<style>.g-image--loading{display:none;}</style>
The Solution / Components

Hardware on the wire.
Policy off to the side.

Two components. The Q-Box encrypts every packet in silicon. The QPM decides who may talk. Nothing else ever touches your data.

The data journey
01
Plain-text in
Endpoint sends clear traffic into the Q-Box endpoint port.
02
Q-Box encrypts
AES-256-GCM in silicon, a fresh key as often as every packet.
03
Cipher on the wire
Only cipher-text crosses the untrusted network.
04
Q-Box decrypts
Peer Q-Box authenticates the source and decrypts.
05
Plain-text out
Clear traffic exits to the destination endpoint.
How it fits together

The architecture

A secure overlay on the network you already run. Trust is created between protected endpoints across an untrusted path.

QPM
Control plane. Q-Boxes register themselves to the QPM, and the QPM pushes policy to registered Q-Boxes. No user traffic ever traverses the QPM.
DATA PLANE · POINT-TO-POINT
PROTECTED
SERVER
PLC / RTU
SENSOR
ANY IP ENDPOINT
PLAIN
Q-BOX
AES-256
UNTRUSTED
NETWORK
AES-256
Q-BOX
PLAIN
PROTECTED
SERVER
PLC / RTU
SENSOR
ANY IP ENDPOINT
Plain-text inside the perimeter · cipher-text on the wire · new keys used up to every packet
01 / The hardware

Q-Box

A silicon encryption device — no processor, no OS, no software — that drops directly in line on the ethernet segment of the device it protects. A hardware barrier discards unauthorized data at line rate.

AES-256
GCM · IN SILICON
#7
0/142
PATENTED JUST-IN-TIME KEYING
2,000
CONNECTIONS / BOX
0
IP · AGENTS · SOFTWARE PATCHES
Q-BOX
ENDPOINT
PLAIN-TEXT
Q-BOX
NETWORK
CIPHER-TEXT
On the roadmap
We aren't done yet — increased throughput and more coming soon.
Contact us for details →
02 / The brain

QPM

The Q-Net Policy Manager is where you describe what is allowed — bring-your-own-OS installable software, or available as a SaaS. It distributes policy; no user traffic ever passes through it.

Zero data path
Establishes secure connections only — never sees your traffic.
Thousands of boxes
Individual or group management with automated keying.
Instant revoke
Pull a Q-Box from the network if a unit is lost or captured.
Plane separation
Control plane fully separated from the data plane.
Deployment

Bump-in-the-wire.
Set & forget.

Drop in
Insert the Q-Box in line on the physical cable. No rip & replace, no IP changes, no agents.
Define policy
In the QPM, declare which Q-Boxes may talk, down to port and protocol. Default deny.
Walk away
No software, patches or reboots. Boxes keep keying even if the QPM goes offline.
Where it runs
Grid edge & OT
Encrypt control traffic over public ethernet for utilities, water, and oil & gas.
Defense & SATCOM
Securing commercial LEO internet solutions & Iridium for maritime and the tactical edge under USAF grant.
Remote access
Reach hard-to-access plants with no servers or software to maintain.
3
DAY USCYBERCOM
EXERCISE

The only solution to remain unbroken — no Q-Net-protected endpoint was ever compromised over the three-day exercise.

— USCYBERCOM smart-city red-team exercise · Validated with NCCoE & NIST