A new secure tunnel protocol for site-to-site and remote-access networks. It protects traffic against today's attackers and against the quantum computers that will break today's VPN key exchange, and it connects faster and with less overhead than IPsec.
Every major VPN in use today agrees on its keys with mathematics that a large quantum computer will break. An adversary does not need that computer yet: it can store encrypted traffic now and read it later. Data that must stay confidential for ten or twenty years is already exposed.
NIST published its first post-quantum standards in 2024. Bolting them onto IPsec adds round trips, fragmentation and yet more configuration. We designed a tunnel around them from the start.
Every session combines proven classical cryptography with NIST-standardized post-quantum algorithms. An attacker has to break both, so the tunnel is never weaker than what you trust today.
One round trip to connect, under a millisecond of CPU per handshake, and less per-packet overhead than IPsec. No algorithm negotiation, so no downgrade attacks and nothing to misconfigure.
The endpoint never answers unauthenticated packets, so port scans see nothing. Floods switch it into a cheap defensive mode while legitimate peers keep working.
Works through NAT, follows laptops between networks without reconnecting, and keeps connecting quickly on lossy links where larger post-quantum handshakes usually struggle.
Research prototype on a 2-vCPU virtual machine over real Linux kernel networking. Production implementations are expected to be substantially faster.
| Property | IPsec / IKEv2 | WireGuard | Our protocol |
|---|---|---|---|
| Round trips before data (post-quantum) | 3 or more | Not post-quantum | 1 |
| Post-quantum key exchange | Extension | Add-on tools only | Built in, hybrid |
| Post-quantum authentication | Large certificates | No | Built in, no certificates needed |
| Algorithm negotiation (downgrade risk) | Yes | No | No |
| Silent to port scans | No | Yes | Yes |
| Packet counters hidden from observers | No | No | Yes |
| Roaming and NAT traversal | Separate extensions | Built in | Built in |
IPsec and WireGuard columns describe the published standards and designs. Comparative throughput benchmarks will follow the production implementation.
Connect offices, data centers and cloud networks with gateways that are quantum-safe today and simple to operate.
Laptops stay connected as they move between Wi-Fi and mobile networks. A Windows test client is in development.
A conservative profile for government, health, finance and critical infrastructure data that must stay secret for decades.
We are inviting a small group of network and security teams to run the prototype in their labs and shape the release. Full technical details are shared under NDA.