Crypto agility
Long-lived systems need more than a single algorithm. They need the ability to adapt. PQSecure™-Agility enables continuous cryptographic agility across Secure Boot, Root of Trust, TLS, IPsec, MACsec, and embedded platforms.
In development. Contact us about early evaluation.
Cryptographic matrix
| Module | Family | Status |
|---|---|---|
| ML-KEM, ML-DSA, SLH-DSA | Post-quantum | In the suite |
| LMS, XMSS | Stateful hash | In the suite |
| AES-GCM, SHA-3 | Symmetric and hash | In the suite |
| CNSA 2.0 additions | Post-quantum | Future |
| Hybrid classical modes | Transitional | Future |
Silicon speed on one side, software reach on the other
Hardware holds the root of trust and the throughput. Software decides what the hardware runs. Neither half alone gives a long-lived system the ability to change its cryptography.
Two halves
-
Hardware-enforced security
The unshakeable root of trust and the speed of physical silicon, without trapping the infrastructure in obsolete cryptography
Provides
- Dedicated side-channel execution boundaries
- Physical fault injection resistance
- High-throughput line-rate acceleration
- Hardware-backed secure key storage
-
Software-defined adaptability
Cryptographic posture updated over time as standards, compliance mandates, and network policies mature
Provides
- Over-the-air algorithm updates
- Seamless runtime security level scaling
- Active policy and algorithm deprecation
- Crypto-agile fallback mechanisms
Engineered for an unknown tomorrow
Whether a deployment runs current standards or algorithms that have not been written yet, the point is to evolve without redesigning hardware.
Where agility applies
- Secure Boot and Root of Trust
-
Anchors platform start-up in an agile root of trust, so authentication keys can rotate safely across decades of field deployment.
- Network protocols
-
Native agility across high-volume data-in-transit pipelines, with support for modern TLS, IPsec, and MACsec traffic.
- Hardware and software co-design
-
Removes the traditional bottleneck between slow, flexible software patches and rigid, ultra-fast hardware accelerators.
- Side-channel and fault injection defense
-
Agility does not compromise assurance. Every selectable algorithm runs inside strictly protected, differential-power-hardened IP.
- Future-proof posture
-
Decouples the product lifecycle from the cryptographic lifecycle. When NIST updates a standard, deployed silicon adapts.
Changing algorithms is an operation, not a project
Swapping cryptography in a fielded system usually means a firmware campaign, a maintenance window, and a fallback plan written by hand.
These are the mechanics that make it routine instead: the policy changes, the keys roll, and the device keeps serving traffic while it happens.
Agile mechanics
- Runtime policy swapping The selected algorithm changes without a rebuild
- Automated key rollover New keys take over without manual staging
- Zero-downtime migration The device keeps serving through the change
- Hardware-safe fallback A failed change lands somewhere known good
Designed for mission-critical lifecycles
Built for systems that have to survive a shifting cryptographic landscape rather than a single standards cycle.
Engineered for
- Government
- Defense
- Aerospace
- Critical infrastructure
- Long-range commercial systems
We combine
- Zero hardware respins
- Runtime policy updates
- Secure Boot and Root of Trust
- TLS, IPsec, and MACsec
- NIST CAVP validation
so a deployment can adapt to standards that do not exist yet.
Certification
A software-driven hardware cryptographic implementation, controlled through a software layer written in generic C.
- Validated
-
- ML-KEM FIPS 203
- ML-DSA FIPS 204
- SLH-DSA FIPS 205
- Vendor
- PQSecure Technologies
The implementation is validated. The product itself has not launched.
Agility has to be designed in, not added later.
Talk with our engineering team about early evaluation and where it needs to sit in your architecture.
Contact us