Live · Post-Quantum Cryptography

One migration path.
Two ways to walk it.

Post-Quantum Cryptography from Collatz Labs ships in two deployment modes — Hybrid, which runs classical and post-quantum algorithms side by side, and Pure, which replaces classical primitives outright. zkAssess's findings tell you which one fits which system.

Two Paths, One Product

Same protections either way. The difference is what's still running alongside it.

Both modes ship from the same codebase, get the same side-channel hardening, and get matched to your systems by zkAssess's findings — not chosen blind.

Hybrid

Classical + Post-Quantum, side by side

A session key derived from both a classical algorithm and ML-KEM at once — an attacker has to break both. The right call for public-facing infrastructure and anything that has to keep working with clients that don't support post-quantum yet.

See how Hybrid works →
Pure

A full replacement — no classical fallback

RSA, ECDSA, and Diffie-Hellman replaced outright with NIST-standardized post-quantum algorithms. The right call for new systems and internal infrastructure with no legacy compatibility constraint.

See the algorithm suite →
Hybrid Post-Quantum Cryptography

Classical and post-quantum key exchange, combined into one shared secret.

A hybrid handshake runs a classical algorithm (like ECDH/X25519) and a post-quantum one (ML-KEM) in parallel, then derives the session key from both. An attacker has to break both the classical and the quantum-resistant algorithm to read the traffic — not just one.

Classical
X25519 / ECDH
+
Post-Quantum
ML-KEM (FIPS 203)
Both combined into a single session key — broken only if both algorithms are broken
Pure Post-Quantum Cryptography

Three standardized primitives. No classical primitive left in the stack.

Pure Post-Quantum Cryptography replaces every quantum-vulnerable primitive outright, using the algorithms NIST finalized in August 2024 — not a placeholder waiting for a future standard.

FIPS 203

ML-KEM

Module-lattice key encapsulation — replaces RSA and ECDH for key exchange and encryption.

FIPS 204

ML-DSA

Module-lattice digital signatures — replaces RSA and ECDSA/EdDSA for signing and authentication.

FIPS 205

SLH-DSA

Hash-based signatures — a conservative fallback with a different mathematical foundation than the lattice-based pair above.

When Pure Beats Hybrid

Right for new systems. Right for the regimes heading toward quantum-safe-only.

2027

CNSA 2.0's procurement gate for new national security systems opens January 2027 — new builds are the moment to go pure, not retrofit later.

0

Legacy clients to carry forward — new systems and internal infrastructure you fully control don't need a classical fallback.

1

Cryptographic stack to maintain going forward, instead of two algorithms running in parallel indefinitely.

Side by Side

Neither is universally "right." The findings and the constraints decide.

This is the same choice enterprises deploying Post-Quantum Cryptography today are actually making.

ConsiderationHybridPure
How it works Classical (e.g. ECDH) and post-quantum (ML-KEM) run side by side; a session breaks only if both fail. Quantum-resistant algorithms replace classical ones outright — no classical fallback.
Best fit Public-facing infrastructure and systems that must stay compatible with clients that don't support post-quantum yet. New systems, and regimes such as CNSA 2.0 that plan to require quantum-resistant-only algorithms.
Who's shipped it Cloudflare, Google Chrome, and Apple iMessage already run hybrid key exchange in production. Expected as the endpoint of most migration roadmaps once compatibility constraints are gone.
Side-channel exposure ML-KEM decapsulation — power/EM leakage, FO-transform exposure, timing variance. ML-DSA signing — signing-time leakage, nonce exposure, no second algorithm as a backstop.
Trade-off Larger handshake sizes and two algorithms to maintain, in exchange for a safer transition. Simpler long-term footprint, but no fallback if a client or dependency can't yet support it.