ExeQuantum launches EQCore for quantum-enhanced encryption system mapping

Beginning January 2027, new national security systems will require post-quantum cryptography, a mandate that has organizations scrambling to assess their cryptographic vulnerabilities. ExeQuantum aims to accelerate this transition with EQCore, a platform designed to discover, remediate, and continuously govern cryptographic risk. The platform, deployable in “days” across any environment, connects discovery, remediation, and governance into a single operational layer. ExeQuantum’s solution centers on three products: CipherScout for discovery, CipherForge for implementation, and CipherWatch for ongoing monitoring, delivering end-to-end migration aligned with standards like NIST, CNSA 2.0, and ISM.

CipherScout Discovers Cryptographic Assets Across Hybrid Environments

CipherScout delivers a Cryptographic Bill of Materials (CBOM) in CycloneDX 1.7 format, a machine-readable inventory detailing every algorithm, key length, certificate, and cryptographic dependency within an organisation’s digital infrastructure. This detailed accounting addresses a critical initial hurdle for businesses facing impending post-quantum cryptography (PQC) mandates, as many significantly underestimate the scope of their cryptographic footprint; a single virtual machine can contain over 150 discrete cryptographic assets.

ExeQuantum’s approach moves beyond simple awareness, providing a granular view of exposure across ten distinct attack surfaces, including TLS endpoints, APIs, and cloud key management systems. The need for such comprehensive discovery is underscored by evolving governmental regulations; CNSA 2.0 will require compliance with PQC for new national security system acquisitions beginning January 2027, while the Australian Signals Directorate’s Information Security Manual (ISM) targets PQC mandates by 2030.

These timelines demand a proactive approach, and CipherScout is designed to rapidly identify cryptographic vulnerabilities that standard tooling often misses, providing a comprehensive view of an organisation’s cryptographic posture. The resulting CBOM isn’t merely a list, but a foundation for a formal migration programme, increasingly becoming a procurement requirement in regulated sectors. Beyond identifying existing cryptographic assets, ExeQuantum’s EQCore platform, powered by CipherScout, is designed for deployment across diverse environments, cloud, on-premise, or even fully air-gapped systems, allowing organisations to maintain control over their keys and data within their own jurisdiction.

This sovereign encryption capability is particularly important for those handling sensitive information or operating in highly regulated industries. The platform’s speed is a key differentiator, with ExeQuantum claiming a working integration requires a single API call to connect with existing application stacks.

The company reports that its system can analyse JWT fleets at a fleet-level population analysis rather than inspecting individual tokens, offering a more efficient and accurate assessment of risk. This granular level of detail is essential for organisations preparing for the transition to PQC, as it allows them to prioritise remediation efforts and allocate resources effectively. “You cannot migrate what you cannot see,” highlights the fundamental principle driving ExeQuantum’s approach to cryptographic discovery, the company says.

The platform’s output aligns with regulatory frameworks, including NIST standards, facilitating compliance reporting and audit trails for regulatory evidence. For Chief Information Security Officers (CISOs) and risk officers, CipherWatch, a continuous monitoring component of EQCore, ensures ongoing protection against evolving threats. Organisations that proactively begin migration now, using tools like CipherScout, will have the time to test, validate, and iterate their security posture, mitigating the risks associated with compressed timelines and potential vulnerabilities.

CipherForge Implements Formally Verified NIST Post-Quantum Algorithms

CipherForge delivers a production-ready implementation of formally verified post-quantum cryptography, supporting the complete suite of NIST FIPS 203, 204, and 205 algorithms, ML-KEM, ML-DSA, and SLH-DSA, alongside emerging standards like Mceliece and FrodoKEM, alongside ISO/IEC 18033-2 Amd 2:2026. This capability addresses a critical gap in the transition to post-quantum security, moving beyond theoretical readiness to provably secure execution within enterprise environments. Unlike many initial PQC implementations, CipherForge is designed for high-throughput applications where both security assurance and operational speed are paramount, eliminating the performance trade-offs often associated with formal verification processes.

The platform’s design prioritises deployment flexibility, offering cloud, on-premise, and hybrid models to accommodate diverse operational and compliance needs. This adaptability is important given the approaching regulatory deadlines; CNSA 2. ExeQuantum positions CipherForge as a solution enabling organisations to meet these timelines without compromising performance or security, a claim substantiated by its focus on formal verification.

The company’s approach aims to eliminate the risk of vulnerabilities present in even well-regarded implementations, delivering provably secure execution by construction. Formal verification, a rigorous mathematical process, ensures that the software behaves exactly as intended, eliminating potential loopholes that could be exploited by attackers. ExeQuantum’s implementation of this process for PQC algorithms is particularly noteworthy, as it addresses a key concern in the field: the potential for subtle flaws in complex cryptographic code.

This is about providing a demonstrable level of assurance that the encryption is truly unbreakable, even against future quantum computing attacks. Custom and national-standard algorithms can also be integrated, catering to jurisdictions with specific cryptographic requirements, further broadening the platform’s applicability. The speed of deployment is another key differentiator, with ExeQuantum claiming a timeframe of “days” rather than months for integration into existing application stacks with a single API call.

This claim is supported by the platform’s embedded library format and centralised management dashboard, designed to minimise friction during implementation. The company’s EQCore control plane, of which CipherForge is a core component, streamlines the entire post-quantum migration process, from discovery of cryptographic assets with CipherScout to continuous compliance monitoring with CipherWatch, according to ExeQuantum. “Discovery tells you where you are exposed. CipherForge closes the gap,” explains the company, highlighting the platform’s end-to-end functionality.

Beyond simply performing cryptographic operations, EQCore is built to align with regulatory frameworks governing cryptographic standards, producing the evidence and reporting required by compliance teams, auditors, and regulators. Specifically, the platform maps to the cryptographic requirements of various frameworks, including NIST CSF, ISO 27001, and the Australian Essential Eight. This alignment is particularly critical for organisations handling sensitive data with long-term confidentiality requirements, such as financial institutions managing decades of transaction records or healthcare organisations protecting patient data.

The urgency of this migration is underscored by the concept of the (HNDL) threat, where adversaries are currently collecting encrypted data with the intention of decrypting it once quantum computers become powerful enough. For such organisations, the window for protecting data is rapidly closing, and the only viable defence is migrating to quantum-resistant algorithms before decryption capabilities emerge. ExeQuantum’s EQCore, with CipherForge at its heart, provides a complete pathway to address this threat, offering a comprehensive solution for discovering, migrating, and continuously monitoring cryptographic exposure.

EQCore Platform Integrates Discovery, Remediation, and Governance

EQCore establishes a unified operational layer for cryptographic risk management, moving beyond isolated security tools to govern cryptography as a core domain, according to ExeQuantum. The platform’s design prioritises sovereignty, transparency, agility, and compliance, principles embodied in the company’s STAC doctrine, and integrates with existing systems like SIEM, GRC, CSPM, and IAM. This approach positions EQCore not as a replacement for current security infrastructure, but as a governing system operating above it, streamlining post-quantum migration and continuous monitoring. The platform’s core functionality is delivered through three interconnected products: CipherScout, CipherForge, and CipherWatch.

Deployment options are designed for flexibility, ranging from on-premise installations operating within existing infrastructure to fully air-gapped environments where the platform functions entirely offline, maintaining data jurisdiction and security. Traditional post-quantum migration projects often span quarters or years, but ExeQuantum aims to compress this timeline significantly. The platform’s containerised deployment, clean API interface, and integrated discovery and remediation capabilities allow organisations to transition from initial assessment to production-ready PQC in days, a timeframe substantially faster than industry expectations. This speed is increasingly critical given approaching compliance deadlines, including the CNSA 2.

CipherWatch Enables Continuous Compliance Monitoring of PQC Migration

The platform’s continuous monitoring capabilities distinguish it from initial migration efforts, acknowledging that cryptographic posture is not static, but subject to drift from new certificates, updated dependencies, and evolving threats. This ongoing assessment is important as compliance deadlines loom, with CNSA 2.0 mandating post-quantum algorithms for new national security systems beginning January 2027 and the ASD ISM targeting PQC adoption by 2030. The system’s architecture operates on a Bring Your Own Database (BYOD) model, a deliberate design choice to maintain data sovereignty for clients.

All scan data, cryptographic inventories, and compliance reports reside within the client’s provisioned database, meaning ExeQuantum does not retain persistent access to sensitive information. “This is not a marketing claim,” the company states, underscoring the commitment to data privacy and control. This approach addresses concerns about data residency and jurisdictional requirements, particularly relevant for government agencies and organisations handling highly confidential information.

The speed of deployment, measured in days rather than months, is enabled by a working integration requiring a single API call. Beyond simply identifying cryptographic vulnerabilities, CipherWatch generates an audit trail for regulatory evidence and board reporting. The system also manages the lifecycle of algorithms, tracking deprecation timelines and migration progress, and automatically alerts security teams to quantum-vulnerable assets introduced into the environment. This proactive approach allows organisations to address emerging risks before they can be exploited, and to demonstrate a robust cryptographic posture to stakeholders.

“The data being harvested today cannot be retroactively protected,” the company explains, emphasizing the urgency of migrating to quantum-resistant algorithms. CipherForge then implements formally verified post-quantum algorithms, while CipherWatch ensures ongoing compliance.

This integrated approach, aligned with regulatory frameworks like NIST CSF, ISO 27001, and the Australian Essential Eight, provides a comprehensive pathway to quantum resilience. The company’s alignment with these frameworks extends to mapping findings to NIST control references and the Australian Essential Eight, simplifying the compliance process for organisations operating under those standards. The ability to deploy EQCore in air-gapped environments, fully isolated from external connectivity, further enhances its appeal to organisations with the most stringent security requirements.

This capability ensures that sensitive data remains within a controlled perimeter, mitigating the risk of external compromise. ExeQuantum’s focus on sovereign encryption and standards-alignment positions it as a key player in the emerging post-quantum cryptography market. The second-best time is now,” the company concludes, urging organisations to act decisively to protect their data in the quantum era.

ExeQuantum, founded in 2024 and headquartered in Melbourne, Australia, is positioning itself as a key player in this transition, offering a comprehensive solution designed to address the complex challenges of post-quantum cryptography. The company’s strategic partnerships, including integration with SharePass and a July 2026 partnership with Grant Thornton UAE, further demonstrate its commitment to delivering PQC readiness across diverse industries and geographies, the company says.

Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Rusty Flint

Rusty Flint

Rusty is a quantum science nerd. He's been into academic science all his life, but spent his formative years doing less academic things. Now he turns his attention to write about his passion, the quantum realm. He loves all things Quantum Physics especially. Rusty likes the more esoteric side of Quantum Computing and the Quantum world. Everything from Quantum Entanglement to Quantum Physics. Rusty thinks that we are in the 1950s quantum equivalent of the classical computing world. While other quantum journalists focus on IBM's latest chip or which startup just raised $50 million, Rusty's over here writing 3,000-word deep dives on whether quantum entanglement might explain why you sometimes think about someone right before they text you. (Spoiler: it doesn't, but the exploration is fascinating)

Latest Posts by Rusty Flint: