Most PQC pitches stop at the algorithm. Aviatrix’s Sep 22 release tries to sell the trunk: encrypt the path and govern what a compromised workload can still reach — on the same enforcement point.
Aviatrix launched Harvest and Decrypt Protection via GlobeNewswire on September 22. Company framing: the “first” post-quantum protection that encrypts and simultaneously governs what a compromised workload can reach, delivering post-quantum encryption and Communication Governance as one policy in software. “First” is a marketing claim until a competitive bake-off says otherwise. The architectural thesis is clearer than the slogan: crypto-agile encryption under enterprise-controlled keys, plus egress / east-west containment so harvest paths close before Q-Day arrives.
Why now — deadlines the company itself puts on the page. The release says the offering arrives a month before federal civilian agencies must file post-quantum migration plans on October 22. It cites Executive Order 14412 dates of December 31, 2030 for post-quantum key establishment (and federal contractor PQC standards) and December 31, 2031 for digital signatures on high-value assets and high-impact systems — print those only as Aviatrix-attributed from the GlobeNewswire text. Same release attributes Google and Microsoft roadmaps for full quantum readiness in 2029; CyberMerge is not independently re-underwriting those vendor roadmaps here — they are Aviatrix’s citations. AWS, per the same PR, is said to publish no equivalent target.
What ships, per company: High-Performance Encryption pitched against IPsec’s ~1 Gbps-per-tunnel collapse; one unnamed Fortune 5 customer claimed at 400 Gbps fully encrypted in production (vendor anecdote — not a CyberMerge-verified benchmark). Control-plane key establishment uses ML-KEM today; hybrid ML-KEM on the data plane is called a fast-follow on the roadmap. Communication Governance on the same gateways — no extra appliance. Crypto visibility / CBOM-style network-path inventory sits on the quantum-safe roadmap. Aviatrix also says it is collaborating with Microsoft on the Quantum Safe program as the network-traffic / harvest-containment piece.
Commercial wedge as stated (TAM Undisclosed): existing Aviatrix customers get the first five policies and five nodes free, no license and no time limit; new customers get a 30-day trial. Free Containment Assessment (self-service; provisional Blast Radius and harvest exposure in about five minutes); Level 2 is a read-only engagement against live flows sized as “Reachable Value at Risk.” Those are company offers. Pipeline and market size: Undisclosed.
POV: the smart move in the pitch is pairing algorithm agility with containment. Harvest-now-decrypt-later is not only a future quantum event — ungoverned egress is a present classic. The weak move is the “first” framing and the Fortune 5 throughput flex without a named customer or third-party measurement. Boards should ask: which paths does Aviatrix actually encrypt today versus promise; who holds the keys when the cloud provider’s own PQC migration finishes; and whether five free policies are a wedge or a toy relative to the east-west surface of a real multi-cloud estate. Cloud network as PQC + harvest containment layer is a serious thesis. Underwrite the architecture. Discount the slogan.
Underwrite sheet — sourced only: Harvest and Decrypt Protection launch Sep 22 (GlobeNewswire / Aviatrix blog / Quantum Insider); PQC encryption + Communication Governance same enforcement point (company); Oct 22 federal PQC plan filing + EO 14412 Dec 31, 2030 / Dec 31, 2031 dates as stated in Aviatrix PR; Google/Microsoft 2029 readiness as Aviatrix-attributed; five free policies + five nodes / 30-day trial / Containment Assessment (company); 400 Gbps Fortune 5 claim (company anecdote); TAM Undisclosed. Question “first.” Ship the containment question to the board.
