ML-KEM-1024  ·  ML-DSA-87  ·  FIPS 203/204  ·  NSA CNSA 2.0

The Post Quantum Security Platform
That Already Works.

Ten integrated products with one provenance chain from cryptographic discovery through signed attribution, all operationally deployed today.

Integrated across ten products: discovery, protection, PKI, audit, signing, and attribution fully connected in a single platform
Provenance native: every security event ML-DSA-87 signed, Qledger anchored, and quantum tamper proof from the moment it occurs
Legacy compatible: Qveil wraps any existing system in ML-KEM-1024 hybrid TLS with no code changes and no downtime
NIST FIPS 203 NIST FIPS 204 ETSI TS 103 744 NSA CNSA 2.0

Your encrypted data is already being collected.

Nation state adversaries are executing Harvest Now Decrypt Later campaigns right now. They are capturing your encrypted traffic today so they can decrypt it the moment cryptographically relevant quantum computers arrive.

Most organizations have no idea where their quantum vulnerable RSA and ECC cryptography lives. It is buried in TLS certificates, code signing pipelines, PKI infrastructure, and legacy applications that nobody has audited in years.

NIST finalized post quantum cryptography standards in 2024. Regulatory frameworks are already incorporating PQC requirements to mitigate harvest now decrypt later attacks which could result in financial and legal penalties.

2024
NIST finalized ML-KEM and ML-DSA as official PQC standards under FIPS 203 and FIPS 204
~5 yrs
Estimated window before cryptographically relevant quantum computers can break today's encryption
Today
Harvest Now Decrypt Later attacks are already underway against high value targets across defense, finance, and government

The market has point solutions while we built the PQE platform.

Every serious competitor solves one piece of the PQC problem, key manager, VPN, signing library, but we built the entire stack because your adversaries attack the entire stack and a chain of custody is only as strong as its weakest link.

Integrated provenance, not siloed products

Every product in the Primum & Terminus stack feeds into a shared signed audit chain: quantum-safe digital signatures (ML-DSA-87) on every event, from every product, in real time. QPKI certificate issuance, Qveil TLS sessions, QVPN tunnel handshakes, Qmark attribution events, all anchored to Qledger. That cross-product provenance is the capability no competitor can replicate without building what we already built.

Discover → Protect → Manage → Audit → Sign → Attribute

Legacy compatible by design, not by accident

Qveil adds quantum-safe encryption (ML-KEM-1024 hybrid TLS) to any existing application without code changes. Existing systems do not need to be replaced to become quantum resistant. We meet your infrastructure where it is and harden it in place. No rip and replace, no downtime, no six-month deployment project.

Zero backend changes required

Compliance native, not compliance retrofitted

Every product implements NIST FIPS 203 and FIPS 204 natively, the post-quantum cryptography standards that define what compliance looks like going forward. Every product aligns with ETSI TS 103 744 and satisfies NSA CNSA 2.0 migration requirements out of the box. The compliance posture is not a layer added on top. It is the architecture itself.

NIST FIPS 203/204  ·  ETSI TS 103 744  ·  NSA CNSA 2.0

Built for the highest stakes environments.

Regulated industries, cleared environments, and high value targets face the greatest quantum risk. Every Primum & Terminus product was designed for organizations where a cryptographic failure has consequences measured in national security, patient safety, financial stability, or legal exposure.

Defense &
Aerospace

Healthcare

Financial
Services

Legal

Government

Research &
Academia

Intelligence &
National Security

Energy & Critical
Infrastructure

Entertainment
& Media

Pharma &
Biotech

LIVE DEMOS

No signup required. Every demo below is a running production deployment on the Primum & Terminus stack.

Discover

Qdiscover

The enterprise cryptographic intelligence platform. QDiscover discovers every cryptographic asset in your environment, builds a live cryptographic bill of materials, monitors baselines continuously, and models blast radius across your entire estate. Compliance as code enforces custom policies in real time.

Try Qdiscover →
Discover

Qpen

Purple team platform with built in PQC posture scoring. Run adversarial Harvest Now Decrypt Later simulations, web application scanning, and cryptographic downgrade detection. See your red and blue team score in real time.

Try Qpen →
Protect

Qveil

Watch ML-KEM-1024 hybrid TLS in action. Toggle policy between audit and enforce mode, observe PQC and classical connections hitting the gateway, and see downgrade attempts blocked in real time, without touching a line of backend code.

Try Qveil →
Protect

Qwall

Network PQC policy enforcement in a live demo. Inspect any TLS endpoint, see connections classified as post quantum or classical, and watch the policy engine apply allow, block, and warn rules in real time.

Try Qwall →
Protect

Qvpn

Live quantum safe tunnel sessions. ML-KEM-1024 handshake, AES-256-GCM transport, session provenance anchored to Qledger. See exactly what a post quantum tunnel looks like from the inside: cryptographic parameters, session identity, and audit trail included.

Try QVPN →
Manage

Qpki

A live ML-DSA-87 certificate authority. Issue quantum safe certificates, manage revocation, and see the full PKI chain: root CA, intermediate CA, and end-entity certificates, all signed with FIPS 204 compliant ML-DSA-87.

Try QPKI →
Manage

Qkrypt

Post quantum key vault with live key generation, rotation, and revocation. Generate ML-KEM-1024 and ML-DSA-87 keys, manage the full key lifecycle, and see every key operation anchored to the Qledger audit chain.

Try Qkrypt →
Audit

Qledger

The provenance layer that connects every product. Qledger is a live ML-DSA-87 signed distributed ledger with PBFT consensus. Every security event from across the platform is recorded here, immutable, independently verifiable, and quantum tamper proof.

Try Qledger →
Sign

Qsign

Upload any document and sign it with ML-DSA-87 under FIPS 204. Receive a quantum safe signed envelope you can share and verify independently, with no trusted third party required and no cloud dependency.

Try Qsign →
Attribute

Qmark

Paste text or upload an image to embed an invisible ML-DSA-87 watermark anchored to Qledger. When a document leaks, detection is immediate and provable, not probabilistic. See attribution in action before your adversaries make it necessary.

Try Qmark →
Command

Qterminus

The single pane of glass for your entire post-quantum cryptography posture. Ten products. One view. Real-time readiness scoring, device fleet management, compliance evidence, and threat forecasting — all wired to live platform data.

  • ✓  Live PQC readiness score across all assets
  • ✓  Device fleet with agent telemetry
  • ✓  Compliance evidence & audit trails
  • ✓  Threat forecast & algorithm lifecycle
  • ✓  MFA-protected, Electron desktop available
Try Qterminus →

Example Qterminus dashboard: overall PQC readiness score 94 out of 100. Module scores — QDiscover 98 percent, QPen 87 percent, Algorithm 96 percent, Forecast 91 percent. 12 devices online, 0 critical alerts. Last sync: just now. Figures are illustrative.

Contact Us

Have questions about the platform, want to request a demo, or ready to start your PQC transition? Reach out directly.

brandontirozzi@primumterminus.com

Brandon Tirozzi — Founder, Primum & Terminus