Networking security company Aviatrix on Wednesday launched Harvest and Decrypt Protection, a product that combines post-quantum encryption with controls on the destinations a compromised workload can reach.

The product enforces a single software policy across network infrastructure enterprises already operate, without requiring network redesigns, hardware replacements or application changes, the company said.

The launch comes one month ahead of an October 22 deadline for United States federal civilian agencies to submit post-quantum migration plans, and ahead of milestones set by major cloud providers. Google and Microsoft have each published roadmaps targeting full quantum readiness in 2029; Amazon Web Services has not published an equivalent target and directs customers towards regulatory deadlines.

The company says many post-quantum approaches focus on replacing cryptographic algorithms, while attackers can already intercept and store encrypted traffic on cloud backbones and other links and decrypt it once capable quantum computers exist, a tactic known as harvest now, decrypt later.

“A post-quantum program is usually measured by how much traffic it encrypts. The better metric is measuring how much traffic is exposed to capture in the first place,” said Scott Raynovich, Founder and Chief Analyst at Futuriom Research.

Aviatrix Chief Executive Officer Doug Merritt said encryption alone does not restrict what a compromised workload can reach, and that what the company calls containment enforces communication policies at the workload level on every available network path.

“Further complicating the situation, a cloud provider can be compliant while its customer is not, because provider migration covers the provider’s own services under the provider’s keys, not the customer’s estate,” Merritt said.

Aviatrix said a Fortune 5 enterprise customer already operates 400 gigabits per second of fully encrypted production traffic across clouds and regions at line rate using its High-Performance Encryption engine, which it said removes a roughly one-gigabit-per-second ceiling of traditional IPsec tunnels. Control-plane key establishment uses the ML-KEM standard, with hybrid ML-KEM on the data plane planned as a fast-follow release.

Most published estimates place Q-Day, the point at which a quantum computer could break current key-exchange mechanisms, between 2030 and 2035, the company said, noting that data-retention mandates of five to seven years for customer records, 10 years for financial records and 20 to 30 years for health records overlap with that window.

Existing Aviatrix customers can deploy the product at no initial cost, with the first five policies and five nodes free and no expiration, Aviatrix said. New customers can evaluate it free for 30 days. The company said it is working with Microsoft through its Quantum Safe program and with global systems integrators to expand availability.