Sovereign post-quantum encryption

AllEyes Resilient.
Encryption 800 Gbps.

FPGA post-quantum network encryptors, ANSSI-certifiable, deployed transparently over your existing links. Engineered in Rouen, built for European critical infrastructure operators facing NIS2 and ANSSI 2027 deadlines.

CSPN Ready · EAL4+ Ready
800 Gbps
Per encryptor
< 5 µs
Added latency
6.4+ Tbps
Per appliance
100 %
Sovereign
Infrastructure

End-to-end encrypted network

Branch offices, datacenters, backbone links — each segment protected by a dedicated encryptor, all managed from a single GARANCE console.

Fiber · Ethernet · 5G · Satellite — every signal encrypted

Benefits

What the hardware actually does

Post-quantum encryption

ML-KEM-1024 + AES-256-GCM hybrid. Resistant to both classical and quantum attacks, following the NIST August 2024 standards and ANSSI January 2025 migration framework.

FPGA acceleration

Encryption happens in the FPGA, not the CPU. 800 Gbps per accelerator with under 5 µs added latency — your network does not notice.

AllEyes Architecture

Keys never touch the host CPU — they stay inside the FPGA. Even if the server OS is compromised, the cryptographic material remains out of reach.

Hardware zeroization

Key destruction in under one second. Physical tamper detection or a remote GARANCE command triggers irreversible erasure of all key material.

100% Rust

The control plane is written entirely in Rust — no buffer overflows, no use-after-free. Auditable and verifiable by design.

CSPN Ready · EAL4+ Ready

Architecture designed from the start for ANSSI evaluation. CSPN dossier in preparation, with EAL4+ Common Criteria as the next milestone.

Zero-knowledge communication

Even this website practices what we preach: the contact form encrypts your message with RSA-4096 + AES-256-GCM in your browser. The transit infrastructure never sees plaintext.

Products

The encryptor tailored to your perimeter

Pick the right form factor for each site — from a 3.4 kg wall-mount box to a multi-terabit chassis. GARANCE manages keys and policies across the fleet.

Edge & Remote Sites

PQC-WAN Agent

1 — 100 Gbps
  • Software, 1U telecom, 1U compact, mini edge
  • ML-KEM-1024 + AES-256-GCM
  • Branches, PoPs, SCADA, OT
  • Managed by GARANCE
Datacenter & Network Core

PQC-800 / 1600 / 2400

800 Gbps — 2.4 Tbps
  • Line-rate FPGA encryption
  • AllEyes architecture
  • Datacenter interconnect, regional core
  • 2U rack · CSPN Ready
Backbone & Hyperscale

PQC-3200 / 6400 / Multi-chassis

3.2 Tbps — Multi-Tbps
  • 4U rack, stackable with no ceiling
  • 12.8 / 19.2 Tbps and beyond
  • Defense, national backbone, sovereign cloud
  • Complete AllEyes architecture
Standalone Deployment

PQC-800S / 1600S

800 Gbps — 1.6 Tbps
  • Dedicated enclosure, no rack server
  • Remote administration (5G)
  • Isolated site, mobile, container
  • Active-active failover (1600S)
Orchestration & Services

GARANCE / PQC SecNumCloud

Sovereign PKI
  • Full ecosystem orchestration
  • Real-time AI supervision
  • SecNumCloud or air-gapped
  • 24/7 managed service available

See the full range →

Discover the customer journey →

Network spectrum

One encryptor for every segment

The same hybrid PQC encryption from a branch in Normandy to a sovereign cloud in Paris — no gaps, no exceptions.

Edge
PQC-WAN Agent
1 — 100 Gbps
Branches, OT, SCADA
Datacenter
PQC-800 to 2400
800 Gbps — 2.4 Tbps
Inter-DC, aggregation
Backbone
PQC-3200 / 6400
3.2 Tbps — Multi-Tbps
National, telecom, defense
Sovereign cloud
PQC SecNumCloud
Managed service 24/7
Operated by Cryptosphere
Linear scalability — from 1 Gbps to 6.4+ Tbps with no architectural ceiling
Deployment

Three operating modes

You decide who holds the keys. We support air-gapped, hybrid, or fully managed — depending on your classification level.

Full sovereignty

Operated by client (air-gapped)
GARANCE on-premises
Defense · Classified

Autonomous

Operated by client with Cryptosphere support
GARANCE on-premises or SecNumCloud
Autonomous OIV · Enterprise

Managed

Operated by Cryptosphere 24/7
GARANCE SecNumCloud France
Telecom · Finance · Delegated OIV
Compliance

Every regulation covered

LPM — OIV In force

249 critical operators · Art. R.1332-41

France’s 249 vital operators must use ANSSI-certified encryption for their critical systems. No exceptions.

NIS2 2024-2025

300+ EE France · ~150 000 UE · NIS2 art. 21

Art. 21 now requires encryption policies for ~150,000 entities across Europe. French transposition (“Loi Résilience”) is underway.

DORA January 2025

EU Finance · DORA art. 9

Since January 2025, EU financial entities must document cryptographic resilience — including monitoring for quantum threats.

II 901 In force

French government

French government networks require ANSSI-qualified products. No alternatives accepted for classified or restricted systems.

SecNumCloud Active

Sensitive cloud

Sensitive cloud workloads require encryption keys under the exclusive control of the operator — not the cloud provider.

ANSSI PQC Horizon 2030

All OIV / OSE operators

From 2027, ANSSI will no longer issue security visas for products without PQC. Full migration expected by 2030 for high-risk use cases.

Read the technical FAQ →

Ready for the post-quantum era?

Whether you need a cryptographic audit, a 4-week POC, or a full rollout — we start where you are.