ANKASecure© is ANKATech's Cryptographic Control Plane. Applications reference a stable key identifier; the platform resolves the algorithm from policy at runtime across 120+ classical, post-quantum (NIST FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA) and composite hybrid algorithms, so migrating from RSA and ECC is a policy update rather than an application rewrite. ANKASecure© delivers a REST API described in OpenAPI 3.0, a Java SDK and a CLI, a five-pillar cryptographic posture dashboard, and a signed, verifiable audit trail. Designed for CISO-level governance and developer-level integration, the platform enforces policy templates aligned with CNSA 2.0 and enables phased PQC migration with zero application downtime.

ANKASecure©

One control plane.

It executes the cryptography.

ANKASecure© does not proxy a policy: it runs the cryptographic operations, manages the key material and records signed evidence — across classical, post-quantum and composite hybrid algorithms. The Root of Trust can stay anchored in your own HSM or cloud KMS.

Request DemoView Docs

THREE CONVERSATIONS YOU DON'T WANT TO HAVE

The board asks. The auditor asks. The regulator asks.

The Board Meeting

CFO asks why you need $3M to 'change some encryption keys.' You have no migration cost model. You have no inventory. You have no timeline. The question lands at 9 AM. Your answer is due before market open.

The Audit Finding

Your SOC 2 auditor flags 'cryptographic controls not aligned to NIST SP 800-208.' Remediation requires inventorying 40+ microservices. Estimated effort: 18 months. Your renewal is in 6.

The Breach Notification

Legal asks whether the stolen dataset was encrypted. It was — with RSA-2048. The question they're about to ask: 'Is that still safe?' You don't have a confident answer.

Book a CISO briefing →
HOW IT WORKS

Four steps to crypto-agility at runtime

No code changes. No downtime. No plaintext exposure. ANKASecure© transforms cryptography from fragile application code into governed, policy-driven infrastructure.

01

Connect

Integrate without touching code

Connect ANKASecure© to your infrastructure via the REST API (OpenAPI 3.0), the Java SDK, or the CLI. Any language can call the REST API. No code changes in your applications. No downtime.

REST APISDKCLI
02

Configure

Policy in minutes, not sprints

Define your cryptographic policy in the Admin Console. Select from 29 pre-built policy templates — NIST, NSA CNSA 2.0, ENISA, BSI, ANSSI, CRYPTREC, MYSEAL 2.0, and more — or build a custom policy. Propagates across all instances in under one second.

29 templates< 1s PropagationCustom Policies
03

Execute

120+ algorithms, one API

Every encrypt, decrypt, sign, and verify request is processed through the active policy. 120+ algorithms available. Applications never see the underlying algorithm.

120+ AlgorithmsRuntime ResolutionZero Expertise Required
04

Evolve

Standards change — you don't re-write

When a standard changes anywhere in the world, update the policy. New operations use the new algorithm immediately; existing data is re-encrypted and re-signed on demand, in streaming, without plaintext exposure and without downtime.

Streaming re-encryptZero PlaintextZero Downtime
THE ALTERNATIVE

Not all options are equal.

CAPABILITY
ANKASecure©
CLOUD-NATIVE KMS
DIY MIGRATION
DO NOTHING

NIST-standardized post-quantum algorithms

ML-KEM, ML-DSA and SLH-DSA — the three finalized in FIPS 203, 204 and 205.

Zero application code changes

Your applications call the same operation before and after. The algorithm is chosen on the server.

Your existing RSA and ECC workloads keep working

Classical and post-quantum live in one catalogue, so a workload moves between them without a rewrite.

Algorithm changes by policy, no redeployment

You change the policy; the next operation uses the new algorithm. No build, no release window.

Re-encrypt data you already stored

Ciphertext that already exists moves to a new algorithm or a new key generation as a governed operation.

Multi-jurisdiction policy templates

14+ standards bodies, so a subsidiary can satisfy its own regulator and not only yours.

Connects to the HSM, KMS, directory and SIEM you already run

45 systems across 8 categories. Nothing in your estate has to move.

Per-tenant custody and integrations

One deployment where each business unit points at its own backend, its own SIEM, its own observability.

Signed, tamper-evident audit evidence

Every operation is recorded under a signature, and any change to the record breaks it.

Cryptographic sovereignty

The key that wraps your keys never leaves your HSM or your own cloud account.

Locked to one provider
6–18 months · significant rework cost
Existential risk
Supported
Partial
Not available

Partial means the capability exists in a narrower form — typically inside one vendor's own keys and driven by your code, not by policy.

CAPA — Crypto Agility Posture Architecture

Five pillars of a crypto-agility posture

The Cryptographic Control Plane reference architecture defines five pillars. ANKASecure© is its originating implementation, and each solution on this site states which pillars it realises.

Pillar 01

Crypto-Agility

An algorithm change is a policy edit that propagates in under a second. Re-encryption and re-signing move the data that already exists, without plaintext.

Pillar 02

Cryptographic Sovereignty

Per-tenant keystores, a seven-state key lifecycle, revocable authority over third parties, and a JOSE-based representation so nothing is locked to ANKATech.

Pillar 03

Frictionless Modernization

Post-quantum cryptography added to systems that cannot be redesigned: import the keys, analyze the archive, convert it, bridge the transition.

Pillar 04

Cryptographic Governance & Compliance

One engine decides what is permitted, in context, and records signed evidence that the decision applied. Regulatory alignment lives here, not in a pillar of its own.

Pillar 05

Enterprise Readiness

ANKASecure© integrates outward. Your HSM, your identity provider, your SIEM and your observability backend stay in place and stay authoritative.

The six maturity levels →Reference architecture: cryptographiccontrolplane.org↗

Nine integration families

Configured per deployment, overridable per tenant

ANKASecure© connects to what the enterprise already runs. Each family has a configuration plane, a runtime plane and a per-tenant override, so one installation serves tenants with different HSMs, identity providers and SIEMs.

Key protection

Thales Luna, Entrust nShield, AWS CloudHSM, AWS KMS, Google Cloud KMS, Azure Key Vault and Azure Managed HSM

Identity federation

OIDC, SAML and LDAP — Microsoft Entra ID, Google, Keycloak, Okta, Auth0, AWS Cognito, Active Directory, OpenLDAP, or any provider of either protocol

Workload identity

Any OIDC issuer a workload’s own platform already uses

SIEM / XDR forwarding

Splunk HEC, Microsoft Sentinel, any SIEM that consumes Syslog CEF over UDP, TCP or TLS, and any XDR over an HMAC-signed OCSF webhook

Observability export

Any OTLP endpoint — IBM Instana, Datadog, Dynatrace

Email and notifications

SendGrid, SMTP, Microsoft 365 Graph, Gmail, SMS, WhatsApp

Timestamping (TSA)

Any RFC 3161 authority — commercial, national or enterprise

Geolocation

Usage and audit enrichment

Licensing

Entitlement and usage reporting as an integration, not a manual process

Every mechanism carries a state: Certified when ANKATech has run a live round trip against the real system, Experimental when the adapter ships and that round trip has not been run. Both states are published, mechanism by mechanism.

See the certification matrix→

The catalogue

120+

algorithms: the NIST post-quantum set, FALCON, HQC, and the classical and regional families

41

composite hybrid pairings, classical + post-quantum

Regional coverage is part of the catalogue, not an add-on: KCMVP for Korea, CRYPTREC for Japan, MySEAL, and the European national profiles.

Composite keys use AND-decrypt: both components are required. ANKASecure© deliberately does not implement the OR-decrypt variant: it is only as strong as the weaker of its two components.

Three deployment models

SaaS

Operated by ANKATech. Fastest to a first governed operation.

Private cloud

Your cloud account, your network, your KMS.

On-premise

Your data centre, your HSM, air-gapped if it must be.

THE PLATFORM

Everything you need, nothing you don't

Quantum-safe encryption in one call

One request names a key and the data. The algorithm is resolved from policy at the server, so your application never chooses it.

Learn more →
encrypt.sh
1# Quantum-safe encrypt in 5 lines
2curl -X POST \
3 "$BASE_URL/api/v3/crypto/encrypt" \
4 -H "Authorization: Bearer $TOKEN" \
5 -d '{
6"kid": "my-mlkem-key", "data": "<base64>" }'

✓ Output

jweToken.ciphertext: 5eym8TW_c8SuK0ltJ3rp…

algorithmUsed: ML-KEM-1024+A256GCM

KEY GOVERNANCE

A key is not a secret you store. It is a thing with rules.

Two questions nothing else answers: what this key is allowed to do, and who is allowed to use it. Both are enforced by the platform, not by the application that calls it.

What the key is allowed to do

A usage ceiling, a soft limit that warns before the ceiling, an expiry, and whether the material may ever leave at all. The platform tracks it; nobody has to be watching.

ANKASecure© · Key detail
An ANKASecure© key detail view showing ML-KEM-1024 at NIST Level 5, exportable set to no, and usage tracked against an 80,000-operation ceiling with a soft limit at 48,000.
Real deployment · non-production data.

Who is allowed to use it

Not a role and not a group: a named actor, one capability, the exchange it applies to, and an optional constraint policy that bounds it further. Revocable one row at a time.

ANKASecure© · Key access
The access tab of an ANKASecure© key, listing which actor may encrypt and which may decrypt, the exchange each grant applies to, and its constraint policy.
Real deployment · non-production data.

And across the whole estate

The same rules, read as a fleet: which keys are past their soft limit, which are approaching the hard one, and how urgently each needs a rotation. The platform names them; nobody assembles the list.

ANKASecure© · Analytics · Usage limits
The ANKASecure© usage limits report: sixteen keys with limits, six above their soft limit, five above 75 per cent of the hard limit, an action-required banner and a table ranking each key by urgency.
Real deployment · non-production data.
DEVELOPER API

One API call. Quantum-safe.

Two fields: the key and the data. Your application never names an algorithm — the policy does, and the response tells you which one it chose. That is the whole integration.

29 data-plane operations are everything an application calls. 547 across the platform, so nothing is console-only.
Copy the call in your language — 20 of them in the API reference, from Shell and Python to Go, Rust and Swift.
Java SDK for the data plane and Java Admin SDK for the control plane; every other language over REST and OpenAPI 3.0.
NIST FIPS 203 / 204 / 205 algorithms on every operation, chosen by policy and never by the caller — and a policy change propagates in under a second.

READY-MADE RECIPES

RSA-2048 → ML-KEM-768 immediate rotationML-DSA-87 sign / verifySign-then-encrypt — nested JWE(JWS)
1# The request names a key. It never names an algorithm.
2curl -X POST "$BASE_URL/api/v3/crypto/encrypt" \
3 -H "Authorization: Bearer $TOKEN" \
4 -H "Content-Type: application/json" \
5 -d '{
6 "kid": "my-mlkem-key",
7 "data": "SGVsbG8gQW5rYQ=="
8 }'
POST /api/v3/crypto/encryptAPI reference↗

ALGORITHM-AGNOSTIC BY DESIGN

120+ Algorithms · 14+ International Standards

ANKASecure© supports 120+ algorithms across NIST, ETSI, ENISA, BSI, ANSSI, CRYPTREC, KISA, MYSEAL 2.0, and more — switch algorithms without rewriting your integration.

ML-
ML-KEM
Key Encapsulation
FIPS 203
ML-
ML-DSA
Digital Signature
FIPS 204
SLH
SLH-DSA
Hash-Based Signature
FIPS 205
FAL
FALCON
Digital Signature
ANSSI / ENISA
XMS
XMSS
Hash-Based Signature
NIST / ISO / IETF
LMS
LMS
Hash-Based Signature
NIST / ISO / IETF
Fro
FrodoKEM
Key Encapsulation
ISO/IEC
HQC
HQC
Key Encapsulation
NIST Round 4

INTEGRATION OPTIONS

CLI
Run ANKASecure© from the command line. Scripts, CI jobs, one-off operations.
REST API
Direct HTTP access to every capability. 120+ algorithms, one endpoint style.
SDK
Java SDK for the data plane and a Java Admin SDK for the control plane. Every other language calls the REST API through a client generated from the OpenAPI specification.
SaaS
Hosted by ANKATech. Isolated tenants, global low-latency, zero infrastructure.
On-Premise
Full deployment in your infrastructure. Keys never leave your environment. Air-gap compatible.

ENTERPRISE INTEGRATIONS — HSM · IAM · OBSERVABILITY

HSM

Thales Luna · Entrust nShield · AWS CloudHSM · AWS KMS · Google Cloud KMS · Azure Key Vault · Azure Managed HSM · SoftHSM

IDENTITY

Active Directory · Microsoft Entra ID · Google · Keycloak · Okta · Auth0 · AWS Cognito · OpenLDAP · any OIDC / SAML / LDAP provider

OBSERVABILITY

Any OTLP endpoint · IBM Instana · Datadog · Dynatrace

SEC ANALYTICS

Splunk HEC · Microsoft Sentinel · any SIEM over Syslog CEF · any XDR (HMAC-signed OCSF webhook)

PKI Consortium MemberPKI Consortium MemberPQC 2025 SponsorPatent-PendingCloud Security Alliance Member

Ready to become crypto-agile?

Every new application integrated with ANKASecure© is born crypto-agile.