Pre-release · Announcement6 September 2026 · Perth, Australia

VeilNet releases the third generation of its overlay, open for evaluation

Conflux 1.0.0-pre puts a machine on a post-quantum network with one command. There's no account to create and no key to manage. We're calling it a pre-release because we'd rather people found the rough edges now than after we call it finished.

Version
1.0.0-pre
Generation
Third
Platforms
7 targets, 5 OS
Primitives
ML-DSA-87 · ML-KEM-1024 · AES-256-GCM

PERTH, AUSTRALIA — VeilNet today released Conflux 1.0.0-pre, the third generation of its sovereign post-quantum network, as a public pre-release. It runs on seven platforms across five operating systems, and getting started takes a single command, with no account to create and nothing to configure first.

VeilNet built its zero-trust network on post-quantum cryptography from the start, instead of retrofitting it later. Conflux 1.0.0-pre is the third generation of that work, and the biggest change isn't a new algorithm. It's full sovereignty.

Delivering sovereignty and simplicity

Every earlier generation still tied customers back to us in some way: an account to hold, a service of ours running in the background, something their security ultimately depended on us for. This release removes the last of it. There's nothing to sign into and nothing of ours in the loop, so if VeilNet were ever breached, subpoenaed or acquired, our customers' networks would carry on exactly as before. There's simply nothing left on our side for anyone to compel.

This matters beyond VeilNet. For years, much of the security industry's answer to “stop trusting the network” has been to trust a vendor instead: a console, an identity service, a cloud control plane sitting between an organisation and its own systems. We've all seen what that costs. A vendor gets breached, or subpoenaed, or changes its terms, and every one of its customers is affected at once. Post-quantum cryptography deals with a threat that's still a few years away. Taking the vendor out of the loop deals with one that exists right now.

The simplicity comes from the same design. A machine joins with one command and doesn't need looking after. What used to be a network project lasting weeks is now something one person can finish in a morning, whether it's a laptop, an industrial sensor or a field radio. The free tier is free of us, not merely free of charge, because there is nothing left on our side to charge for.

Why this can't wait for 2030

Organisations aren't asking whether the transition is coming any more. They're asking which of their systems have no upgrade path, and that can be answered today.

The first post-quantum mandates land in 2030, and they're already being written into procurement. Most of the estates we're asked to look at have equipment that will still be in service by then and can't be made post-quantum on its own. An overlay protects that equipment where it is, without anyone having to replace it.

About VeilNet

VeilNet builds sovereign, post-quantum networking. One overlay protects everything an organisation runs, whatever physical network sits underneath, and the organisation keeps full control of it. There's no vendor in the data path and no vendor console to breach. VeilNet has been built on post-quantum cryptography since 2025.

Media and evaluation enquiries: sovereign@veilnet.com.au

Quick start

Two commands, and the network is up

Install the binary, run conflux up on one machine, then run it on every other machine with the taint it printed. Everything else, install steps per platform, the two modes, taints, reverse proxy, uplinks, commands and the security model, is in the documentation.

1 — the first machine
$ sudo conflux up
  Overlay IPv4 [e.g. 10.128.0.7/24, blank for IPv6-only]: 10.128.0.1/24

Minted a taint for this network:

    brhk-2mq9-tzva-6pjs

  anchor       anchor6btpa3gn6w4stipba4hekzho7caw6srfyy5puvbz7mfanaiept5a
  overlay      fd80:c4b9:99ae:4411:c531:fd4f:754f:f08a/48
  overlay      10.128.0.1/24
  interface    anchor0
  credential   valid until 2026-09-13T06:35:43Z (6d 23h)
  service      active (systemd: conflux.service, enabled at boot)
2 — every other machine
$ sudo conflux up --taint brhk-2mq9-tzva-6pjs

A reboot needs nothing typed: the service is registered, the credential renews itself, and the machine comes back at the same overlay address.

Detail — Download

Available for every major platform

There are seven builds, across five operating systems. Check the download against the checksums, then see install notes for the right platform.

Every link points at the 1.0.0-pre release, which is where each new build of this line is published. The digests are the release's own SHA256SUMS, uploaded on 24 September 2026, read when this page was built.

Feedback

Tell us what turned up

If something didn't work, didn't make sense, or didn't match the docs, tell us here. It goes straight to the people who wrote it. Your email is optional, but we can only reply if you leave one.

From conflux version.