Tessera 1U rack appliance
Quantum Secure Encryption

Tessera

Available now

Post-quantum network encryption gateway for site-to-site WAN traffic. Deploys beside your existing edge in days, with a single short cutover and zero disruption.

Overview

A quantum-safe gateway for the network you already have.

Tessera is an integrated hardware and software system. An onboard Aevum quantum random number generator supplies the entropy, and NIST-standardised post-quantum algorithms (ML-KEM for key agreement, ML-DSA for signatures, FIPS 203 and 204) protect the traffic. Keys are generated and held in a hardware-rooted secure enclave and never leave it.

It deploys as a sidecar: a Layer-3 appliance beside your existing edge routing. Your SD-WAN keeps making every routing decision, and Tessera wraps a post-quantum layer inside your existing IPsec tunnel. Because the protection sits underneath what you already run, deployment needs no re-addressing, no replacement hardware and no scheduled outage beyond one short cutover.

Tessera is vendor-blind by construction. The two Guards on a link agree keys directly with each other, and the Distributor that introduces them holds no secrets and cannot read either side. This means a compromise of Quantasphere does not expose your traffic. It also means peers keep communicating through any outage of ours: your links never depend on our infrastructure being online.

FIG. 01 — TESSERA ARCHITECTURE TRUSTED · SITE A TRUSTED · SITE B UNTRUSTED Tessera Distributor brokers keys only · holds no secrets · cannot read traffic Tessera Guard + QRNG A ATTESTED ✓ Tessera Guard + QRNG B ATTESTED ✓ plain encrypted encrypted plain Site A Network SD-WAN A SD-WAN B Site B Network IPSEC · OUTER INTERNET / WAN TESSERA PQC · INNER Your data 1 2 3 4 5 6 7 VALVE-7: OPEN
Key features

Vendor-blind key agreement

Keys never leave your hardware.

Continuous hardware attestation

Every peer keeps proving it is genuine. A tampered device is cut off automatically.

Zero-teardown key rotation

Keys refresh constantly with no break in live traffic.

Sidecar deployment

Drops in beside your SD-WAN. No rip-and-replace.

Fails safe, never silently

On any PQC-layer failure, traffic falls back to your existing IPsec with a visible alarm. Never silently, and never to an unverified peer.

Inter-organization pairing

Connect different organizations securely. The broker holds no secrets.

Specifications
Form factor1U rack appliance
Deployment modelLayer-3 sidecar beside existing edge routing (e.g. SD-WAN)
ThroughputUp to 100 Gbps
LatencySub-100 microseconds
Post-quantum algorithmsML-KEM + ML-DSA (NIST FIPS 203/204)
Key handlingVendor-blind key agreement; keys generated and held in a hardware-rooted secure enclave, never exported
Entropy sourceIntegrated Aevum quantum random number generator
AttestationContinuous mutual hardware attestation
Key rotationContinuous, zero-teardown
Failure behaviourFail-safe to existing IPsec with visible alarm
Network interfaces2x RJ45; 2x pluggable module ports (SFP, SFP+, QSFP or QSFP28, configuration dependent); 1x dedicated management port; 1x USB
ManagementRead-only metrics push; no inbound remote access, not even by Quantasphere
CertificationsNIST FIPS 140-3 and Common Criteria (EAL) certification in progress

Specifications subject to change.

Use cases

Energy & SCADA

Substation-to-control-centre links stay protected without touching the control network.

Healthcare

Multi-site hospital networks, where patient data stays sensitive for decades.

Defense field encryption

Highest-security deployments with strict compliance requirements.

Inter-bank / financial backbone

Settlement and clearing traffic between institutions.

Resources

Tessera brochure

Coming soon.

Tessera datasheet

Coming soon.

Talk to us

Request a briefing or a pilot scope.

See Tessera on your own network.

Request a briefing