Why ExeQuantum

We build the cryptography, not just the dashboard around it

Our team brings together award-winning cryptographic researchers from CSIRO Data61, enterprise security leaders from PayPal and Braintree, and high-growth operators who have scaled platforms across APAC and globally. That depth is why we own the full stack: a formally verified PQC implementation, a native cryptographic discovery engine and the sovereign control plane that governs both.

Technical moat

Constant-time by construction, not by convention

CipherForge uses a Jasmin/C hybrid architecture. Every subroutine that handles secret values is written in Jasmin, a domain-specific language that enforces constant-time execution and enables formal verification at the assembly level. Public-only operations remain in C where compiler optimisations are safe. This closes the last-mile compiler gap that affects even well-regarded implementations.

ExeQuantum CEO Samuel Tseitkin presenting the ML-KEM timing side-channel vulnerability that the Jasmin architecture solves

Samuel Tseitkin presenting the timing side-channel vulnerability in ML-KEM's division operation that CipherForge's Jasmin architecture eliminates by construction.

The compiler gap

Optimisers and compilers cannot guarantee constant-time

Standard C compilers can silently introduce timing side-channels through branch prediction, instruction reordering and dead-code elimination. Even audited implementations are vulnerable to this. Jasmin prevents it by construction: the compiled output is verifiably constant-time regardless of the compiler.

Performance

Formal assurance without a performance trade-off

The Jasmin ML-DSA signing implementation matches or exceeds the throughput of the C reference, disproving the common assumption that verified implementations must be slower. ML-KEM runs at parity with formal verification guarantees the reference cannot provide.

Scarcity

A ground-up rearchitecture to replicate

Rebuilding this architecture requires a combination of cryptographic engineering and formal methods expertise that is globally scarce. The Jasmin implementation is not a wrapper around an open-source library. It is a purpose-built, formally verified cryptographic engine.

End-to-end

One platform, not five vendors

Splitting cryptographic discovery, implementation and monitoring across multiple vendors creates gaps at every handoff: inconsistent data models, duplicated onboarding, competing priorities. EQCore governs the full lifecycle in one control plane, with one API, one data model and one chain of accountability.

Multi-vendor approach

Certificate discovery from one vendor. Key management from another. Implementation consulting from a third. Each with its own data format, dashboard and support contract. Gaps between tools become gaps in coverage.

ExeQuantum

CipherScout discovers. CipherForge migrates. CipherWatch monitors. All three share a common data model inside EQCore, with a single CBOM that travels from inventory through remediation to ongoing posture. One vendor, one chain of accountability.

Library-only vendors

Provide PQC algorithms as a library or SDK. No native discovery of what cryptography your estate actually runs. No continuous monitoring. You still need separate tools to find the problem and verify the fix.

ExeQuantum

Owns the discovery engine and the formally verified implementation layer. The same platform that finds your RSA-2048 certificate also executes the ML-KEM swap and alerts you if the certificate reappears in a future scan.

Hyperscaler PQC

Cloud providers are shipping PQC at the edges of their own infrastructure. They are structurally incentivised to confirm their environment is safe, not to surface cryptographic exposure in your on-premises or multi-cloud estate.

ExeQuantum

Vendor-neutral discovery across cloud, on-premises and air-gapped environments. No conflict of interest. CipherScout scans your actual estate, not just the parts inside one provider's boundary.

Sovereignty

Zero access by architecture, not by policy

ExeQuantum's BYOD (Bring Your Own Database) architecture means all scan data is stored in your own provisioned database. We never hold, retain or have persistent access to client data. This is not a policy commitment that could be reversed. It is a structural impossibility built into the platform.

Data residency

Your data stays in your jurisdiction

Scan results, cryptographic inventories and CBOM outputs never cross jurisdictional boundaries. The database is yours, provisioned and controlled within your own infrastructure boundary.

Air-gapped

Deployable without an internet connection

The full platform runs on-premises or in air-gapped environments. The on-premises bundle is verified at install with ML-DSA-65 and minisign, so you can prove the software you run is the software we signed.

Compliance

Audit-ready from day one

BYOD architecture satisfies data sovereignty requirements across GDPR Article 32, NIS2, DORA and sector-specific frameworks. The audit conversation is straightforward: we never had the data.

Why this matters

A policy can be changed. An architecture cannot. When a regulator or auditor asks where your cryptographic inventory data is stored, the answer is simple: in your own database, inside your own boundary, under your own access controls. ExeQuantum never sees it.

Industry engagement

Shaping the standards, not just following them

ExeQuantum contributes to the global PQC conversation through standards bodies, government-backed research partnerships and industry roundtables. We are trusted for technical input, not just as a vendor selling into the space.

ExeQuantum participating in a PKI Consortium Post-Quantum Cryptography Conference roundtable

PKI Consortium Post-Quantum Cryptography Conference roundtable. ExeQuantum alongside Scott Rea (eMudhra / DirectTrust), Anestis Bechtsoudis (CENSUS Labs) and Setiaji (Senior Advisor to the Minister of Health, Republic of Indonesia)

Standards

PKI Consortium

Active participant and roundtable contributor at the PKI Consortium's Post-Quantum Cryptography Conference, the highest-profile global PQC standards event.

Government

AUKUS and ASD

Confirmed AUKUS Authorised User with Licence Free Environment permit for technology transfer across Australia, the UK and the US. Direct engagement with the Australian Signals Directorate.

Research

University partnerships

Peer-reviewed research with RMIT University. Guest lecture partnerships with Swinburne University and Deakin University. Our CTO was a Postdoctoral Fellow at CSIRO Data61.

Third-party recognition

Featured in the Wavestone 2026 PQC Migration Radar, the CIGI G7 Special Report on Quantum Technologies and Finance, and the Austrade Quantum Technology Capability Report. Named as a major player alongside IBM, Thales and Entrust in The Business Research Company's Quantum-Safe HSM Global Market Report. See our full credentials

See what you actually run

Book a discovery scan and receive a Cryptographic Bill of Materials of the cryptography in your estate, without your data leaving your environment.