[Name revealed at launch] POST-QUANTUM SECURE TUNNEL
IN STEALTH · PROTOTYPE VALIDATED · 2026

Encrypted today.
Still private in 2046.

A new secure tunnel protocol for site-to-site and remote-access networks. It protects traffic against today's attackers and against the quantum computers that will break today's VPN key exchange, and it connects faster and with less overhead than IPsec.

Request early access See the measurements
CONNECTONE ROUND TRIP
Site A Site B hello, hybrid-quantum-safe reply: both sides authenticated encrypted data flows
IKEv2 with post-quantum key exchange: 3+ round trips Here: 1
1 round trip to a mutually authenticated, quantum-safe session
0.7 ms CPU per handshake and side, measured on the research prototype
17× faster worst-case connection at 20% packet loss (62.4 s down to 3.6 s)
0 replies to scans, forged, replayed or tampered packets in attack testing
WHY NOW

Your VPN traffic can be recorded today and decrypted tomorrow.

Every major VPN in use today agrees on its keys with mathematics that a large quantum computer will break. An adversary does not need that computer yet: it can store encrypted traffic now and read it later. Data that must stay confidential for ten or twenty years is already exposed.

NIST published its first post-quantum standards in 2024. Bolting them onto IPsec adds round trips, fragmentation and yet more configuration. We designed a tunnel around them from the start.

HARVEST NOW, DECRYPT LATER
Today Encrypted tunnel traffic is captured and archived.
Years The archive waits. Nothing looks wrong on your network.
Q-day A quantum computer recovers the session keys, and the archive opens.
With us Every session key also depends on post-quantum secrets. The archive stays closed.
CAPABILITIES

Quantum-safe, without giving up what makes a tunnel pleasant to run.

Hybrid by design

Every session combines proven classical cryptography with NIST-standardized post-quantum algorithms. An attacker has to break both, so the tunnel is never weaker than what you trust today.

Light and fast

One round trip to connect, under a millisecond of CPU per handshake, and less per-packet overhead than IPsec. No algorithm negotiation, so no downgrade attacks and nothing to misconfigure.

Invisible to scanners

The endpoint never answers unauthenticated packets, so port scans see nothing. Floods switch it into a cheap defensive mode while legitimate peers keep working.

Built for real networks

Works through NAT, follows laptops between networks without reconnecting, and keeps connecting quickly on lossy links where larger post-quantum handshakes usually struggle.

MEASURED, NOT PROMISED

Numbers from the lab.

Research prototype on a 2-vCPU virtual machine over real Linux kernel networking. Production implementations are expected to be substantially faster.

Handshake cost stays under 1.2 ms

CPU time per side, median of 200 handshakes
Standard profile
0.63 ms
0.72 ms
High-security profile
0.67 ms
0.79 ms
Long-term secrecy profile
1.03 ms
1.14 ms
Initiator Responder

Connects fast even on bad links

Worst 1% of 300 cold starts, seconds to first reply
10% packet loss
26.1 s
2.6 s
20% packet loss
62.4 s
3.6 s
30% packet loss
105.7 s
4.7 s
Conventional retry Our loss recovery

Line-rate goals, prototype today

TCP throughput through the tunnel, mean of 3 runs
Reference implementation
201 Mbit/s
Second, independent implementation
336 Mbit/s
Two independent implementations interoperate byte for byte. 72 automated tests and a 10-scenario network lab pass on both. No plaintext observed on the wire in packet captures.
HOW IT COMPARES

Post-quantum from the first packet, not bolted on.

Property IPsec / IKEv2 WireGuard Our protocol
Round trips before data (post-quantum)3 or moreNot post-quantum1
Post-quantum key exchangeExtensionAdd-on tools onlyBuilt in, hybrid
Post-quantum authenticationLarge certificatesNoBuilt in, no certificates needed
Algorithm negotiation (downgrade risk)YesNoNo
Silent to port scansNoYesYes
Packet counters hidden from observersNoNoYes
Roaming and NAT traversalSeparate extensionsBuilt inBuilt in

IPsec and WireGuard columns describe the published standards and designs. Comparative throughput benchmarks will follow the production implementation.

Site-to-site

Connect offices, data centers and cloud networks with gateways that are quantum-safe today and simple to operate.

Remote access

Laptops stay connected as they move between Wi-Fi and mobile networks. A Windows test client is in development.

Long-term confidentiality

A conservative profile for government, health, finance and critical infrastructure data that must stay secret for decades.

ROAD TO RELEASE

Security is earned in public. Here is our path.

  1. DONE Specification and prototype Protocol specified, prototype validated in a network lab.
  2. DONE Independent implementation Second codebase interoperates with the first.
  3. NEXT Formal verification Machine-checked proofs of the handshake's security properties.
  4. PLANNED Independent audit External cryptographic review before any production use.
  5. PLANNED Public release Name, specification and research paper published together.

Test it before anyone else.

We are inviting a small group of network and security teams to run the prototype in their labs and shape the release. Full technical details are shared under NDA.

Or write to saeed.gholipour@hotmail