Skip to content
Nexsys

The threat

Adversaries are recording today what they hope to decrypt tomorrow.

  • “Harvest now, decrypt later” is already practice
  • Defence data recorded now stays sensitive for decades
  • A conventionally encrypted record may not last that long
todaythe quantum eraCONVENTIONAL ENCRYPTIONPOST-QUANTUM ENCRYPTION

Adversaries are recording today.Post-quantum protection holds for the record’s lifetime.

What to encrypt

Encrypt the parts that must stay secret.

  • Encryption is policy-based and happens live while you share
  • Encrypt individual fields, file contents or entire records
  • Proof of authenticity survives encryption and the record still verifies
SELECTED PARTSWHOLE RECORD

You choose what to encrypt.Authenticity survives either way.

Need-to-know

A node can carry an encrypted record. Only the authorised recipient can open it.

  • Owners can encrypt the record and grant access later
  • Nodes can carry the record but cannot open it
  • Recipients can open the record only when they have the key
  • The owner can securely send the key to authorised recipients
  • This key can only be used by the recipient, nobody in between can use it
OwnerForwarding nodeHas the keyHas no keyThe forwarding node cannot open itcannot openThe key cannot be retrievedOpensCannot openOpens

The record stays encrypted on the way.Owner decides who can open it.

By level

Grant access to a single record or a whole level.

  • You can grant access to a single record. The rest stays encrypted
  • You can grant a whole level. Every record at that level and every sublevel opens
  • Records that appear later at that level or a sublevel open under the same grant
  • The grant does not reach a higher level. Those records stay encrypted
OwnerHigher levelLevelSublevel

What this gives you

Post-Quantum Encryption

  • NIST/FIPS PQC, CNSA 2.0
  • Need-to-know, enforced
  • Works across untrusted links
  • Grant access later
  • Holds for the record’s lifetime
  • Field, file, or whole record
  • Authenticity survives encryption
  • Access by level

Frequently asked questions

Post-Quantum Encryption questions, answered directly.

Why encrypt now if quantum computers are not here yet?

Because the recording is happening now. Adversaries collect conventionally encrypted traffic today and wait. That is “Harvest now, decrypt later”. Defence data recorded now stays sensitive for decades. A conventionally encrypted record may not last that long. NIST/FIPS-approved post-quantum cryptography (PQC) and CNSA 2.0 are how the encryption holds for the record’s lifetime.

Do I have to encrypt the whole record?

No. You encrypt only what must stay secret. File contents can encrypt while the metadata fields stay usable, so the record can still move. Individual fields encrypt the same way. The whole record is the other option, when nothing in it should stay usable.

If I encrypt, can they still verify it is authentic?

Yes. Proof of authenticity survives encryption and the record still verifies. That holds if you encrypt selected parts or the whole record. The recipient can confirm the copy is genuine without opening what you encrypted.

Can I grant access later without sending the record again?

Yes. The encrypted record can move first. Grant access later. You send the key. The same copy opens. Nothing is resent. The copy can wait, encrypted, until the key arrives.

Can I grant a whole level, not just one record?

Yes. You can grant access to a single record, or to a whole level. A level grant opens every record at that level and every sublevel, including records that appear later. It does not reach a higher level. Those records stay encrypted.

What happens when the algorithms change?

Algorithms and keys upgrade as standards evolve. That is crypto-agile. Post-quantum protection holds for the record’s lifetime, including when the approved algorithms change.

Arrange a technical briefing.

Request a briefing