Post-quantum migration evidence · regulated finance · Latin America and the EU
Find what breaks. Fix it first.
We find the cryptography that quantum computers will break, rank it by how long your data has to stay secret, and plan the migration.
Quantum computers cannot break real keys today. The risk is data copied now and decrypted later, and the deadlines governments have already published.
The clock
Two of these are probabilities. Two are deadlines.
Nobody knows when a quantum computer will break today’s public-key cryptography. The deadlines do not wait for that answer, and neither does an attacker who copies your encrypted data today to decrypt it later.
PROBABILITY · WITHIN 10 YEARS
chance of a cryptographically relevant quantum computer, by expert survey
PROBABILITY · WITHIN 15 YEARS
chance of a cryptographically relevant quantum computer, by expert survey
Post-quantum key establishment
Post-quantum digital signatures
US federal agencies, for high value assets and high impact systems. It also directs a proposed rule requiring covered federal contractors to comply with NIST post-quantum standards by 31 December 2030.
National transition plans and first pilots
High-risk use cases transitioned
Medium-risk use cases transitioned
A recommendation to EU Member States, not a law that binds a firm directly. It cites DORA and NIS2 as rules that already require state-of-the-art cryptography.
Classical key establishment deprecated
Classical public-key algorithms disallowed
US guidance, still a draft. US agencies must align their plans with it.
Probability bands from the Global Risk Institute Quantum Threat Timeline Report 2025 (Mosca and Piani, published March 2026, 26 experts surveyed). Deadlines from US Executive Order 14412, the EU Coordinated Implementation Roadmap, and NIST IR 8547, which is still a draft. Each binds different organizations.
What we do
Four steps.
- 01 FIND
Every place you use cryptography: code, libraries, certificates, network connections, and key management. Each finding records where it was seen.
- 02 RANK
Each asset by one test: how long the data must stay secret, plus how long the migration takes, against the horizon you plan for. If the first two add up to more, it is exposed.
Try the exposure test - 03 PLAN
A migration to the NIST post-quantum standards, usually running old and new side by side first, with a way back at every phase.
Try the algorithm selector - 04 KEEP THE EVIDENCE
A signed, linked record of the work that you keep and your auditor can check without us. Our assessment tooling seals each step, the cryptography inventory, the exposure ranking and the migration plan, as linked receipts in one evidence file that the free checker verifies offline.
How Counterfoil works
Counterfoil
The stub you keep.
Counterfoil is a receipt book for automated work. Each step is written down, linked to the step before it, and signed. If a record is edited later, the link breaks, and anyone can see it with a free checker that runs on their own machine.
It proves the record has not changed and that we signed it. It does not prove the work itself was right, and the receipt says so. Our assessment tooling seals the inventory, the exposure ranking and the migration plan this way.
Work you can check
We measure systems people depend on, in public.
Found a 44-day silent failure in the Stellar Development Foundation’s contract-population workflow and reported it. SDF merged a fix the following day.
contract-wasms issue 26Diagnosed a second pipeline failure to a specific dependency regression, with the failing build identified and remediation routes laid out.
contract-verifications issue 1Published a cross-verifier coverage snapshot of the ecosystem, aggregates only, with the full method attached so anyone can recompute it.
coverage snapshotContributed a measured data point to the Stellar Development Foundation’s verification-registry API design discussion.
stellar discussion 1945ON IBM QUANTUM HARDWARE
CHSH Bell test and GHZ-Mermin on ibm_marrakesh: S = 2.733 (32 sigma over the classical bound of 2), M = -3.859.
A reproduction of textbook physics on a single device, not loophole-free (locality and detection loopholes remain open). Not a novel result.
WHEN WE WERE WRONG
Results we published in March 2026 turned out to have been computed on a simulator, not the quantum hardware they were labeled with. We found it and corrected it in public.
Read the correctionThe tools
What is live, and what is not yet public.
2 tools run in your browser today. The others are built and tested and are used in our engagements, but you cannot open them yet.
Algorithm Selector
LIVEPick the right post-quantum algorithm for your use case. Deterministic routing through NIST standards (FIPS 203/204/205). Every recommendation traceable. Free tool.
OpenCryptographic Inventory
BUILT · NOT PUBLICScan your codebase and find every cryptographic asset: keys, certificates, protocols, libraries. Output: a machine-readable inventory with quantum risk scores.
Quantum Key Provenance
IN BUILDA signed certificate of where key material came from, checkable offline. Our quantum entropy source is not running today, so no quantum-origin certificate is issued.
Migration Tracker
DEMOTrack a post-quantum migration against regulatory deadlines. The public version is a demo with sample data that saves nothing. The full tracker, with a hash-chained audit trail and PDF export, is built and tested but not public.
OpenCrypto-Agility Planner
BUILT · NOT PUBLICMap your cryptographic dependencies, plan phased migration (classical → hybrid → post-quantum), and roll back any phase if needed.
Key Management
BUILT · NOT PUBLICPost-quantum key management compatible with AWS KMS. Supports ML-KEM and ML-DSA at all security levels. AES-256-GCM encryption at rest.
Regional Compliance Bridge
BUILT · NOT PUBLICMap NIST post-quantum standards to LATAM regulators: SUGEF, SFC, CNBV, BACEN, CMF. Deterministic knowledge base, never LLM-generated. Spanish, Portuguese, English output.
Secure Agent Sandbox
BUILT · NOT PUBLICA process-level environment for running AI agents: scope firewall, audit log, post-quantum key protection at rest, and automatic shutdown if boundaries are crossed. Post-quantum channel encryption and signed model manifests are on the roadmap.
Counterfoil
FLAGSHIPA receipt book for automated work: signed, linked records anyone can check with a free checker. Our assessments seal the inventory, the exposure ranking and the migration plan as linked receipts; other tools are not connected yet.
OpenStore-Now-Break-Later Risk Score
LIVECheck whether data copied today stays secret long enough: how long it must stay secret plus how long migration takes, against the horizon you plan for. Runs in your browser; nothing is sent.
OpenQuantum Hardware Connector
IN BUILDTranslates circuits for several quantum backends and estimates what a run would cost. It does not submit jobs yet.
Start here
What breaks, what does not, and what to fix first.
A scoped quantum threat assessment, delivered as a document you own. Based in Costa Rica, working in English and Spanish, in Latin American and European time zones.