Aviatrix today introduced Harvest and Decrypt Protection, a post-quantum security offering designed to encrypt network traffic while also controlling the destinations a compromised workload can access. The solution combines post-quantum encryption with Communication Governance through a single policy enforced in software on the network infrastructure enterprises already operate.
Aviatrix Harvest Protection includes five policies at no cost to get started, with no trial expiration and no purchase requirement. The launch comes one month ahead of the October 22 deadline for federal civilian agencies to submit post-quantum migration plans, and ahead of comparable milestones established by major cloud providers. Google and Microsoft have each published roadmaps targeting full quantum readiness in 2029. Amazon Web Services has not published an equivalent target and instead directs customers toward applicable regulatory deadlines. The Aviatrix Cloud Native Security Fabric is quantum-safe.
Many post-quantum security approaches focus primarily on replacing cryptographic algorithms. Attackers, however, can intercept encrypted information moving across cloud backbones, cloud-to-cloud connections, edge-to-cloud environments, and internal cloud infrastructure, then retain that data until quantum computing capabilities make decryption possible. Sensitive information can also be extracted through unmanaged egress routes without requiring a quantum computer.
Aviatrix’s crypto-agile encryption is designed to prevent captured traffic from being deciphered by future quantum computers, while Communication Governance, including egress governance, restricts the routes through which data can leave an environment today. Together, the capabilities provide the Aviatrix Cloud Native Security Fabric with quantum-safe key exchange across the network paths it encrypts.
“A post-quantum program is usually measured by how much traffic it encrypts. The better metric is measuring how much traffic is exposed to capture in the first place. It’s critical to close the open paths that don’t need to be open so that this traffic can’t be recorded today and read years from now. Closing those paths solves the harvest problem as much as the algorithm does, so the two of them belong in one program rather than two,” said Scott Raynovich, Founder and Chief Analyst at Futuriom Research.
Aviatrix’s crypto-agile encryption and Communication Governance technologies operate across the network infrastructure enterprises already have in place. Encryption keys remain under enterprise control rather than being managed by cloud providers. The technologies are designed to operate without requiring network redesigns, hardware replacements, or application modifications.
“Post-quantum readiness is an architecture problem. Encryption protects data in motion, but most enterprise cloud environments place no constraint on what a compromised workload can reach, exposing valuable data for harvest,” said Doug Merritt, Chief Executive Officer of Aviatrix. “Chokepoint Security cannot close that gap, because a chokepoint governs only the traffic that routes through it, and the paths that carry data out of a cloud estate frequently do not. Containment closes it at the workload, on every path available to it. Further complicating the situation, a cloud provider can be compliant while its customer is not, because provider migration covers the provider’s own services under the provider’s keys, not the customer’s estate.”
Containment provides architectural enforcement of explicit communication policies at the workload level. It determines what each workload can access and what can access it, using workload identity and protocol as enforcement granularity across every available network path, regardless of whether a compromise has already been identified.
The timing of post-quantum migration remains uncertain because Q-Day—the point at which a sufficiently capable quantum computer could compromise today’s key-exchange mechanisms—is not known. Most published estimates place Q-Day between 2030 and 2035. Data retention mandates also overlap with this projected window, including five to seven years for customer records, 10 years for financial records, and 20 to 30 years for health records.
Aviatrix is partnering with global systems integrators and security services providers to expand availability of Harvest and Decrypt Protection. The company is also working with Microsoft through its Quantum Safe program on the network traffic and Harvest Now, Decrypt Later containment solution, complementing other quantum-safe partners focused on certificate management and device posture.
What Harvest and Decrypt Protection Delivers
High-performance encryption without a throughput trade-off. Traditional Internet Protocol Security can approach a one-gigabit-per-second ceiling per tunnel, contributing to why many enterprises do not encrypt cloud transit. Aviatrix’s patented High-Performance Encryption engine is designed to remove that limitation. A Fortune 5 enterprise customer is already operating 400 gigabits per second of fully encrypted production traffic across clouds and regions at line rate.
Crypto agility controlled through policy. Cryptographic algorithms can be changed through configuration rather than requiring hardware replacement. The National Institute of Standards and Technology has already encountered a post-quantum candidate that was broken after progressing through its selection process. As cryptographic weaknesses emerge, Aviatrix enables enterprises to change algorithms through a configuration update instead of a hardware refresh. Control-plane key establishment currently uses the ML-KEM standard, while hybrid ML-KEM on the data plane is planned as a fast-follow release on the Aviatrix platform roadmap.
Communication Governance through the same gateways. Harvest and Decrypt Protection controls the destinations available to workloads, reducing the communication channels attackers can exploit for data extraction. The technology also replaces cloud-native routing approaches that prioritize connectivity without necessarily providing equivalent security controls. No additional appliance is required.
Cryptographic visibility for audit and compliance. The Aviatrix quantum-safe roadmap adds crypto visibility to Harvest and Decrypt Protection, providing insight into exposed applications, dependencies, and communications occurring in cleartext. This creates a network-path cryptographic inventory that filesystem and certificate scanners cannot provide.
Free entry for existing Aviatrix customers. Harvest and Decrypt Protection can be deployed initially at no cost by existing Aviatrix customers. A policy represents an individual rule defining what a workload may access or how a network path should be encrypted. The first five policies and five nodes are free, with no license requirement or expiration. Enterprises can therefore address their first five security gaps before deciding whether to purchase.
New customers can also evaluate Aviatrix for 30 days at no charge before making a commitment.
The Deadlines Are Already Here
The October 22 filing deadline is part of a broader set of post-quantum requirements. Executive Order 14412 establishes December 31, 2030, as the deadline for post-quantum key establishment and December 31, 2031, for digital signatures involving high-value assets and high-impact systems. It also requires federal contractors to meet post-quantum standards by December 31, 2030.
Payment Card Industry Data Security Standard 4.0 has treated cryptographic inventory as an active audit requirement since March 31, 2025. Commercial National Security Algorithm Suite 2.0 requires new National Security System acquisitions to support post-quantum algorithms beginning January 1, 2027, affecting vendors that supply those systems. Meanwhile, the proposed update to the Health Insurance Portability and Accountability Act Security Rule would require encryption of electronic protected health information both in transit and at rest, prompting health organizations to begin their inventories ahead of the rule’s potential implementation.
Cloud provider migration programs address the provider’s infrastructure, according to its own timelines and under provider-controlled keys. Google states that customers remain responsible for their applications, updating client-side software to support post-quantum handshakes and managing their own asymmetric key lifecycle. Amazon Web Services states that its link-layer encryption provides point-to-point protection rather than end-to-end encryption across multiple network segments. As a result, enterprises remain responsible for post-quantum protection across their own environments.
Availability
Harvest and Decrypt Protection, described as the first post-quantum offering available on the Aviatrix Cloud Native Security Fabric, is available now.
Organizations can begin with a free Containment Assessment, a self-service tool that evaluates five characteristics of a cloud environment and produces a provisional Blast Radius and harvest exposure assessment in approximately five minutes. Organizations seeking a more detailed measurement can proceed to Containment Assessment level 2, a read-only, agentless assessment of live runtime flows that calculates exposure in monetary terms as Reachable Value at Risk before any policy is deployed.
For more information and the full quantum-safe delivery roadmap, visit aviatrix.ai/harvest-and-decrypt-protection or contact your Aviatrix representative.
______
About Aviatrix
Aviatrix® is pioneering the Cloud Native Security Fabric, the architecture the Containment Era requires. The Cloud Native Security Fabric governs every workload communication path across every cloud, every VPC, every Kubernetes cluster, and every serverless function, from a single policy plane. One rule. Universal propagation. Enforced at the workload, not at a chokepoint. Trusted by more than 500 of the world’s leading enterprises. For more information, visit aviatrix.ai.
Read the Futuriom report, Implementing Crypto Agility for PQC Networking Infrastructure, released today.
Join our LinkedIn group Information Security Community!
