Skip to content
HolonomiX
Products/HX-PQC-Encryption Lifecycle Platform
Deployed

HX-PQC-Encryption Lifecycle Platform

Cryptographic posture, converted into signed, replayable evidence — from first inventory to continuous assurance.

Free CBOM inventory in one command. Signed, deterministic migration quotes. Runtime protection across Cloud, Self-Hosted, and Air-Gapped editions.

StatusDeployed
EditionsCloud · Self-Hosted · Air-Gapped
StandardsFIPS 203 · FIPS 204 · FIPS 205
Entry pointFree scan — CycloneDX 1.6 CBOM
ProcurementPrivate offer / pilot
Discover Quote Migrate Protect Assure Prove

Find every quantum-vulnerable cryptographic dependency. Migrate with signed proof. Protect runtime systems. Prove posture continuously.

The HX-PQC-Encryption Lifecycle Platform converts cryptographic posture into signed, replayable evidence. It starts with a free cryptographic inventory and proceeds through migration, runtime protection, and continuous assurance, across Cloud, Self-Hosted, and Air-Gapped editions.

Cryptography is distributed across source code, libraries, TLS endpoints, certificates, keys, databases, protocols, queues, middleware, identity systems, and vendor products. Most organizations have no authoritative inventory of where asymmetric cryptography exists, which algorithms are quantum-vulnerable, and which systems can migrate without operational disruption. The chain of evidence begins with a CBOM and ends with signed proof.

Federal driver

NIST finalized the first three post-quantum cryptography standards in 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). OMB M-26-15 requires covered federal agencies to submit a PQC Migration Plan to OMB and ONCD within 120 days of June 24, 2026, identifying cryptographic-inventory methods and automated tools. National security systems are excluded.

Discover Quote Migrate Protect Assure Prove

One lifecycle. Five surfaces.

Scan · Free

Know your quantum-vulnerable crypto and what it costs to fix in one command.

Free cryptographic inventory, CycloneDX CBOM, readiness report, signed deterministic quote, and dry-run preview.

Migrate

Execute the post-quantum migration with proof of every asset moved.

Turns a scan into a migration plan, mints post-quantum key material, re-wraps data-encryption keys, and executes approved batches with rollback-aware, ledgered proof.

Runtime

Protect live workloads with PQC runtime controls and signed evidence.

A PQC encryption service, SDK, middleware, enforcement engine, and key-rotation operations for production systems.

Assure

Prove PQC posture continuously across environments.

Recurring discovery, drift detection, posture scoring, validators, findings management, and signed posture snapshots.

Platform

The enterprise bundle: Migrate, Runtime, and Assure with the free Scan on-ramp.

Enterprise standardization across Cloud, Self-Hosted, and Air-Gapped editions under one platform agreement.

The split follows the buyer

Every stage has a natural owner, a clear artifact, and a commercial boundary.

Discover

What cryptography do we have?

Scan produces the inventory and the CBOM.

Commercial boundary Free
Quote

What would migration cost?

Scan produces a signed deterministic quote.

Commercial boundary Free quote
Migrate

Can we safely remediate?

Migrate plans and executes the migration with ledgered proof.

Commercial boundary Paid mutation
Protect

Are live workloads using quantum-ready protection?

Runtime adds the SDK, middleware, service, and evidence.

Commercial boundary Recurring license
Assure

Can we prove posture continuously?

Assure monitors drift and validates posture.

Commercial boundary Recurring license
Standardize

Can we make this the enterprise standard?

Platform bundles the full lifecycle.

Commercial boundary Platform agreement

Free to know. Paid to change.

Discovery costs nothing and requires no entitlement. Mutation, protection, and standing proof are licensed. The boundary is the same one the buyer already reasons about.

Free to know HX-PQC Scan

Free cryptographic inventory, CBOM, readiness report, signed quote, and dry-run preview.

Paid to change HX-PQC Migrate

Real mutation, key minting, DEK re-wrapping, batch execution, and rollback-aware migration require an entitlement.

Recurring to protect HX-PQC Runtime

Runtime protection for live workloads is licensed as a recurring production capability.

Recurring to prove HX-PQC Assure

Continuous posture, drift detection, validators, and the ledger explorer are licensed as recurring assurance.

Premium to control HX-PQC Platform

Enterprise standardization across Cloud, Self-Hosted, and Air-Gapped editions.

Three editions

Every surface is available on every edition. The buyer chooses a deployment boundary, not a feature-limited product.

Cloud

Fast-start teams, marketplace buyers, commercial pilots.

Commercial posture Subscription, private offer, or platform agreement.
Operational boundary HolonomiX-hosted services with customer connectors.
Entitlement verification Online plus cached validation
Evidence export Download and API export

Self-Hosted

Enterprises with VPC or Kubernetes and internal controls.

Commercial posture Annual platform agreement plus support.
Operational boundary Customer-controlled runtime in the customer environment.
Entitlement verification Local verification with signed entitlement
Evidence export Local export and optional support bundle

Air-Gapped

Defense, critical infrastructure, sovereign and restricted networks.

Commercial posture Premium annual appliance or private deployment.
Operational boundary Offline entitlements, offline updates, local evidence export.
Entitlement verification Offline verification only
Evidence export Removable media, signed export

Closed implementation. Open evidence.

The chain begins with a CBOM and ends with signed proof. Every stage emits an artifact a buyer can carry into security, engineering, compliance, procurement, and an executive decision.

Scan
CBOM CycloneDX 1.6
Readiness report JSON, PDF, HTML
Signed quote JSON, PDF

Inventory that can travel across teams, and a deterministic commercial scope.

Commercial
Order JSON, PDF
Entitlement Signed token

Procurement and entitlement mapping, with license and limits.

Migrate
Migration plan JSON, PDF
Migration event Ledger event

Execution plan with rollback, and proof of every asset moved.

Runtime
Protected envelope Binary with JSON metadata
Runtime evidence Ledger event

Proof of live protection on each protected data operation.

Assure
Finding JSON
Posture snapshot Signed JSON, PDF

Posture issue lifecycle, and audit evidence.

Signed artifacts, deterministic quotes, ledger replay, and offline verification are the substrate. The implementation is closed; the evidence is open and verifiable without a HolonomiX connection.

The product family uses ML-DSA-65 for signing, ML-KEM-768 where key encapsulation is implemented, and AES-256-GCM for data encryption where applicable. HolonomiX uses NIST-standardized algorithms where implemented.