Analysis
QuTrust takes the raw output your existing tools already produce and works out what it means. What is vulnerable, how badly, how long the data behind it must stay secret, and how hard the system will be to change.
Post-quantum cryptography migration for financial institutions. QuTrust analyzes what your existing tools find, sequences the work, and produces the evidence your regulators ask for.
Built for financial institutions answering to more than one regulator.
01 · The problem
Attackers are recording encrypted data today and storing it, waiting for a quantum computer powerful enough to unlock it. That data includes payment instructions, mortgage records, client files, and settlement data.
Regulators have responded with published deadlines to migrate to post-quantum cryptography, the new mathematics that quantum computers cannot break. The migration itself is the hard part.
Every change to your environment changes your exposure. You need a system that keeps telling you what keys and locks to fix.
02 · What QuTrust is
In a large institution, cryptography sits in thousands of places across software, devices, cloud services, and vendors. Most organizations cannot yet say where all of it lives.
QuTrust analyzes the cryptography your existing tools already find, sequences the work to replace it across Cloud, IT, OT, AI, and distributed ledger technology (DLT), and produces the evidence your risk managers, regulators, and board ask for.
QuTrust closes the gap most IT, cyber, and security teams face.
03 · The difference
You probably already own scanners. Keep them. QuTrust does not replace them and does not compete with them. It reads their output, along with your certificate tools, your cloud, your code and your system of record, and turns all of it into a single managed migration with an owner, a sequence and a deadline for every item.
A list of findings is not a plan. QuTrust is the plan, and the proof that you executed it.
04 · How QuTrust works
QuTrust takes the raw output your existing tools already produce and works out what it means. What is vulnerable, how badly, how long the data behind it must stay secret, and how hard the system will be to change.
It turns that into an ordered plan with the regulatory lens applied, so the first item on the list is the right first item and you can show why.
It produces the evidence, on demand, that your board and your regulators ask for. Not a document that goes stale the day it prints.
These are loops, not steps. They run continuously and feed each other. The plan updates as work completes and as your environment changes.
The services and systems you rent, including managed services where the provider controls the cryptography.
Your own networks, certificates, identity systems, applications and code.
Operational technology. The specialized hardware, including the dedicated devices that sign and protect payments.
Model endpoints, training pipelines, model integrity and the systems around them. The newest surface, and the one almost nobody is analyzing yet.
Distributed ledger technology. Blockchains, bridges, custody systems, smart contracts, and the keys your validators and nodes sign with.
Covering all five as one coordinated program is the difference between a migration and five disconnected projects.
Distributed ledgers are the hardest place in the estate to fix, for a reason unique to them. Everywhere else, you replace a weak signature and move on. On a ledger, the record is permanent. You cannot go back and re-sign history, and every signature already written stays readable to whoever eventually holds a quantum computer.
Bridges concentrate that risk further, because a single set of keys often controls value moving between chains.
If you are running tokenized assets, digital bond issuance, stablecoin infrastructure or a settlement network, this surface is not future work. It is the one with the shortest window and the least room to correct later.
05 · Who it is for
Everyone works from the same migration. Each person sees the part they are accountable for.
You need to know where the risk actually is, how bad it is, and what happens first. QuTrust gives you the exposure picture across all four surfaces and the sequence to reduce it.
06 · What you get
Where your institution stands. Findings, severity, what depends on what, and which exposures are driven by a regulatory deadline rather than by technical severity alone. Written so a board can read it and an auditor can check it.
What to fix, in what order, by when, and how far along you are. It updates as work completes and as regulations move. When a supervisor asks where you are, this is the answer, current on the day they ask.
07 · Integrations
QuTrust ingests from the tools already in your environment. Vulnerability scanners, certificate and key management platforms, cloud providers, code repositories, OT monitoring, and your system of record.
Do not see yours? We build connectors. Ask us.
Integration is via documented APIs and standard protocols. All product and company names are trademarks of their respective owners. Listing does not imply partnership or endorsement.
08 · Why us
The founders of ArcQubit introduced the first formal academic definition of Dual Quantum Technology Risk Exposure.
Our founding team comes from national laboratories, defense, and international nuclear cybersecurity, with more than twenty publications across IEEE, ANS, and IAEA forums.
We are not repackaging someone else's tech. We built the framework this category is measured against.
Dual Quantum Technology Risk Exposure is the condition where an institution faces both 1) security risk from cryptographic attacks and 2) strategic risk from delaying quantum adoption [1].
[1] S. M. Rosado et al., "Quantum Technology Readiness Adoption Model," IEEE QCNC 2026, pp. 392-394, doi: 10.1109/QCNC69040.2026.00072.
09 · How it scales
QuTrust is sold directly, and priced to the scope of your estate and the number of entities and jurisdictions you operate in. Pricing is discussed in the first conversation.
Single entity, beginning the work
Core analysis, the Quantum Exposure Report, the roadmap dashboard, and basic pipeline checks.
An active migration programme
Higher analysis volume, scheduled audit-ready reporting, certificate tooling and system-of-record integration.
Large, multi-entity institutions
Large-scale continuous analysis, board-ready reporting, multi-regulator filtering, scanner and hardware integrations.
The highest assurance requirements
Self-run local command-line analysis, air-gap capable deployment, full programmatic access, and a named team available around the clock.
Services, including assessment, advisory and implementation support, are scoped and priced separately.
Talk to us about scope10 · GRC Program Ready
Four different things get sold in this market. They sound similar. They are not, and the difference is where most post-quantum programs go wrong.
| Level | The question it answers | What it is | Position |
|---|---|---|---|
| 1. Inventory | What do we have? | A census of every algorithm, certificate and library, and where each one lives. It has no opinion. A complete inventory tells you nothing about risk. | Ingested |
| 2. Assessment | Where are we? | Exposure at a point in time. Findings, severity, what depends on what. Inventory plus judgment. It ends at the truth. | QuTrust |
| 3. Roadmap | In what order, and by when? | The work sequenced across years, respecting dependencies, vendor timelines and deadlines. It moves as reality moves. | QuTrust |
| 4. Action plan | Who does what, starting Monday? | Named person, named system, specific change, due date. It lives in your ticketing system, not ours. | Customer-owned |
The common failure is simple. A vendor delivers a lower level and names it a higher one. Inventory gets called assessment. Assessment gets called a roadmap. Each step up sounds more valuable, so the naming drifts while the deliverable stays put. Buyers pay for a program and receive a list.
Compliance mapping is not a fifth level. It is a lens that runs across all four. Knowing which regulation cares about which finding does not change what you have or what breaks first. It changes what you do first, and a technically moderate finding can go straight to the top because a legal deadline sits behind it. A vendor selling mapping as the whole program is selling a filter and calling it a plan.
We do not write your tickets or assign your people. We do check whether the change actually happened, because a closed ticket is a claim and a changed system is evidence.