ArcQubit Launches the QuTrust CLI, Bringing Full Stack Post-Quantum Migration Analysis Inside the Institution's Own Boundary

The QuTrust CLI brings Full Stack post-quantum migration analysis inside financial institutions, including fully air-gapped environments.

FOR IMMEDIATE RELEASE

Financial institutions can now run QuTrust analysis locally, including in air-gapped environments, and feed the results into a single living migration roadmap across Cloud, IT, OT, and AI.

TAMPA, Fla., August 5, 2026 ArcQubit Inc. today announced the launch of the QuTrust CLI, a locally run analysis client for QuTrust, the company's Full Stack post-quantum cryptography (PQC) migration platform for banks, insurers, exchanges, payment processors, and market infrastructure operators.

The QuTrust CLI removes the last obstacle for institutions that cannot send cryptographic data outside their own perimeter. Analysis runs where the data already lives, inside the institution's boundary and, where required, fully air-gapped. Results feed the same Quantum Exposure Report and the same living migration roadmap that every other QuTrust deployment produces. Institutions operating under data residency rules, cross-border restrictions, or classified handling requirements no longer have to choose between sovereignty and a real migration program.

Financial institutions are being asked a question their current tooling cannot answer. Supervisors in different jurisdictions are issuing PQC expectations on different clocks, and boards want to know a single thing: where are we, and when will we be finished. Most institutions already own scanners, certificate managers, cloud posture tools, and OT visibility platforms. What they do not own is the layer that turns all of that output into a migration program with owners, sequence, and dates.

QuTrust is that layer. It is an analyzer, not a scanner. It ingests from the tools an institution already runs, including vulnerability scanners, certificate and key management systems, cloud APIs, identity systems, network telemetry, OT visibility platforms, model registries, and vendor advisory feeds. It analyzes their collective output into one unified cryptographic posture across four surfaces, always in the same order: Cloud, IT, OT, and AI.

The platform produces two outputs.

The Quantum Exposure Report. A live cryptographic inventory that answers, in real time, what the institution's current PQC posture is across every asset it owns, organized by urgency and severity so remediation can be sequenced rather than guessed.

The living PQC migration roadmap dashboard. A continuously updated migration program, not a point-in-time assessment, showing what has moved, what is in flight, what is blocked, and what the institution can evidence to a supervisor today.

QuTrust runs three continuous loops: continuous analysis, continuous prioritization, and continuous reporting. Alignment includes NIST FIPS 203, 204, and 205 [1], NIST SP 800-208 [2], and CISA's Automated Cryptography Discovery and Inventory (ACDI) framework [3], [4], with reporting views mapped to the supervisory regimes a global institution answers to, including the EU Digital Operational Resilience Act (DORA), guidance from the G7 Cyber Expert Group, the UK National Cyber Security Centre, and the Monetary Authority of Singapore.

"The institutions with the most cryptographic exposure are usually the ones least able to send their data anywhere," said Shadya Maldonado Rosado, Co-Founder and Chief Executive Officer of ArcQubit. "They were being asked to prove a migration they had no safe way to measure. The CLI closes that gap. The analysis goes to the data, not the other way around."

The timing reflects a market that has compressed. Critical financial systems are expected to migrate between 2030 and 2032, with full transition landing in the mid-2030s. Vendor commitments have moved forward as well, and institutions are beginning to write named cryptographic migration dates and crypto-agility commitments into contracts and renewals. Long-lived financial data is the asset class most exposed to harvest-now, decrypt-later collection, which makes the effective deadline for many institutions earlier than the published one.

"The scanners are essential. They produce the raw data," said Ryan Cloutier, Quantum AI Solutions Architect at ArcQubit. "QuTrust is where the scanner outputs come to become a migration program. It makes the investments an institution has already made finally answer the board's question."

ArcQubit's research underpins the platform. The company introduced the first formal academic definition of dual quantum technology risk exposure, the condition where an organization simultaneously faces strategic risk from delayed quantum adoption and security risk from cryptographic vulnerability.

Availability. The QuTrust CLI is available now through a sales-led engagement. It is included with the Sovereign tier for unlimited local self-run analysis, and is available to other tiers as part of a scoped deployment. QuTrust deployment options range from hosted, to in-perimeter within the institution's own boundary, to sovereign deployment with air-gap capability. Pricing is set by cryptographic risk exposure across jurisdictional reach, data sovereignty, and systemic consequence. Institutions can request a scoped assessment at https://bookings.cloud.microsoft/book/QuTrustBookingPage@arcqubit.ai/


About ArcQubit

ArcQubit's work on quantum technology risk was published and presented at IEEE before QuTrust existed. Our founding team comes out of national laboratories, defense and international nuclear cybersecurity, with more than twenty publications across IEEE, ANS and IAEA forums.

We are not repackaging someone else's scanner. We built the framework this category is measured against.

Media Inquiries

Media inquiries may be submitted through the ArcQubit booking page at https://bookings.cloud.microsoft/book/QuTrustBookingPage@arcqubit.ai/

References

[1] National Institute of Standards and Technology, "Post-Quantum Cryptography FIPS Approved: FIPS 203, FIPS 204, and FIPS 205," Computer Security Resource Center, Aug. 13, 2024. [Online]. Available: https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved

[2] D. A. Cooper, D. C. Apon, Q. H. Dang, M. S. Davidson, M. J. Dworkin, and C. A. Miller, "Recommendation for stateful hash-based signature schemes," National Institute of Standards and Technology, Gaithersburg, MD, USA, NIST SP 800-208, Oct. 2020. [Online]. Available: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-208.pdf

[3] Cybersecurity and Infrastructure Security Agency, "Strategy for migrating to automated post-quantum cryptography discovery and inventory tools," CISA, Washington, DC, USA, Sep. 2024. [Online]. Available: https://www.cisa.gov/resources-tools/resources/strategy-migrating-automated-post-quantum-cryptography-discovery-and-inventory-tools

[4] Cybersecurity and Infrastructure Security Agency, "Post-quantum cryptography initiative," CISA. [Online]. Available: https://www.cisa.gov/topics/risk-management/quantum

Learn more

See what QuTrust can do in your environment.

Talk with the team about deployment, analysis, and a living post-quantum migration roadmap.

Book a working session