HX-PQC-Encryption Lifecycle Platform
Cryptographic posture, converted into signed, replayable evidence — from first inventory to continuous assurance.
Free CBOM inventory in one command. Signed, deterministic migration quotes. Runtime protection across Cloud, Self-Hosted, and Air-Gapped editions.
Find every quantum-vulnerable cryptographic dependency. Migrate with signed proof. Protect runtime systems. Prove posture continuously.
The HX-PQC-Encryption Lifecycle Platform converts cryptographic posture into signed, replayable evidence. It starts with a free cryptographic inventory and proceeds through migration, runtime protection, and continuous assurance, across Cloud, Self-Hosted, and Air-Gapped editions.
Cryptography is distributed across source code, libraries, TLS endpoints, certificates, keys, databases, protocols, queues, middleware, identity systems, and vendor products. Most organizations have no authoritative inventory of where asymmetric cryptography exists, which algorithms are quantum-vulnerable, and which systems can migrate without operational disruption. The chain of evidence begins with a CBOM and ends with signed proof.
NIST finalized the first three post-quantum cryptography standards in 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). OMB M-26-15 requires covered federal agencies to submit a PQC Migration Plan to OMB and ONCD within 120 days of June 24, 2026, identifying cryptographic-inventory methods and automated tools. National security systems are excluded.
One lifecycle. Five surfaces.
The split follows the buyer
Every stage has a natural owner, a clear artifact, and a commercial boundary.
Free to know. Paid to change.
Discovery costs nothing and requires no entitlement. Mutation, protection, and standing proof are licensed. The boundary is the same one the buyer already reasons about.
Free cryptographic inventory, CBOM, readiness report, signed quote, and dry-run preview.
Real mutation, key minting, DEK re-wrapping, batch execution, and rollback-aware migration require an entitlement.
Runtime protection for live workloads is licensed as a recurring production capability.
Continuous posture, drift detection, validators, and the ledger explorer are licensed as recurring assurance.
Enterprise standardization across Cloud, Self-Hosted, and Air-Gapped editions.
Three editions
Every surface is available on every edition. The buyer chooses a deployment boundary, not a feature-limited product.
Closed implementation. Open evidence.
The chain begins with a CBOM and ends with signed proof. Every stage emits an artifact a buyer can carry into security, engineering, compliance, procurement, and an executive decision.
Inventory that can travel across teams, and a deterministic commercial scope.
Procurement and entitlement mapping, with license and limits.
Execution plan with rollback, and proof of every asset moved.
Proof of live protection on each protected data operation.
Posture issue lifecycle, and audit evidence.
Signed artifacts, deterministic quotes, ledger replay, and offline verification are the substrate. The implementation is closed; the evidence is open and verifiable without a HolonomiX connection.
The product family uses ML-DSA-65 for signing, ML-KEM-768 where key encapsulation is implemented, and AES-256-GCM for data encryption where applicable. HolonomiX uses NIST-standardized algorithms where implemented.