Skip to content
HolonomiX
Products/HX-PQC-Encryption Lifecycle Platform
Available now · Private Appliance · Scoped Pilot

HX-PQC-Encryption Lifecycle Platform

Cryptographic posture becomes signed, replayable evidence from first inventory to continuous assurance.

Scan produces a signed file-protection inventory and a derived CycloneDX CBOM within the authorized scope. The platform also produces signed, deterministic migration quotes. Runtime protection is available in customer-controlled environments; Cloud, Self-Hosted, and Air-Gapped editions are planned next.

StatusPrivate Appliance · Scoped Pilot
EditionsRoadmap: Cloud · Self-Hosted · Air-Gapped
StandardsInventories FIPS 203, 204, 205
Signs with ML-DSA-65
Entry pointFree scan · CycloneDX 1.6 CBOM
ProcurementPrivate offer / pilot
Discover → Quote → Migrate → Protect → Assure → Prove

Evaluate HX-PQC for your team

Who it serves
Security and platform teams responsible for cryptographic inventory, migration and ongoing protection.
When to evaluate
You need to establish the cryptography in an authorized scope, plan its migration and retain evidence of protection and posture.
Outcome to establish
An inventory, derived CBOM and signed migration quote, with migration events, runtime evidence and posture snapshots from the licensed services in scope.
Deployment
Private Appliance · Scoped pilot
Evidence to review
CBOM, signed deterministic quotes, migration events, runtime evidence and posture snapshots
Commercial starting point
Request free Scan access for an authorized scope. Migration, runtime protection and continuous assurance require separately scoped licensing through a Private Appliance or pilot engagement.

HX-PQC connects cryptographic discovery within an authorized scope to migration, runtime protection and continuous assurance, with signed evidence at each stage.

The HX-PQC-Encryption Lifecycle Platform converts cryptographic posture into signed, replayable evidence. It starts with a free cryptographic inventory and proceeds through migration, runtime protection, and continuous assurance, delivered through customer-controlled Private Appliance and scoped pilot engagements; Cloud, Self-Hosted, and Air-Gapped editions are prioritized next.

Cryptography is distributed across source code, libraries, TLS endpoints, certificates, keys, databases, protocols, queues, middleware, identity systems, and vendor products. Most organizations have no authoritative inventory of where asymmetric cryptography exists, which algorithms are quantum-vulnerable, and which systems can migrate without operational disruption. The chain of evidence begins with a CBOM and ends with signed proof.

Federal driver

NIST finalized the first three post-quantum cryptography standards in 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). OMB M-26-15 requires covered federal agencies to submit a PQC Migration Plan to OMB and ONCD within 120 days of June 24, 2026, identifying cryptographic-inventory methods and automated tools. National security systems are excluded.

Discover → Quote → Migrate → Protect → Assure → Prove

Free Scan access and scope

Request Scan access with the operating system, source types and authorized scope you intend to inspect. Scan is free; migration and continuing protection require their own entitlement.

Access and installation

The customer appliance provides signed collector packages for Linux x86-64 and Windows through WSL. An appliance administrator enrolls the collector using a one-time token. Use the installation instructions and release verification material supplied for that appliance.

The inquiry begins access coordination. It does not create an account or start a scan.

Inspection scope

For file inspection, authorize a real directory, its recursive scope and the collector's read permissions. The collector reads files locally and sends signed inspection records rather than file contents. It records exclusions and inspection failures; symlinks are excluded.

Browser folder selection supplies a metadata preview. Content inspection requires the local collector. Confirm supported connectors and permissions separately for databases, certificates and other sources.

Reviewable results

The file-protection manifest records the enumerated files and their encrypted, unencrypted or unresolved states. Its CycloneDX CBOM is a derived view of cryptographic findings. Review unresolved and incomplete coverage alongside the findings before estimating migration scope.

Discovery and estimates do not authorize mutation.

The PQC lifecycle from discovery through continuous assurance

Scan · Free

Scan: inventory and migration estimates

Free cryptographic inventory, CycloneDX CBOM, readiness report, signed deterministic quote, and dry-run preview.

Migrate: execution and asset evidence

Turns a scan into a migration plan, mints post-quantum key material, re-wraps data-encryption keys, and executes approved batches with rollback-aware, ledgered proof.

Runtime: workload protection

A PQC encryption service, SDK, middleware, enforcement engine, and key-rotation operations for production systems.

Assure: continuous posture verification

Recurring discovery, drift detection, posture scoring, validators, findings management, and signed posture snapshots.

Platform: the enterprise bundle

Migrate, Runtime, and Assure under one platform agreement, with Scan as the free starting point. The bundle extends across Cloud, Self-Hosted, and Air-Gapped editions as they launch.

Commercial boundaries across the cryptographic lifecycle

Every stage has a natural owner, a clear artifact, and a commercial boundary.

What cryptography do we have?

Scan produces the inventory and the CBOM.

Commercial boundary Free

What would migration cost?

Scan produces a signed deterministic quote.

Commercial boundary Free quote

Can we safely remediate?

Migrate plans and executes the migration with ledgered proof.

Commercial boundary Paid mutation

Are live workloads using quantum-ready protection?

Runtime adds the SDK, middleware, service, and evidence.

Commercial boundary Recurring license

Can we prove posture continuously?

Assure monitors drift and validates posture.

Commercial boundary Recurring license

Can we make this the enterprise standard?

Platform bundles the full lifecycle.

Commercial boundary Platform agreement

Free discovery and licensed services

Discovery costs nothing and requires no entitlement. Mutation, protection, and standing proof are licensed. The boundary is the same one the buyer already reasons about.

Free to know HX-PQC Scan

Free cryptographic inventory, CBOM, readiness report, signed quote, and dry-run preview.

Paid to change HX-PQC Migrate

Real mutation, key minting, DEK re-wrapping, batch execution, and rollback-aware migration require an entitlement.

Recurring to protect HX-PQC Runtime

Runtime protection for live workloads is licensed as a recurring production capability.

Recurring to prove HX-PQC Assure

Continuous posture, drift detection, validators, and the ledger explorer are licensed as recurring assurance.

Premium to control HX-PQC Platform

Enterprise standardization under one platform agreement as editions launch.

Planned deployment editions

Current delivery is a customer-controlled Private Appliance or scoped pilot, with packaging, updates, support and licensed services agreed for the engagement. The planned editions below describe standardized operating and entitlement arrangements; they are not additional routes available to order today.

Cloud

Fast-start teams, marketplace buyers, commercial pilots.

Commercial posture Subscription, private offer, or platform agreement.
Operational boundary HolonomiX-hosted services with customer connectors.
Entitlement verification Online plus cached validation
Evidence export Download and API export

Self-Hosted

Enterprises with VPC or Kubernetes and internal controls.

Commercial posture Annual platform agreement plus support.
Operational boundary Customer-controlled runtime in the customer environment.
Entitlement verification Local verification with signed entitlement
Evidence export Local export and optional support bundle

Air-Gapped

Defense, critical infrastructure, sovereign and restricted networks.

Commercial posture Premium annual appliance or private deployment.
Operational boundary Offline entitlements, offline updates, local evidence export.
Entitlement verification Offline verification only
Evidence export Removable media, signed export

Closed implementation with independently verifiable evidence

The chain begins with a CBOM and ends with signed proof. Every stage emits an artifact a buyer can carry into security, engineering, compliance, procurement, and an executive decision.

Scan
CBOM CycloneDX 1.6
Readiness report JSON, PDF, HTML
Signed quote JSON, PDF

Inventory that can travel across teams, and a deterministic commercial scope.

Commercial
Order JSON, PDF
Entitlement Signed token

Procurement and entitlement mapping, with license and limits.

Migrate
Migration plan JSON, PDF
Migration event Ledger event

Execution plan with rollback, and proof of every asset moved.

Runtime
Protected envelope Binary with JSON metadata
Runtime evidence Ledger event

Proof of live protection on each protected data operation.

Assure
Finding JSON
Posture snapshot Signed JSON, PDF

Posture issue lifecycle, and audit evidence.

Signed artifacts, deterministic quotes, ledger replay, and offline verification are the substrate. The implementation is closed; the evidence is open and verifiable without a HolonomiX connection.

The product family uses ML-DSA-65 for signing and AES-256-GCM for data encryption where applicable. HolonomiX uses NIST-standardized algorithms where implemented.

Scope the cryptographic lifecycle

Security and platform teams managing cryptographic discovery, migration, runtime protection and continuous assurance across the PQC lifecycle.

Inputs

Repositories or environments, authorized scope, target cryptographic policy, migration requirements and runtime or assurance integrations.

Outputs

A CBOM and signed deterministic quote from Scan; ledgered migration events from Migrate; protection evidence from Runtime; and posture snapshots from Assure, according to the selected services.

Limits

Scan inventories and estimates without mutation. Migration, runtime protection and continuous assurance are licensed and scoped separately. Planned deployment editions do not imply current air-gapped operation.

Availability: Private Appliance · Scoped pilot.