Aviatrix announced Harvest and Decrypt Protection, delivering combined post-quantum encryption and communication governance as a single software policy. The new offering arrives one month before federal civilian agencies face a deadline to file post-quantum migration plans on October 22, positioning Aviatrix ahead of cloud providers like Amazon Web Services, which directs customers to meet regulatory requirements.
“A post-quantum program is usually measured by how much traffic it encrypts,” said Scott Raynovich, Founder and Chief Analyst at Futuriom Research, “The better metric is measuring how much traffic is exposed to capture in the first place.” Aviatrix Harvest Protection comes with five free policies to start, with no trial clock and no purchase required, enabling immediate adoption.
Aviatrix Harvest and Decrypt Protection: Unified Post-Quantum Encryption & Governance
Aviatrix delivers five free post-quantum policies to start, with no trial clock and no purchase required, allowing organizations to begin securing cloud networks without initial purchase or time constraints. This offering provides a low-barrier entry point for addressing potential threats from future quantum computers, enabling enterprises to close initial security gaps before committing to a larger investment.
The first five policies and nodes are available without license or time limit, a strategy designed to accelerate adoption and proactive risk mitigation. Google and Microsoft have both published roadmaps for full quantum readiness in 2029, while Amazon Web Services has not announced a comparable target, instead directing customers to meet regulatory obligations.
Aviatrix’s solution addresses an immediate need for encryption and governance, filling a competitive gap while those longer-term plans develop. The better metric is measuring how much traffic is exposed to capture in the first place.” He continued, “It’s critical to close the open paths that don’t need to be open so that this traffic can’t be recorded today and read years from now.
Closing those paths solves the harvest problem as much as the algorithm does, so the two of them belong in one program rather than two.” Aviatrix’s patented High-Performance Encryption engine distinguishes its approach by avoiding the throughput limitations of standard Internet Protocol Security, which often collapses to around one gigabit per second per tunnel.
This performance improvement is critical for protecting cloud transit, as many enterprises currently leave this traffic unprotected due to bandwidth constraints. Key establishment on the control plane uses the ML-KEM standard today, and hybrid ML-KEM on the data plane is a fast-follow release on the Aviatrix platform roadmap. Beyond encryption, Harvest and Decrypt Protection governs what every workload can reach, reducing potential data exfiltration channels and replacing cloud-native routing that prioritizes connectivity over security.
The company is also collaborating with Microsoft on the Quantum Safe program, providing network traffic and containment. This integration complements existing quantum-safe solutions focused on certificate management and device posture. Aviatrix’s roadmap extends Harvest and Decrypt Protection with crypto visibility, mapping which applications are exposed, what they depend on, and where they communicate in cleartext, the company says. This network-path cryptographic inventory is a capability not currently available through filesystem or certificate scanning.
Google states plainly that customers must manage their own applications, update client-side software, and manage asymmetric key lifecycles, while Amazon Web Services provides point-to-point security with its link-layer encryption and does not provide end-to-end encryption. Aviatrix asserts that the enterprise’s responsibility for security remains within its own infrastructure.
Crypto-Agile Encryption Addresses Data Harvest & Egress Threats
Unlike solutions focused solely on encryption algorithms, Aviatrix’s approach tackles both the risk of data interception and the potential for unauthorized data egress, a combination the company asserts is critical for comprehensive security. According to Aviatrix, the architecture of many cloud environments leaves enterprises vulnerable to data harvesting even without quantum decryption capabilities. Compromised workloads can access and exfiltrate valuable data through ungoverned egress paths, bypassing encryption altogether.
Aviatrix’s solution aims to address this by governing workload reach, limiting the potential damage from a compromised system and reducing the scope of data exposed to capture. The company’s crypto-agile encryption is designed to require no network redesign, hardware refresh, or application changes, simplifying deployment and minimizing disruption, according to Aviatrix. This approach contrasts with the need for extensive client-side updates highlighted by Google, offering a potentially faster path to quantum readiness.
Data retention mandates, ranging from five to thirty years for various record types, fall within the probable timeframe for the arrival of a functional quantum computer, estimated between 2030 and 2035. Doug Merritt, Chief Executive Officer of Aviatrix, said, “Encryption protects data in motion, but most enterprise cloud environments place no constraint on what a compromised workload can reach, exposing valuable data for harvest.” Aviatrix is collaborating with global systems integrators and security services providers to accelerate the availability of Harvest and Decrypt Protection to a wider customer base, and is currently offering five free policies to start, with no trial clock and no purchase required.
Post-quantum readiness is an architecture problem. Encryption protects data in motion, but most enterprise cloud environments place no constraint on what a compromised workload can reach, exposing valuable data for harvest.
Doug Merritt, Chief Executive Officer of Aviatrix
Containment Architecture Limits Workload Reach Beyond Chokepoints
Containment enforces explicit communication policy at every workload, governing both outbound and inbound traffic based on workload identity and protocol, regardless of compromise detection status. This approach differs from chokepoint security, which only controls traffic routed through designated points, leaving ungoverned egress paths vulnerable to data exfiltration. Aviatrix’s solution addresses this by establishing a system where communication is governed on every available path, independent of whether a breach has occurred, effectively limiting the scope of potential damage.
The company delivers this capability through a software-based policy applied across existing network infrastructure, a key distinction from solutions requiring hardware refreshes or extensive network redesigns, the company says. Aviatrix Harvest Protection comes with five free policies to start, with no trial clock and no purchase required, allowing organizations to begin closing critical security gaps without immediate financial commitment.
These policies function as single rules governing what a workload may reach, or how a path is encrypted, offering a granular level of control over network communications. Aviatrix intends this to allow enterprises to address their first five vulnerabilities before making any purchasing decisions. The company frames this as a shift toward a Cloud Native Security Fabric, governing all workload communication across diverse cloud environments, virtual private clouds, Kubernetes clusters, and serverless functions from a single policy plane.
A post-quantum program is usually measured by how much traffic it encrypts. The better metric is measuring how much traffic is exposed to capture in the first place. It’s critical to close the open paths that don’t need to be open so that this traffic can’t be recorded today and read years from now.
Scott Raynovich, Founder and Chief Analyst at Futuriom Research
Source: https://aviatrix.ai/newsroom/press-release/aviatrix-launches-harvest-and-decrypt-protection/




See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
