Quant.rich

A board roadmap for the encryption you still have to move.

One cryptographic inventory, in priority order. You keep your HSM and certificate vendors.

Request the inventory
  • One institution
  • Map, order, plan
  • Fixed fee
  • Vendors stay
For the person who has to answer the board. 2026

Who reads it

Written for the person who has to answer.

Where is breakable public-key cryptography still in use, who runs it, and what moves first?

CISO

The file for the board.

Head of PKI

The inventory of keys and certificates.

Operational resilience

Owners, dates, and dependencies.

Third-party risk

Vendor deadlines in the contract.

Board risk committee

One page they can adopt.

Supervisor liaison

A dated quantum-safe roadmap.

The work

Three things. A few weeks.

A post-quantum migration plan starts as a map of the estate you already have. We do not replace the vendors who will do the cutover.

01

Cryptographic inventory

Every place the institution still uses breakable public-key cryptography: TLS, signing, APIs, HSMs, cloud keys, and the vendors who run them.

02

Priority order

Long-lived secrets first. Customer files, contracts, and deals that must stay confidential for years. Short-lived session keys later.

03

Quantum-safe roadmap

One page: milestones, owners, vendor deadlines, and what “done” means. A board can adopt it. A supervisor can read it.

Why now

Why a bank buys this now.

Supervisors are asking for a quantum-safe roadmap. The useful answer is an inventory and an order of work.

The exposure

Recorded traffic can be read later

A future quantum computer breaks today’s public-key encryption. Data that must stay secret for years is already the priority, because it can be stored now and decrypted when the machine exists.

The clock

Boards are being asked for a date

G7 guidance points critical financial systems at 2030–2032, with a fuller transition around 2035. Some supervisors want a board-level plan sooner. The first question is still where the cryptography is.

The gap

Each vendor sees only their box

Your HSM vendor, your certificate vendor, and your cloud key service will each say they are quantum-safe on their own timeline. None of them can see the whole estate.

What this is

The map under the answers you already have.

Your vendors will each report a timeline. This is the inventory of the estate they do not share.

What you already hearWhat you leave with
Each vendor reports their own timelineOne inventory of the whole estate
An innovation-lab pilotA file the board can adopt
A new cipher or a new HSMYour current vendors stay in place
A science briefing on quantum computersOwners, milestones, and a definition of done
A living platform on day oneA fixed-fee report first. A subscription only if the board uses it

The engagement

A fixed-fee inventory and a post-quantum migration plan.

We show one institution where classical encryption still protects long-lived data, and the order in which to move it. Your CISO keeps the vendors. We produce the map they cannot produce alone.

Week 1–2

Scope the estate

We agree what is in: in-house systems, cloud, and named vendors. We work from exports you already hold — certificate lists, HSM inventories, TLS scans, and contract registers. We do not arrive and scan production on our own.

Week 3–6

Build the cryptographic inventory

Each use of breakable public-key cryptography is tagged with the algorithm, where the key lives, who operates it, and how long the data must stay secret. Gaps are written down. A missing system is a finding, not a silent omission.

Week 7–8

Set the order

Long-lived customer, contract, and deal data moves first. Short-lived trading sessions wait. Vendor-owned systems are listed with the question you will put in the contract.

Week 9–10

Write the one-page roadmap

Milestones, owners, vendor deadlines, and a definition of done. You take it to the board. If they use it, we can keep the inventory current. If they do not, you have paid for a single report.

Who this meeting is for

The CISO, the head of PKI, or the person who owns operational resilience and third-party risk. The innovation lab buys quantum pilots. This buyer needs a file for the board.

Illustrative sample · not a client report

The page a board can adopt.

This is the shape of the quantum-safe roadmap. Names, systems, and dates on a real engagement are the institution’s. Nothing below is a customer.

Board risk committee · quantum-safe roadmap

Decision requested

Classical public-key encryption still protects data this institution must keep secret for years. That data can be recorded now and read later. The committee is asked to adopt the order below and to name an owner for each line.

WhatCryptography todayWho runs itOrder
Customer archive, 15-year retentionRSA-2048Cloud storage vendorMove first
Board and deal correspondenceECDH on mail gatewayIn-houseMove first
Interbank file transferRSA on VPNNetwork vendorContract deadline
Card-scheme keysVendor-managedSchemeTheir roadmap, your date
Intraday trading TLSECDHE, session-onlyIn-houseLater
Owner

CISO, reporting to the committee.

Next milestone

Inventory accepted, then vendor dates in contracts.

Done means

Long-lived data no longer depends on breakable public-key encryption alone.

Pricing

Pay for the report. Subscribe only if the board uses it.

We do not publish a rate card. The fee follows the size of the estate: how many legal entities, how many certificate sources, and how many vendors sit on the critical path.

Board report

Fixed fee

Quoted after a scoping call. One institution.

  • Cryptographic inventory, including named vendors and cloud services
  • Priority order: long-lived data first
  • One-page quantum-safe roadmap with owners and dates
  • A working session to walk the board pack

Request a scope

Living inventory

After the report

Only if the board uses the first page.

  • The same inventory, kept current
  • Vendor roadmap changes recorded against your dates
  • A refresh before each board cycle
  • No platform fee until the report has been used

Company

We write the map. Your vendors do the cutover.

Quant.rich produces a cryptographic inventory and a quantum-safe roadmap for one financial institution at a time. The deliverable is a file a board can adopt: where breakable public-key encryption still sits, what must move first, and who owns each date.

We do not sell a quantum computer, a new encryption algorithm, or a replacement for your HSM and certificate vendors. Those firms already have a product. They cannot see the rest of the estate.

The first engagement is a fixed-fee report. A living inventory comes after, and only if the board uses the page.

Request

Request the inventory.

Tell us the institution and who owns the question. We reply with what the first six weeks would cover, and a fixed fee for that scope.

  • One institution. No platform demo.
  • You keep your HSM, TLS, and certificate vendors.
  • The output is a board page, or we have not finished.

Scope

What the engagement covers.

In the engagement
  • A cryptographic inventory of breakable public-key use, including vendors and cloud services
  • A priority order based on how long the data must stay secret
  • A one-page quantum-safe roadmap with owners and dates
  • The questions to put into vendor contracts
Outside it
  • Replacing your HSM, certificate, or cloud key vendor
  • Writing or certifying a new encryption algorithm
  • Operating production keys or running an unscoped network scan
  • A quantum-computing pilot for portfolios, risk, or trading

How we handle data

How the inventory is handled.

The work product describes your cryptography. Treat the rules below as the starting position for the engagement letter, not as a certified control set.

We start from exports you already have

Certificate lists, HSM inventories, cloud key reports, and the vendor register. A production scan happens only if it is written into the scope, on your network, under your change control.

The inventory is yours

You keep the working papers and the board page. We do not reuse a named system, vendor, or finding in marketing.

We do not claim a certification we do not hold

This site does not assert SOC 2, ISO 27001, or a completed penetration test. If a supervisor or procurement team needs a specific control, we say whether we have it before the work starts.

Keys stay where they are

We do not take custody of private keys, HSMs, or production certificates. The engagement identifies them. It does not operate them.