic Bill of Materials of the cryptography in your estate, without your data leaving your environment.