Protect Today’s Data from Tomorrow’s Computers
Protect new and existing applications, long-lived data, and connections to legacy systems without rebuilding your technology from scratch.Build post-quantum protection into new applications, modernize existing software, or use NoPorts to protect connections to systems that cannot be changed.
Atsign gives you a practical, backward-compatible path so you can move at your own pace as standards and threats evolve.
// The Exposure Window Is Already Open
Quantum computers cannot yet break the encryption algorithms widely used today, but the threat has already begun. Attackers are stealing and storing sensitive encrypted data and plan on decrypting it once sufficiently powerful quantum computers are available. This is commonly known as the “harvest now, decrypt later” threat, or HNDL.
That should change how organizations think about timing. The key questions are how long sensitive information must remain confidential and how long it will take to replace the encryption protecting it. For intellectual property, government information, financial records, health data, and critical infrastructure information, the exposure window is already open.
NIST, CISA, NSA, and the UK’s NCSC have published post-quantum migration guidance and timelines. Their concern is practical. Finding where cryptography is used, updating it, testing the changes, and moving systems to new standards can take years.
“If your information will still be sensitive when quantum attacks become practical, you need to take action now.”
// A Simpler Way to Make the Transition
Preparing for post-quantum threats should not require every development team to design, implement, and maintain complex cryptography on its own.
Atsign is building post-quantum cryptography and crypto agility into its core SDKs. This gives organizations a common foundation for protecting new applications, modernizing existing software, and securing connections to legacy systems.
The implementation includes:
Post-quantum cryptography
New cryptographic methods designed to resist attacks from both conventional and future quantum computers.
Crypto agility
The ability to adopt new cryptographic methods as standards and threats evolve.
Flexible migration
Compatibility-first and post-quantum-default options that let organizations transition at their own pace.
Open development
Publicly accessible roadmap information, architecture decisions and code progress through GitHub.
// Three Paths to Post-Quantum Readiness
01
Build new applications
Use the updated Atsign SDKs to build post-quantum-ready applications through traditional development or with Atsign AI Architect.
02
Modernize existing applications
Integrate the updated SDKs into existing software without undertaking a wholesale application rewrite.
03
Protect connections to legacy systems
Use NoPorts to add post-quantum protection to connections and data flows involving systems that cannot or will not be modernized.
// A Flexible, Backward-Compatible Approach
Atsign will make compatibility-first and post-quantum-default options available side by side. They use the same underlying implementation and differ primarily in their preset defaults. Customers can choose the option that best fits their environment and change those defaults as their migration progresses.
Compatibility-first
New cryptographic methods designed to resist attacks from both conventional and future quantum computers.
Post-quantum by default
The ability to adopt new cryptographic methods as standards and threats evolve.
Planned availability
- Dart and Flutter SDKs: Early September 2026
- NoPorts: September 2026
- Java and Python SDKs: October 2026
- JavaScript early access: November 2026
// Designed for Today’s Standards and Tomorrow’s Changes
The default configuration combines NIST-standardized post-quantum cryptography with established classical cryptography. An alternative post-quantum key-establishment option is also available for organizations with different security requirements.
The current technical foundation includes:
- X-Wing as the default hybrid key-establishment method, combining ML-KEM-768 and X25519
- ML-KEM-1024 as an alternative key-establishment option
- AES-256-GCM for application data encryption
- ML-DSA-65, standardized as FIPS 204, for authentication and digital signatures
- A crypto-agile architecture that allows algorithms and defaults to change as standards evolve
// Frequently Asked Questions
The implementation uses the NIST-standardized post-quantum algorithms ML-KEM and ML-DSA as part of a hybrid cryptographic design.
No. NoPorts protects the connection and data flow to the legacy system. It does not modify or make the underlying application itself quantum-safe.
No. Compatibility-first and post-quantum-default options will be available side by side. Customers can choose the starting configuration that fits their environment and adjust the defaults as their migration progresses.
Crypto agility is the ability to change cryptographic methods as standards, technology and threats evolve without redesigning the entire platform.
No. Quantum computers are not currently capable of breaking the widely used encryption discussed here. The concern is that encrypted information captured today may remain valuable when that capability eventually exists.
// Explore Atsign’s Post-Quantum Readiness Resources
Press release
Read the August 26 announcement.
Technical White Paper
Learn what Atsign implemented, why it matters and how the migration works.
Architecture Overview
See how post-quantum protection fits into the Atsign Platform.
Technical Webinar and Demonstration
Join Atsign on September 16 for a technical overview and demonstration.
// Start Planning Your Post-Quantum Transition
Post-quantum migration will take time, but preparing for it does not have to require a disruptive overhaul. Speak with an Atsign engineer about your applications, infrastructure and long-term data-protection requirements.
talk with an engineer