Aviatrix is launching Harvest and Decrypt Protection, a cloud security offering that combines post-quantum encryption with workload communication governance to help enterprises limit both future quantum decryption risk and the paths attackers can use to exfiltrate data today.
The software applies both controls through a single policy and enforcement point across cloud environments.
Aviatrix combines post-quantum encryption and communication governance
Aviatrix’s new crypto-agile encryption makes captured traffic worthless to a future quantum computer while its communication governance – including egress governance – closes the paths data leaves through today.
Harvest and Decrypt Protection provides:
- Encryption that does not cost throughput: Aviatrix’s High Performance Encryption engine provides line-rate encryption in production across clouds and regions.
- Crypto agility as a policy setting: Hybrid ML-KEM on the data plane is a fast-follow release on the Aviatrix platform roadmap.
- Communication Governance on the same gateways: Governs what every workload can reach, cutting the channels attackers use to extract data and replacing cloud-native routing that provides connectivity without security. With no additional appliance required.
- Evidence auditors require: The Aviatrix quantum-safe roadmap extends Harvest and Decrypt Protection with crypto visibility, mapping which applications are exposed, what they depend on, and where they communicate in cleartext.
- Free to start: The first five policies and five nodes are free, with no license and no time limit.
These new offerings will make the Aviatrix Cloud Native Security Fabric quantum-safe.
Why this matters to partners
For MSPs, MSSPs, and cloud solution providers, the launch could create an opening to bring post-quantum readiness into existing cloud security conversations. Partners can build services to assess cryptographic exposure, identify unprotected workload communications, and help customers prepare migration plans as quantum-related requirements approach.
Aviatrix’s free starting tier could also give partners a lower-friction way to introduce those conversations with customers before broader post-quantum migrations become necessary.
Free entry tier arrives ahead of federal migration deadlines
The quantum solution is free to start with no trial clock and no purchase required. It will arrive a month before federal civilian agencies must file post-quantum migration plans on October 22 and years before major cloud providers reach the same deadline.
Harvest and Decrypt Protection, along with the Aviatrix Cloud Native Security Fabric, run on the network enterprises already operate on with enterprise control rather than cloud provider control.
“Post-quantum readiness is an architecture problem. Encryption protects data in motion, but most enterprise cloud environments place no constraint on what a compromised workload can reach, exposing valuable data for harvest,” said Doug Merritt, CEO, Aviatrix.
“Chokepoint Security cannot close that gap, because the traffic carrying the data out never crosses the chokepoint. Containment closes it at the workload, on every path available to it. Further complicating the situation, a cloud provider can be compliant while its customer is not, because provider migration covers the provider’s own services under the provider’s keys, not the customer’s estate,” Merritt added.
Post-quantum deadlines put cryptography planning in focus
The aforementioned October 22 filing is one of several quantum-related deadlines for organizations to keep an eye on.
Executive Order (EO) 14412 sets Dec. 31, 2030 as the deadline for post-quantum key establishment and Dec. 31, 2031 for digital signatures on high-value assets and high-impact systems. It also requires federal contractors to meet post-quantum standards by Dec. 31, 2030.
Various industries have also been monitoring quantum deadlines to prepare for a post-quantum future.
Since March 31, 2025, the Payment Card Industry Data Security Standard 4.0 has made a cryptographic inventory a live audit item.
Beginning Jan. 1, 2027, the Commercial National Security Algorithm Suite 2.0 will require new National Security System acquisitions to support post-quantum algorithms.
Additionally, there is a proposed update to the Health Insurance Portability and Accountability Act Security Rule that would make encryption of electronic protected health information mandatory in transit and at rest.





