
Tessera
Available nowPost-quantum network encryption gateway for site-to-site WAN traffic. Deploys beside your existing edge in days, with a single short cutover and zero disruption.
A quantum-safe gateway for the network you already have.
Tessera is an integrated hardware and software system. An onboard Aevum quantum random number generator supplies the entropy, and NIST-standardised post-quantum algorithms (ML-KEM for key agreement, ML-DSA for signatures, FIPS 203 and 204) protect the traffic. Keys are generated and held in a hardware-rooted secure enclave and never leave it.
It deploys as a sidecar: a Layer-3 appliance beside your existing edge routing. Your SD-WAN keeps making every routing decision, and Tessera wraps a post-quantum layer inside your existing IPsec tunnel. Because the protection sits underneath what you already run, deployment needs no re-addressing, no replacement hardware and no scheduled outage beyond one short cutover.
Tessera is vendor-blind by construction. The two Guards on a link agree keys directly with each other, and the Distributor that introduces them holds no secrets and cannot read either side. This means a compromise of Quantasphere does not expose your traffic. It also means peers keep communicating through any outage of ours: your links never depend on our infrastructure being online.
Vendor-blind key agreement
Keys never leave your hardware.
Continuous hardware attestation
Every peer keeps proving it is genuine. A tampered device is cut off automatically.
Zero-teardown key rotation
Keys refresh constantly with no break in live traffic.
Sidecar deployment
Drops in beside your SD-WAN. No rip-and-replace.
Fails safe, never silently
On any PQC-layer failure, traffic falls back to your existing IPsec with a visible alarm. Never silently, and never to an unverified peer.
Inter-organization pairing
Connect different organizations securely. The broker holds no secrets.
| Form factor | 1U rack appliance |
| Deployment model | Layer-3 sidecar beside existing edge routing (e.g. SD-WAN) |
| Throughput | Up to 100 Gbps |
| Latency | Sub-100 microseconds |
| Post-quantum algorithms | ML-KEM + ML-DSA (NIST FIPS 203/204) |
| Key handling | Vendor-blind key agreement; keys generated and held in a hardware-rooted secure enclave, never exported |
| Entropy source | Integrated Aevum quantum random number generator |
| Attestation | Continuous mutual hardware attestation |
| Key rotation | Continuous, zero-teardown |
| Failure behaviour | Fail-safe to existing IPsec with visible alarm |
| Network interfaces | 2x RJ45; 2x pluggable module ports (SFP, SFP+, QSFP or QSFP28, configuration dependent); 1x dedicated management port; 1x USB |
| Management | Read-only metrics push; no inbound remote access, not even by Quantasphere |
| Certifications | NIST FIPS 140-3 and Common Criteria (EAL) certification in progress |
Specifications subject to change.
Energy & SCADA
Substation-to-control-centre links stay protected without touching the control network.
Healthcare
Multi-site hospital networks, where patient data stays sensitive for decades.
Defense field encryption
Highest-security deployments with strict compliance requirements.
Inter-bank / financial backbone
Settlement and clearing traffic between institutions.
Tessera brochure
Coming soon.
Tessera datasheet
Coming soon.
Talk to us
Request a briefing or a pilot scope.
