Post-quantum,
without the rebuild
Build post-quantum readiness into your network architecture. VeilNet provides post-quantum secure connectivity across distributed cloud, on-premises and edge environments, with cryptographic agility, local policy enforcement and control over your infrastructure and keys.
Post-quantum security, enforced at every node
VeilNet combines post-quantum cryptography with cryptographic identity and distributed policy enforcement. Every endpoint holds its own keys and enforces network policy, including in disconnected environments.
Three generations of zero trust.
Then a new category.
Each generation fixed the one before it and kept a centre of its own: a gateway, a vendor's cloud, a coordination server. VeilNet has none. It's post-quantum on every connection, and it runs entirely in-house.
Tunnel into the network
- IPsec
- OpenVPN
- WireGuard
- Weak point
- An internet-facing gateway, and the whole network behind it once inside.
- Sovereignty
- In-house.
- Post-quantum
- Retrofitted, where it exists.
Hide services behind a cloud
- cloudflared
- Twingate
- Weak point
- Every connection runs through the vendor's cloud. If it's down, so is access.
- Sovereignty
- Rented. Identity and policy live in the vendor's console.
- Post-quantum
- Retrofitted, where it exists.
Connect machines directly
- Tailscale
- NetBird
- ZeroTier
- Weak point
- A coordination server decides membership, and relay servers carry what NAT blocks.
- Sovereignty
- The vendor's, unless the control plane is self-hosted.
- Post-quantum
- Retrofitted, where it exists.
Take the centre out
- No centre to target. Any machine relays for the others, and can't read what it carries.
- Entirely in-house, from the root of trust to every node.
- Required on every connection: ML-KEM-1024 and ML-DSA-87.
Products are placed by their core architecture. Self-hosting changes who runs the centre, not whether there is one.
One network. Any infrastructure.
A single software overlay virtualises the TCP/IP stack across Layers 1–3, creating a secure virtual network on the infrastructure you already run.
Create a single Layer 2 network across sites, systems and workloads, wherever they are, over the networks they already use.
Each node is identified, authenticated and connected using cryptographic identity. Membership is a signed credential chain that every node checks for itself, and addresses are derived from identity, so sites and systems join without a coordination server or changes to the nodes already there.
- Multi-region cloud — Connect environments across regions through a unified virtual network
- Edge and remote infrastructure — Reconnect and reroute automatically when links drop or networks change
- Adaptive routing — Take the best direct or relayed path, up to five hops, and switch when it fails
Publish internal services to authorised users, systems and partners on your VeilNet network. Access is governed by cryptographic identity and network policy, and traffic is encrypted end to end to the node publishing the service.
Services remain private to the network while supporting standard TCP and UDP traffic. Access can be provisioned and revoked through network membership and identity policy.
- Identity-based access — Authorise users, systems and suppliers through cryptographic identity
- Private service exposure — Make internal services reachable through the virtual network
- Local policy enforcement — Apply membership and access policy at each node
- Host isolation — Publish services from a userspace network stack, so the host itself never joins the overlay
- TCP and UDP services — Publish any TCP or UDP service, not only HTTP
Run the same secure networking across cloud, on-premises, edge and remote environments, over IP networks or, where there is none, over point-to-point serial links.
VeilNet extends the same cryptographic identity, network policy and security architecture across diverse infrastructure.
- Cloud and data centre — Connect AWS, GCP, private cloud and on-premises environments
- Defence and edge — Connect deployed, remote and intermittently connected systems
- Non-IP links — Connect nodes point to point over serial and other byte-stream links, with no IP network underneath
- Long-life infrastructure — Apply modern security architecture across systems with extended operational lifecycles
Full control across the network stack.
VeilNet operates within the organisation's infrastructure and security architecture, providing control across network identity, cryptographic infrastructure, security policy and connected systems.
Your guardian is your root of trust. It, the realms beneath it and every node run on infrastructure you control, under your own change management, and nothing above it can dissolve your realm, read its traffic or stop its nodes.
Guardian services manage node enrolment, delegated authority, network membership and security policy across distributed systems.
Key management follows one PKI tree, from the genesis through your guardian to every node. Each node's identity is an ML-DSA-87 key. Traffic is sealed with AES-256-GCM under session keys from ephemeral ML-KEM-1024 keys that rotate every ten minutes, each signed by the node's identity, giving forward secrecy in ten-minute windows.
Connected systems communicate directly across available network infrastructure, with end-to-end encryption protecting data in transit.
VeilNet runs in cloud-native, on-premises, edge, disconnected and air-gapped environments. A network that never leaves one site needs nothing public, and every node keeps enforcing policy with no connection upstream.
Move from PQC strategy to implementation.
Talk to us about assessing cryptographic architectures, validating post-quantum approaches and developing a practical transition roadmap across distributed infrastructure.