HX-PQC-Encryption Lifecycle Platform
Cryptographic posture becomes signed, replayable evidence from first inventory to continuous assurance.
Scan produces a signed file-protection inventory and a derived CycloneDX CBOM within the authorized scope. The platform also produces signed, deterministic migration quotes. Runtime protection is available in customer-controlled environments; Cloud, Self-Hosted, and Air-Gapped editions are planned next.
Signs with ML-DSA-65
Evaluate HX-PQC for your team
- Who it serves
- Security and platform teams responsible for cryptographic inventory, migration and ongoing protection.
- When to evaluate
- You need to establish the cryptography in an authorized scope, plan its migration and retain evidence of protection and posture.
- Outcome to establish
- An inventory, derived CBOM and signed migration quote, with migration events, runtime evidence and posture snapshots from the licensed services in scope.
- Deployment
- Private Appliance · Scoped pilot
- Evidence to review
- CBOM, signed deterministic quotes, migration events, runtime evidence and posture snapshots
- Commercial starting point
- Request free Scan access for an authorized scope. Migration, runtime protection and continuous assurance require separately scoped licensing through a Private Appliance or pilot engagement.
HX-PQC connects cryptographic discovery within an authorized scope to migration, runtime protection and continuous assurance, with signed evidence at each stage.
The HX-PQC-Encryption Lifecycle Platform converts cryptographic posture into signed, replayable evidence. It starts with a free cryptographic inventory and proceeds through migration, runtime protection, and continuous assurance, delivered through customer-controlled Private Appliance and scoped pilot engagements; Cloud, Self-Hosted, and Air-Gapped editions are prioritized next.
Cryptography is distributed across source code, libraries, TLS endpoints, certificates, keys, databases, protocols, queues, middleware, identity systems, and vendor products. Most organizations have no authoritative inventory of where asymmetric cryptography exists, which algorithms are quantum-vulnerable, and which systems can migrate without operational disruption. The chain of evidence begins with a CBOM and ends with signed proof.
NIST finalized the first three post-quantum cryptography standards in 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). OMB M-26-15 requires covered federal agencies to submit a PQC Migration Plan to OMB and ONCD within 120 days of June 24, 2026, identifying cryptographic-inventory methods and automated tools. National security systems are excluded.
Free Scan access and scope
Request Scan access with the operating system, source types and authorized scope you intend to inspect. Scan is free; migration and continuing protection require their own entitlement.
Access and installation
The customer appliance provides signed collector packages for Linux x86-64 and Windows through WSL. An appliance administrator enrolls the collector using a one-time token. Use the installation instructions and release verification material supplied for that appliance.
The inquiry begins access coordination. It does not create an account or start a scan.
Inspection scope
For file inspection, authorize a real directory, its recursive scope and the collector's read permissions. The collector reads files locally and sends signed inspection records rather than file contents. It records exclusions and inspection failures; symlinks are excluded.
Browser folder selection supplies a metadata preview. Content inspection requires the local collector. Confirm supported connectors and permissions separately for databases, certificates and other sources.
Reviewable results
The file-protection manifest records the enumerated files and their encrypted, unencrypted or unresolved states. Its CycloneDX CBOM is a derived view of cryptographic findings. Review unresolved and incomplete coverage alongside the findings before estimating migration scope.
Discovery and estimates do not authorize mutation.
The PQC lifecycle from discovery through continuous assurance
Scan: inventory and migration estimates
Free cryptographic inventory, CycloneDX CBOM, readiness report, signed deterministic quote, and dry-run preview.
Migrate: execution and asset evidence
Turns a scan into a migration plan, mints post-quantum key material, re-wraps data-encryption keys, and executes approved batches with rollback-aware, ledgered proof.
Runtime: workload protection
A PQC encryption service, SDK, middleware, enforcement engine, and key-rotation operations for production systems.
Assure: continuous posture verification
Recurring discovery, drift detection, posture scoring, validators, findings management, and signed posture snapshots.
Platform: the enterprise bundle
Migrate, Runtime, and Assure under one platform agreement, with Scan as the free starting point. The bundle extends across Cloud, Self-Hosted, and Air-Gapped editions as they launch.
Commercial boundaries across the cryptographic lifecycle
Every stage has a natural owner, a clear artifact, and a commercial boundary.
What cryptography do we have?
Scan produces the inventory and the CBOM.
What would migration cost?
Scan produces a signed deterministic quote.
Can we safely remediate?
Migrate plans and executes the migration with ledgered proof.
Are live workloads using quantum-ready protection?
Runtime adds the SDK, middleware, service, and evidence.
Can we prove posture continuously?
Assure monitors drift and validates posture.
Can we make this the enterprise standard?
Platform bundles the full lifecycle.
Free discovery and licensed services
Discovery costs nothing and requires no entitlement. Mutation, protection, and standing proof are licensed. The boundary is the same one the buyer already reasons about.
Free cryptographic inventory, CBOM, readiness report, signed quote, and dry-run preview.
Real mutation, key minting, DEK re-wrapping, batch execution, and rollback-aware migration require an entitlement.
Runtime protection for live workloads is licensed as a recurring production capability.
Continuous posture, drift detection, validators, and the ledger explorer are licensed as recurring assurance.
Enterprise standardization under one platform agreement as editions launch.
Planned deployment editions
Current delivery is a customer-controlled Private Appliance or scoped pilot, with packaging, updates, support and licensed services agreed for the engagement. The planned editions below describe standardized operating and entitlement arrangements; they are not additional routes available to order today.
Cloud
Fast-start teams, marketplace buyers, commercial pilots.
Self-Hosted
Enterprises with VPC or Kubernetes and internal controls.
Air-Gapped
Defense, critical infrastructure, sovereign and restricted networks.
Closed implementation with independently verifiable evidence
The chain begins with a CBOM and ends with signed proof. Every stage emits an artifact a buyer can carry into security, engineering, compliance, procurement, and an executive decision.
Inventory that can travel across teams, and a deterministic commercial scope.
Procurement and entitlement mapping, with license and limits.
Execution plan with rollback, and proof of every asset moved.
Proof of live protection on each protected data operation.
Posture issue lifecycle, and audit evidence.
Signed artifacts, deterministic quotes, ledger replay, and offline verification are the substrate. The implementation is closed; the evidence is open and verifiable without a HolonomiX connection.
The product family uses ML-DSA-65 for signing and AES-256-GCM for data encryption where applicable. HolonomiX uses NIST-standardized algorithms where implemented.
Scope the cryptographic lifecycle
Security and platform teams managing cryptographic discovery, migration, runtime protection and continuous assurance across the PQC lifecycle.
Inputs
Repositories or environments, authorized scope, target cryptographic policy, migration requirements and runtime or assurance integrations.
Outputs
A CBOM and signed deterministic quote from Scan; ledgered migration events from Migrate; protection evidence from Runtime; and posture snapshots from Assure, according to the selected services.
Limits
Scan inventories and estimates without mutation. Migration, runtime protection and continuous assurance are licensed and scoped separately. Planned deployment editions do not imply current air-gapped operation.
Availability: Private Appliance · Scoped pilot.