Every regulated institution has a cryptographic deadline.

QuTrust is the Full Stack post-quantum cryptography migration platform. It shows you where your vulnerable cryptography is, turns that into a living migration roadmap, and produces the evidence your regulators ask for.

  • IEEE
  • NIST-ALIGNED
  • JPMORGAN INNOVATION ECONOMY
  • MICROSOFT FOR STARTUPS
  • VOSB / WOSB

01  ·  The deadline

The threat arrives later.
The damage starts now.

Attackers are recording encrypted data today and storing it, waiting for a quantum computer powerful enough to unlock it. This is called harvest now, decrypt later, and it means any data that must stay secret for years is already exposed. Payment instructions, mortgage records, client files, settlement data.

Regulators have responded with published deadlines to migrate to post-quantum cryptography, the new mathematics that quantum computers cannot break. The migration itself is the hard part. In a large institution, cryptography is buried in thousands of places across software, devices, cloud services and vendors. Most organisations cannot yet say where all of it lives.

The question is no longer whether you migrate. It is whether you can prove you are on track.

02  ·  The platform

One platform. Three things, continuously.

Full visibility

01

One clear picture of where vulnerable cryptography lives across the entire organisation. Not a snapshot. A current view that updates as your environment changes.

A living migration roadmap

02

A prioritised, step-by-step plan that updates itself as work gets done. Not a report that is out of date the day it prints.

Continuous governance

03

The evidence your board and your regulators need, on demand, showing the migration is real and on schedule.

03  ·  Full Stack

Cryptography hides in four places.
QuTrust covers all four.

Full Stack means every layer where cryptography lives, managed as one coordinated programme. Most tools cover one or two.

Cloud

01

The services and systems you rent rather than own. Keys, certificates, managed services, and the cryptography inside them.

IT

02

Your internal estate. Applications, networks, certificate authorities, identity systems, and code.

OT

03

Operational technology. The specialised physical hardware, including the dedicated devices that sign and protect payments.

AI

04

The newest surface. The cryptography inside artificial intelligence systems, model pipelines, and agent infrastructure. Almost no one else is looking here yet.

04  ·  The difference

Scanners tell you what's broken.
QuTrust tells you what to do about it.

SCANNER FINDINGSQUTRUSTMIGRATION ROADMAP

You probably already own scanners. Keep them. QuTrust does not replace them and does not compete with them. It reads their output, along with your certificate tools, your cloud, your code and your system of record, and turns all of it into a single managed migration with an owner, a sequence and a deadline for every item.

A list of findings is not a plan. QuTrust is the plan, and the proof that you executed it.

05  ·  Integrations

It works with what you already run.

QuTrust ingests from the tools already in your environment. Vulnerability scanners, certificate and key management platforms, cloud providers, code repositories, OT monitoring, and your system of record.

Do not see yours? We build connectors. Ask us.

06  ·  What you get

On day one, and every day after.

The Quantum Exposure Report

A clear, defensible picture of your cryptographic risk. What is exposed, how severe it is, how long you have, and what it would take to fix. Written so a board can read it and an engineer can act on it.

The living migration roadmap

The always-current plan. What to fix, in what order, who owns it, and how far along you are. It changes as your estate changes and as your teams close work.

07  ·  Use cases

What institutions use QuTrust for.

One roadmap, many regulators

The situationA global institution answers to a dozen regulators in different countries, all asking about the same cryptography, all on different timelines.

With QuTrustEvery regulator is answered from one source of evidence, filtered to the jurisdiction and entity that asked.

Migrating payments without downtime

The situationPayment hardware, card systems, and settlement messaging cannot go offline, and they are among the hardest cryptography to change.

With QuTrustThe roadmap sequences OT and payments work against real dependencies, so migration happens in the right order and nothing stops moving money.

Getting control of the certificate estate

The situationHundreds of thousands of certificates and keys across IT, issued by different authorities, owned by different teams, with no single inventory.

With QuTrustOne current view of the estate, prioritised by exposure, with ownership assigned and progress tracked.

Proving progress to the board

The situationThe board asks whether the institution will hit the deadline, and the honest answer today is a spreadsheet and a guess.

With QuTrustBoard-ready reporting generated from live migration data, not assembled by hand each quarter.

Stopping new exposure before it ships

The situationTeams keep shipping new code and new services that introduce vulnerable cryptography, so the problem grows faster than it is fixed.

With QuTrustPipeline checks catch vulnerable cryptography before it reaches production, so the estate stops getting worse while you migrate.

Bringing an acquisition into the programme

The situationA new subsidiary, entity, or acquired business arrives with an unknown cryptographic estate and its own regulator.

With QuTrustThe entity is added as a workspace, assessed, and folded into the same roadmap and the same evidence trail.

08  ·  Who it is for

One roadmap. Four views.

Everyone works from the same migration. Each person sees the part they are accountable for.

You need to know where the risk actually is, how bad it is, and what happens first. QuTrust gives you the exposure picture across all four surfaces and the sequence to reduce it.

09  ·  Why us

We defined this problem before we built the product.

ArcQubit's work on quantum technology risk was published and presented at IEEE before QuTrust existed. Our founding team comes out of national laboratories, defence and international nuclear cybersecurity, with more than twenty publications across IEEE, ANS and IAEA forums.

We are not repackaging someone else's scanner. We built the framework this category is measured against.

Bridge to Utility

ArcQubit

QuTrust is one of three distinct products in ArcQubit's portfolio, built by a veteran-owned, Tampa Bay based team working across commercial and national security programmes.

10  ·  How it scales

Four tiers. No two migrations are the same size.

QuTrust is sold directly, and priced to the scope of your estate and the number of entities and jurisdictions you operate in. Pricing is discussed in the first conversation.

Starter

Single entity, beginning the work

Core analysis, the Quantum Exposure Report, the roadmap dashboard, and basic pipeline checks.

Up to 10 users · 1 workspace

Professional

An active migration programme

Higher analysis volume, scheduled audit-ready reporting, certificate tooling and system-of-record integration.

Up to 50 users · 3 workspaces

Enterprise

Large, multi-entity institutions

Large-scale continuous analysis, board-ready reporting, multi-regulator filtering, scanner and hardware integrations, a dedicated manager with guaranteed response times.

Up to 250 users · 10 workspaces

Sovereign

The highest assurance requirements

Unlimited analysis and users, unlimited workspaces, self-run local command-line analysis, air-gap capable deployment, full programmatic access, and a named team available around the clock.

Unlimited users · Unlimited workspaces

Services, including assessment, advisory and implementation support, are scoped and priced separately.

Talk to us about scope

11  ·  Questions

Before you book.

Does QuTrust replace our existing scanners?

No. QuTrust reads their output. Scanners produce findings, QuTrust turns findings into a sequenced migration with owners, dependencies and deadlines, then produces the evidence that the work was done. Keep the tools you have.

How long does a migration programme actually take?

For a large institution, multiple years. That is the reason the roadmap has to be living rather than a one-time report. The first Quantum Exposure Report is typically available within weeks of connecting your existing tools.

Can QuTrust run in an air-gapped environment?

Yes, on the Sovereign tier. That tier includes self-run local command-line analysis and air-gap capable deployment.

What data does QuTrust need access to?

Metadata about cryptographic assets, not the secrets themselves. QuTrust reads inventories, certificate metadata, configuration and scanner output. It does not need private keys.

Which regulations and deadlines does it map to?

The published post-quantum timelines that apply to regulated institutions, across the jurisdictions you operate in. Multi-regulator filtering means one source of evidence answers each of them in the form they expect.

How is this different from a cryptographic bill of materials tool?

A bill of materials is an inventory. It tells you what you have. QuTrust starts there and adds prioritisation, sequencing, ownership, progress and evidence. The inventory is an input, not the product.

What does the first 90 days look like?

Connect existing tools, produce the first Quantum Exposure Report, agree the prioritisation model with your security and compliance leads, and stand up the roadmap with owners assigned. You finish the quarter with a defensible plan rather than a list.

How is QuTrust priced?

By the size of your estate, the number of entities and jurisdictions, and the tier you need. We do not publish prices because no two estates are the same shape. It is covered directly in the first conversation, not held back for a third meeting.

Start with your exposure picture.

A working session is 45 minutes. We walk your environment, show you what a Quantum Exposure Report looks like against an estate like yours, and tell you plainly what the migration would involve. No obligation and no pricing pressure.

Book a working session
Book a working session