ANKASecure© migrates existing encrypted data and signatures to NIST post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) without decrypting the payload: the data key is re-wrapped inside the control plane, in streaming with bounded memory, and the same operation re-signs. A policy template aligned with NIST, NSA CNSA 2.0, BSI, ANSSI, ETSI or CRYPTREC enforces the target across every application in under a second, PKCS#12 keystores are imported through a seven-stage validation pipeline, and composite hybrid keys require both the classical and the post-quantum component to decrypt. Every step is recorded in a signed, tamper-evident audit trail. Discovery and inventory of the existing estate are delivered by ANKATech channel partners.

The data you encrypted last year is already collected.

Harvest now, decrypt later is not a forecast — it is an accounting problem with a date attached. Migrating to post-quantum algorithms means re-encrypting what already exists, and the usual answer is to decrypt it first. ANKASecure© removes that step.

CISOHead of cryptographySecurity architect

Is this you

Three ways this lands on your desk

A regulator set a date

NIS2, DORA, a central-bank circular, or a federal procurement rule that names FIPS 203, 204 and 205. You need a plan with evidence, not a statement of intent.

A customer sent a questionnaire

It asks which algorithms protect their data and when you will move. Nobody in the building can answer it across all the applications.

Someone did the HNDL maths

Your retention period is longer than the window anyone trusts. The exposure already exists, and it grows every day you keep writing with the current algorithm.

Who signs this: A CISO or head of cryptography with a dated obligation, a budget line, and an application estate they do not personally control. If cryptography still lives in each team’s code, this is the conversation.

How it works

Four moves, none of them a rewrite

The applications keep calling the same operation. What changes is what the control plane decides to do underneath.

  1. Declare the target, once

    Pick the policy template your obligation names — NIST, NSA CNSA 2.0, BSI, ANSSI, ETSI, CRYPTREC and more. ANKASecure© starts refusing key material that does not satisfy it, everywhere, in under a second. No application ships to make that true.

  2. Bring the existing keys in

    ANKASecure© imports PKCS#12 keystores through a seven-stage validation pipeline that reports each certificate’s real status and its migration path. Expired material is imported deliberately, because data encrypted under it still has to be readable.

  3. Patent pending

    Re-encrypt without exposing plaintext

    The data key is unwrapped and re-wrapped inside the control plane. The payload is never decrypted to storage, never to a log, and never to the caller. It streams with bounded memory, so a terabyte archive is the same operation as a 4 KB record — and the same operation re-signs, so signatures migrate too.

    • REENCRYPT
    • RESIGN
    • streaming, bounded memory
    • no plaintext egress
  4. Hedge while the standards settle

    Composite keys pair a classical and a post-quantum component and require both to decrypt — the AND-decrypt mode. If one component is broken, the payload is not. ANKASecure© deliberately does not implement the OR-decrypt variant.

Where the migration actually stands

Post-quantum adoption measured over a real estate, not estimated — the classical, post-quantum and hybrid split, and every algorithm in use ranked by how many keys hold it. The number you start from is usually the uncomfortable one.

ANKASecure© · Analytics · Algorithm usage
The ANKASecure© algorithm usage report: 4,143 keys, post-quantum adoption at 18.2 per cent, 2,147 classical, 547 post-quantum and 208 hybrid keys, with the algorithms in use ranked beneath.
Real deployment · non-production data.

Fifteen minutes

What you will actually watch

Live, on your data shape, against a real deployment. Nothing in this list is a mock-up or a roadmap item.

  1. A file encrypted under RSA. The envelope, and the key it points at.

  2. The policy is tightened to a post-quantum minimum. The next key generation is refused, with the reason.

  3. Re-encryption to ML-KEM. Memory stays flat while the file streams. No plaintext anywhere you can point at.

  4. The old envelope still opens, because the old key was retired and not destroyed. The lifecycle state that makes that a rule rather than a favour.

  5. The audit trail for every step, signed, with the policy decision recorded next to the operation.

  6. Your question, answered on the deployment rather than on a slide.

What it rests on

The capabilities underneath, with their state

  • Shipping

    Re-encryption and re-signing without plaintext exposure

    Compact and streaming, bounded memory at any file size.

  • Shipping

    120+ algorithms

    The NIST post-quantum set (ML-KEM, ML-DSA, SLH-DSA), FALCON and HQC alongside the classical and regional families, plus 41 composite hybrid pairings.

  • Shipping

    29 policy templates

    29 of them algorithm-availability templates, and 24 of those tied to a named standard or jurisdiction.

  • Shipping

    PKCS#12 import

    Seven-stage validation pipeline with certificate status and migration-path analysis.

  • Shipping

    Signed audit trail

    Tamper-evident chain, queryable per tenant, forwardable to your SIEM with the signature preserved.

  • Per channel

    Discovery and inventory

    What your estate uses today, delivered by ANKATech channel partners. Discovery produces visibility; the control plane produces control.

All of the platform →

The framework

Where this sits in CAPA

The Cryptographic Control Plane reference architecture describes each pillar through the scenarios it must handle and one practical test. This solution is two of those scenarios, and it is measured against their tests.

01

Primary pillar

Crypto-Agility

Scenario realised

Transitioning to post-quantum cryptography

Practical test

“Can the cryptographic strategy change without requiring an application change or release?”

03

Primary pillar

Frictionless Modernization

Scenario realised

Modernizing historical encrypted data

Practical test

“Can the protection of data encrypted years ago be changed today, without the originating application and without plaintext at rest?”

04

Supporting pillar

Cryptographic Governance & Compliance

Scenario realised

Enforcing a new enterprise security requirement

Practical test

“Can the organization prove, by querying the control plane, which policy applied to a given operation, and change that policy centrally?”

L1–L2L3–L4

Maturity move

From algorithms hardcoded in application code to a Control Plane where an algorithm change is a policy update. The migration itself is the step from level 2 to level 3; keeping it that way is level 4.

The six maturity levels →Reference architecture: cryptographiccontrolplane.org

What this does not do

  • It does not find your cryptography for you. Inventory across an estate is a discovery engagement, and ANKATech partners run it.

  • It does not re-encrypt data it cannot reach. Anything held by a system that will not delegate the operation stays where it is.

  • It does not certify you. ANKASecure© maps its controls to NIST CSWP 39, the GSA PQC Buyer’s Guide and OWASP and hands you the evidence; the determination is still your auditor’s.

Bring your worst file.

A terabyte archive, an expired certificate, a format nobody owns. Fifteen minutes on a live deployment.

Book the demo