In this article
Enterprise security programs often fail before the technology is evaluated. They begin with an oversized scope, demand production-wide access, create a long infrastructure project, and ask decision-makers to fund continuous monitoring before anyone has seen a trustworthy inventory.
A post-quantum cryptography program can start differently. The reason to begin now is visible in the public Harvest Now, Decrypt Later demonstration: data captured under vulnerable cryptography can retain value long after its initial transmission.
The practical sequence is read-only discovery, a scoped assessment, a controlled endpoint cohort, and evidence-led expansion. This gives security and engineering teams something concrete—a cryptographic inventory, a CBOM, coverage evidence, dependency findings, and a migration roadmap—before they commit to a broader rollout.
Separate platform installation from evidence collection
There are two deployment decisions, and they should not be confused.
The first is where the QuantumGenie platform runs. Depending on customer requirements, the application can be deployed in an approved hosted environment or installed within customer-controlled infrastructure. An on-premises deployment can run on a designated Linux system so that collected evidence, credentials, inventory, and reports remain within the organization’s controlled environment.
The second decision is how the platform receives evidence. Different surfaces need different collection methods:
- Cloud: dedicated read-only identities, roles, tokens, or service accounts limited to required metadata APIs.
- Source code: read-only repository integrations or approved exports.
- Databases: metadata-first connectors and explicitly authorized sampling where necessary.
- Endpoints and IoT: customer-controlled deployment of CipherEdge™ agents to an approved cohort.
- Network: authorized telemetry from selected hosts or a SPAN/mirror-port integration where appropriate.
- Certificates and keys: provider APIs, certificate-manager metadata, key-management metadata, and confirmed service bindings.
This separation makes the architecture easier to reason about. Installing the platform does not automatically authorize every collector, and adding one connector does not silently expand access to another environment.
Start with a read-only cryptographic baseline
The first operational milestone should be a baseline assessment, not a production-wide remediation exercise.
A typical starting scope combines one or more source-code integrations with a cloud connector. The customer creates a dedicated read-only identity using a documented minimum-permissions policy. QuantumGenie validates access, inventories the authorized regions and services, and makes blocked or permission-limited scopes visible rather than treating them as empty. The public open-source repository scan offers a concrete example of the repository-discovery experience.
The baseline can then produce:
- cryptographic usage occurrences in source code;
- certificate, managed-key, secret, compute, and storage metadata;
- algorithm and protocol classifications;
- evidence provenance and collection coverage;
- confirmed certificate and key relationships;
- quantum-readiness and confidence distributions;
- a standards-aligned CycloneDX CBOM; and
- an executive findings and migration report.
Connector setup may be quick, but assessment duration varies. Region count, service breadth, repository volume, rate limits, network conditions, and enterprise approval processes all affect timing. A credible implementation plan should distinguish time to establish access from time to complete and validate the scan.
Move from inventory to a controlled endpoint cohort
Connectors show what platforms report. Endpoint telemetry can expose cryptographic posture that cloud and repository APIs do not reveal: local certificate stores, disk artifacts, runtime behavior, device identity, software posture, and approved network observations.
CipherEdge™ supports two deployment profiles:
CipherEdge Light™
CipherEdge Light™ is intended for managed workstations and resource-conscious distributed devices. Typical targets include employee laptops and desktops, Linux workstations, embedded computers, IoT gateways, cameras, Raspberry Pi-class systems, and other approved edge populations. Its role is bounded endpoint, disk, and network telemetry rather than high-throughput network inspection.
CipherEdge Plus™
CipherEdge Plus™ is intended for load balancers, physical and virtual servers, virtual machines, gateways, and higher-throughput environments. It is also the appropriate profile for authorized SPAN or mirror-port traffic collection. The Plus profile carries a different operational and commercial footprint because the evidence volume and processing requirements are higher.
The right pilot is usually mixed. A small cohort can include representative Windows and Linux endpoints, a server or gateway, an IoT or edge device where relevant, and one Plus deployment at an approved network observation point. That produces more useful evidence than installing the same profile on a large number of similar laptops.
Use the customer’s existing software-distribution control plane
Enterprise deployment should fit established operational controls. Windows agents can be packaged for customer-managed tools such as Microsoft SCCM or another approved endpoint-management channel. Linux packages can be distributed through systems such as Red Hat Satellite. The customer decides the target group, schedule, maintenance window, approval gates, and rollback policy.
As one QuantumGenie co-founder explained during a technical briefing:
“If they are familiar with Red Hat Satellite and Microsoft SCCM, it’s very easy to deploy our endpoint telemetry agents.”
This design avoids turning the vendor into an alternate fleet administrator. QuantumGenie supplies the documented package, configuration, prerequisites, validation steps, and support; the enterprise retains its ordinary software-distribution authority.
Scaling the cohort should not change the deployment method
Once a package and policy have been approved, expanding the cohort is an orchestration decision. The mechanism used for a small group should be the same mechanism used for a larger one.
“It does not matter whether it is 100 or 1000 devices.”
The statement refers to the deployment operator’s workflow, not a guarantee that all estates take the same amount of time. Larger rollouts still require capacity planning, change windows, network controls, compatibility testing, support readiness, and staged cohorts.
Online and offline devices also need predictable behavior:
“If they are online, they will receive and get updated automatically on the spot.”
“But if they are offline and come online the next day, they will get updated the next day.”
That is the familiar software-distribution model: the command targets an approved group, reachable systems receive it according to policy, and temporarily offline systems receive it when they next check in. Deployment dashboards should distinguish assigned, downloaded, installed, reporting, failed, deferred, and offline states.
A realistic rollout has explicit gates
An enterprise PQC readiness rollout can be organized into five stages:
1. Architecture and access workshop
Confirm data residency, platform location, network boundaries, authentication, approved evidence sources, retention, access roles, and change controls. Produce the target architecture and responsibility matrix. A structured PQC readiness assessment can capture these prerequisites before technical access is requested.
2. Read-only discovery
Connect approved repositories and cloud accounts. Run a baseline inventory, preserve coverage and permission evidence, validate a sample of findings, and generate the initial CBOM.
3. Endpoint pilot
Deploy CipherEdge Light™ and CipherEdge Plus™ to a small, representative cohort. Validate resource use, telemetry quality, connectivity, offline behavior, allow-listing, log handling, and uninstall or rollback procedures.
4. Causal mapping and migration planning
Use the Causal Security Engine™ and Security World Model™ to connect high-priority findings to services, repositories, files, data stores, certificates, keys, and business processes. Use Causal Risk Triage™ to create a reviewable order of work.
5. Controlled expansion and remediation
Expand approved endpoint cohorts, add further connectors, and execute remediation waves through CipherNova™. Maintain human approval for code changes, certificate issuance, key rotation, production cutovers, and exception handling. Refresh the CBOM after changes to verify the new state.
An initial technical enablement can often fit within a week when prerequisites and customer approvals are ready. That is not the same as claiming that a complete enterprise scan or migration finishes in seven days. The program timeline depends on scope, regions, repositories, endpoint availability, change controls, validation depth, and customer cadence.
Commercial packaging should follow the operating model
PQC pricing becomes confusing when every connector, scan, endpoint, graph, and report is treated as an unrelated line item. A clearer model separates the baseline assessment from continuous telemetry and advanced analysis.
One-time discovery and CBOM assessment
The initial package is scoped by the size and complexity of the authorized estate. Relevant dimensions include cloud accounts and regions, repositories, database systems, certificate and key populations, infrastructure services, and expected evidence volume. Deliverables can include the validated inventory, CycloneDX CBOM, coverage statement, executive report, technical findings, and migration roadmap.
Recurring CipherEdge™ monitoring
Continuous endpoint telemetry is priced according to the number and type of monitored systems. CipherEdge Light™ and CipherEdge Plus™ have distinct unit profiles because they serve different device classes and collection depths. A pilot can begin with a mixed cohort and expand after evidence quality and operational fit are confirmed.
Advanced causal intelligence and remediation
The Causal Security Engine™, Security World Model™, Causal Risk Triage™, and CipherNova™ remediation workflows add dependency analysis, business-impact prioritization, guided migration, and verification. These capabilities can be packaged according to required surfaces, workflows, and operating scale.
The commercial principle is straightforward: pay once to establish the baseline; subscribe where continuous evidence and monitoring are needed; add advanced causal and remediation capabilities according to program scope. Exact pricing follows a scoping exercise rather than an arbitrary endpoint count alone. The public pricing overview provides a starting point for that conversation.
What the customer should receive
Even a limited pilot should end with decision-ready artifacts:
- a coverage and permissions record showing what was and was not assessed;
- a normalized cryptographic inventory across connected surfaces;
- a CycloneDX-compatible CBOM with provenance;
- an executive readiness summary;
- technical findings with evidence and affected relationships;
- a prioritized migration roadmap;
- an endpoint-pilot operations report;
- a proposed production architecture; and
- a commercial scale-out model tied to actual scope.
These artifacts let security leaders evaluate the program before approving broader telemetry or remediation. They also give channel partners and internal engineering teams a repeatable way to present evidence without relying on a live demonstration alone.
Design principles for a low-friction PQC program
Five principles keep deployment proportionate:
- Read-only first. Begin with the minimum metadata and repository permissions required for discovery.
- Customer-controlled distribution. Use established endpoint and Linux package-management channels.
- Representative pilots. Choose devices and systems by architectural value, not headline quantity.
- Visible uncertainty. Report blocked scopes, missing relationships, stale evidence, and unclassified algorithms.
- Human-approved change. Automation may prepare and validate remediation, but production issuance, rotation, cutover, and merge remain governed actions.
This is how a PQC readiness initiative becomes an operating program rather than another prolonged integration project: establish evidence quickly, prove the model on a bounded scope, and scale through controls the enterprise already trusts. Further technical material is available in the QuantumGenie Knowledge Base, while the PQC competition matrix compares the scope of different market approaches.
Frequently asked questions
Must a customer deploy endpoint agents before receiving a CBOM?
No. A useful first CBOM can be generated from authorized repository, cloud, database, certificate, and key-management evidence. Endpoint telemetry expands coverage where those integrations cannot see local or runtime posture.
Does read-only mean no risk?
No access is risk-free. Read-only permissions reduce the ability to alter customer systems, but credentials, metadata, logs, network boundaries, retention, and operator access still require proper controls. Permissions should be dedicated, minimal, reviewable, and revocable.
Is a one-week deployment guaranteed?
No. Initial enablement may fit within a week when infrastructure, approvals, and distribution channels are ready. Full scan, validation, endpoint rollout, and migration schedules depend on estate size and customer governance.
Why use both Light and Plus?
They address different environments. Light supports bounded telemetry on distributed endpoints and resource-conscious devices. Plus supports heavier servers and approved high-throughput network observation. A mixed pilot tests the actual estate more effectively.
Is the pricing purely per endpoint?
No. The baseline assessment is scoped by the estate and evidence sources. Continuous CipherEdge™ monitoring has a per-device dimension, differentiated by profile. Causal analysis and remediation capabilities are added according to workflow and scale.



