Sovereign post-quantum networking

Post-quantum,
without the rebuild

Build post-quantum readiness into your network architecture. VeilNet provides post-quantum secure connectivity across distributed cloud, on-premises and edge environments, with cryptographic agility, local policy enforcement and control over your infrastructure and keys.

CNSA 2.0ASD 2030EU PQC roadmap
ML-KEM-1024ML-DSA-87AES-256-GCMReinforcement learningDecentralisation
01 — Why VeilNet

Post-quantum security, enforced at every node

VeilNet combines post-quantum cryptography with cryptographic identity and distributed policy enforcement. Every endpoint holds its own keys and enforces network policy, including in disconnected environments.

Post-quantum by default

ML-KEM for key establishment and ML-DSA for cryptographic identity and authentication.

NIST-standard cryptography

ML-KEM and ML-DSA from the NIST Post-Quantum Cryptography standardisation process, with AES-256-GCM for authenticated encryption.

Crypto-agile architecture

Algorithms are versioned as cipher suites throughout the protocol, so new ones can be added as standards evolve. Each network chooses its suite when it is created.

Cryptographic identity

Every node's identity is an ML-DSA key, and its membership a credential chain in the network's PKI tree. Both are checked before any connection opens, and together they are the basis for policy enforcement.

Distributed policy enforcement

Membership and routes are signed and spread peer to peer, and every node enforces membership, routing and compartment rules for itself, with no central controller.

Sovereign key control

Cryptographic identities and network security functions operate within organisation-controlled infrastructure.

Self-hosted and air-gapped

Deploy across cloud, on-premises, edge, restricted and disconnected environments, with security policy enforced locally.

End-to-end encryption

Network traffic is authenticated and encrypted between connected endpoints using modern cryptographic primitives.

02 — A new category

Three generations of zero trust.
Then a new category.

Each generation fixed the one before it and kept a centre of its own: a gateway, a vendor's cloud, a coordination server. VeilNet has none. It's post-quantum on every connection, and it runs entirely in-house.

Fig. 02 — How zero trust evolved01 / 04
1990sNow
LANGATEWAY
Conventional VPN

Tunnel into the network

  • IPsec
  • OpenVPN
  • WireGuard
Weak point
An internet-facing gateway, and the whole network behind it once inside.
Sovereignty
In-house.
Post-quantum
Retrofitted, where it exists.
CONNECTORVENDOR CLOUD
Reverse proxy

Hide services behind a cloud

  • cloudflared
  • Twingate
Weak point
Every connection runs through the vendor's cloud. If it's down, so is access.
Sovereignty
Rented. Identity and policy live in the vendor's console.
Post-quantum
Retrofitted, where it exists.
CONTROL
Overlay mesh VPN

Connect machines directly

  • Tailscale
  • NetBird
  • ZeroTier
Weak point
A coordination server decides membership, and relay servers carry what NAT blocks.
Sovereignty
The vendor's, unless the control plane is self-hosted.
Post-quantum
Retrofitted, where it exists.
Gossip non-mesh

Take the centre out

  • VeilNet
Weak point
No centre to target. Any machine relays for the others, and can't read what it carries.
Sovereignty
Entirely in-house, from the root of trust to every node.
Post-quantum
Required on every connection: ML-KEM-1024 and ML-DSA-87.

Products are placed by their core architecture. Self-hosting changes who runs the centre, not whether there is one.

03 — Capabilities

One network. Any infrastructure.

A single software overlay virtualises the TCP/IP stack across Layers 1–3, creating a secure virtual network on the infrastructure you already run.

Create a single Layer 2 network across sites, systems and workloads, wherever they are, over the networks they already use.

Each node is identified, authenticated and connected using cryptographic identity. Membership is a signed credential chain that every node checks for itself, and addresses are derived from identity, so sites and systems join without a coordination server or changes to the nodes already there.

  • Multi-region cloud — Connect environments across regions through a unified virtual network
  • Edge and remote infrastructure — Reconnect and reroute automatically when links drop or networks change
  • Adaptive routing — Take the best direct or relayed path, up to five hops, and switch when it fails

Publish internal services to authorised users, systems and partners on your VeilNet network. Access is governed by cryptographic identity and network policy, and traffic is encrypted end to end to the node publishing the service.

Services remain private to the network while supporting standard TCP and UDP traffic. Access can be provisioned and revoked through network membership and identity policy.

  • Identity-based access — Authorise users, systems and suppliers through cryptographic identity
  • Private service exposure — Make internal services reachable through the virtual network
  • Local policy enforcement — Apply membership and access policy at each node
  • Host isolation — Publish services from a userspace network stack, so the host itself never joins the overlay
  • TCP and UDP services — Publish any TCP or UDP service, not only HTTP

Run the same secure networking across cloud, on-premises, edge and remote environments, over IP networks or, where there is none, over point-to-point serial links.

VeilNet extends the same cryptographic identity, network policy and security architecture across diverse infrastructure.

  • Cloud and data centre — Connect AWS, GCP, private cloud and on-premises environments
  • Defence and edge — Connect deployed, remote and intermittently connected systems
  • Non-IP links — Connect nodes point to point over serial and other byte-stream links, with no IP network underneath
  • Long-life infrastructure — Apply modern security architecture across systems with extended operational lifecycles
AUNZUSCAGBSecurity without boundary
04 — Sovereignty

Full control across the network stack.

VeilNet operates within the organisation's infrastructure and security architecture, providing control across network identity, cryptographic infrastructure, security policy and connected systems.

Full sovereignty
YOUR INFRASTRUCTURE, END TO END01Root of trustML-DSA-87 · GENERATED AND HELD OFFLINE, IN A SAFE02Guardian serviceSELF-HOSTED MANAGEMENT — ENROL, DELEGATE, SUPERVISE, REVOKE03Realms and sub-realmsA REALM PER BUSINESS UNIT OR SITE — ORG CHART IS THE NETWORK04NodesTHE OVERLAY ITSELF — PEER TO PEER, NO TRAFFIC VIA A THIRD PARTYNODENODENODENODENODEREVOKED

Your guardian is your root of trust. It, the realms beneath it and every node run on infrastructure you control, under your own change management, and nothing above it can dissolve your realm, read its traffic or stop its nodes.

Guardian services manage node enrolment, delegated authority, network membership and security policy across distributed systems.

Key management follows one PKI tree, from the genesis through your guardian to every node. Each node's identity is an ML-DSA-87 key. Traffic is sealed with AES-256-GCM under session keys from ephemeral ML-KEM-1024 keys that rotate every ten minutes, each signed by the node's identity, giving forward secrecy in ten-minute windows.

Connected systems communicate directly across available network infrastructure, with end-to-end encryption protecting data in transit.

VeilNet runs in cloud-native, on-premises, edge, disconnected and air-gapped environments. A network that never leaves one site needs nothing public, and every node keeps enforcing policy with no connection upstream.

Start with an evaluation

Move from PQC strategy to implementation.

Talk to us about assessing cryptographic architectures, validating post-quantum approaches and developing a practical transition roadmap across distributed infrastructure.

01
AssessIdentify cryptographic dependencies, assess current architectures and understand where post-quantum requirements affect systems, services and network infrastructure.
02
DesignEvaluate architectural options, define security requirements and develop a practical pathway for introducing post-quantum security across cloud, on-premises and distributed environments.
03
ValidateRun technical evaluations and proofs of concept in representative environments to validate architecture, security controls, performance and operational requirements.
Air-gapped welcomeNo data leaves the estate