American Binary: Why “Mostly Post Quantum” Is Another Way to Say Vulnerable
If you’ve sat through a vendor briefing in the last 2 years, you’ve been told your stack is now quantum safe. Somebody bolted a hybrid post quantum key exchange onto an otherwise unchanged product, put a badge on a slide, and moved on. As a CISO, I’ve learned to ask follow up questions. Which parts, exactly? Almost always the answer is some parts. That gap between some and all is where American Binary has decided to build a company.
I put that question to Cris Salas, EVP of Sales at American Binary and team, across a presentation and discussion of the company’s product in July. Ambit, Inc., doing business as American Binary, was founded by national security and technology operators to build post quantum network security software for outfits that, in the company’s phrasing, can’t afford to be wrong about security. It’s a marketing line. But as Salas laid out the customer profile it proved an accurate one. Federal agencies, defense contractors, critical infrastructure operators, and enterprises whose data has a shelf life measured in decades, not quarters.
Harvest Now, Decrypt Later does not require a working quantum computer, and Salas is emphatic that it’s underway at this moment. Adversaries capture encrypted traffic today financial records, PII, credentials, source code, intelligence and warehouse it until quantum capability matures. What separates this from ordinary security debt is the disclosure problem, and it’s the point Salas came back to most often. Whoever gets there first profits from silence. You won’t learn that the window closed. You’ll only learn what was in the archive.
Partial Compliance Is Failure
What makes American Binary worth a serious look is that it’s anchored itself to the one standard that refuses to grade on a curve.
NSA’s CNSA (Commercial National Security Algorithm) 2.0 sets the cryptographic requirements for National Security Systems. It mandates that networking equipment, VPNs included, support and default to CNSA 2.0 post quantum cryptography by January 2026, and that all new NSS acquisitions be quantum resistant in 2027. It’s deliberately stricter than broader NIST guidance, permitting only maximum-security levels, and it is blunt about what does not count. “Do not use a hybrid or other non-standardized solution on NSS mission systems,” NSA writes, and it “does not recommend the usage of quantum key distribution and quantum cryptography for securing National Security Systems.”
Scope is the part most vendor claims quietly elide, and Salas was direct about it. CNSA 2.0 covers four components authentication, key exchange, bulk encryption, and hashing and under the standard, partial compliance is failure. Three out of four is not seventy-five percent secure. That is an exploitable seam, which is precisely how attackers approach cryptographic systems. Not through the strongest component. Around it.
Ambit Client, the company’s enterprise VPN, covers all four. ML-KEM-1024 for authentication and key exchange, AES-256-GCM for bulk encryption, SHA2-512 for hashing, with no pre quantum or classical cryptography anywhere in the stack. Salas claims the product stands alone in that full-stack coverage, with the nearest competitors leaning on elliptic curve, pre-shared keys, or Diffie-Hellman for at least one component which is to say, on cryptography a quantum capable adversary is expected to break. Getting mutual authentication out of ML-KEM-1024 is not a configuration choice but a genuine engineering problem, and it’s where the company’s patent filed Cryptographic Construction Innovation lives.
Somebody Actually Checked the Math
American Binary departs from the industry norm here, and security leaders should pay attention to how. The company didn’t simply assert that its construction works. It put that construction through a symbolic proof, privately peer reviewed by qualified third parties, validating mutual authentication under ML-KEM-1024 along with the remaining claims required for CNSA 2.0 compliance. A formal attestation from the reviewers is available on request. These are not friendly analyst firm reviewers.
“No known VPN post quantum or classical, deployed or research has been subjected to specification and formal verification of comparable depth.”
– Dr. Joe Kiniry, PhD and Dr. Tom Shrimpton, PhD, former Galois Principal Scientists / DARPA
Oracle’s Cryptography Review Board reached a similar conclusion through a different door. It evaluated Ambit Client against NIST recommendations, FIPS standardization, and NSA regulation, then validated the product as aligned with Oracle’s own post quantum strategy. That gate matters more than a typical partner badge, because Oracle inherits reputational exposure for any cryptographic claim it endorses. Strong disincentive to wave something through.
Their advisory bench reinforces it. Brian LaMacchia, a principal architect of post quantum cryptography standards and longtime IACR board member. Bruce Schneier, whose work on applied cryptography most of us have on a shelf. Whitfield Diffie, co-inventor of public-key cryptography and a Turing Award recipient. That’s not a logo wall those are reputations that do not survive endorsing something unsound.
For a CISO, formal verification is not an academic nicety. It’s a procurement accelerant that compresses diligence cycles and hands your auditors, your regulators, and your board something defensible instead of a vendor datasheet.

About That Performance Tax
Ask any network team about post quantum migration and you’ll hear the same objection. Larger keys, fatter handshakes, slower everything. It’s the argument I’ve heard used most often to defer the transition another budget cycle.
When I put that objection to Salas, the answer was that American Binary’s numbers move in the opposite direction, and that the mechanism is the same Cryptographic Construction Innovation behind the compliance story. The construction cuts handshake packet size by roughly 4,600 bytes against an out-of-the-box CNSA 2.0 implementation. Over mobile networks with MTU constraints, that’s three packets instead of seven or eight the difference between post quantum cryptography that works on a 5G or satellite link and post quantum cryptography that only works in a lab.
On throughput, the company pairs Vector Packet Processing with the Data Plane Development Kit to parallel process packets rather than handle them sequentially. The claimed results run to 100 percent of line rate sustained on terabit networking, 70 percent faster client-to-server downloads than the leading enterprise VPN, and a maximum supported throughput 4,167 percent above the nearest competitor, whose comparable figure is 24 Gbps and needs a dedicated hardware cluster to reach it. Ambit Client needs no hardware replacement.
Operationally it matches. Deployment in hours, not weeks, with SSO and full fleet rollout. Twenty supported architecture categories from point-to-point through multi-cloud and IoT/OT segmentation, across all major desktop and mobile operating systems. And the metric most telling for anyone who’s run a helpdesk 98 percent of users touch the client once every two weeks. Security that generates tickets does not stay deployed.
Crypto Agility, or Doing It Once
Salas’s strategic argument and the one I’d put in front of a board concerns the transition, not the technology. Most vendors are selling a hybrid path, classical plus post quantum running together, which means a partial migration now and a full migration later. Two projects, two change windows, two rounds of validation, two budgets. NSA has said not to do it on mission systems. American Binary’s position is that a purely quantum resistant architecture built from the ground up lets you transition one time instead of two or more.
Then it goes a step further. Ambit Client is designed for full crypto agility, so algorithms swap at the product level as standards evolve, with protection against downgrade attacks, and the underlying protocol swaps too. At the heart of the VPN, and available standalone, sits MaxKyber the company’s post quantum network protocol, peer reviewed as fully meeting CNSA 2.0. Interoperability is handled three ways today. Tunnel-in-tunnel as either the inner or outer layer, protocol switching, and algorithm or protocol swapping, with a protocol interface package for firewalls and an inline encryptor on the 2026 roadmap.
Their pitch to a board is that this is the last cryptographic replacement cycle you fund. Standards will change again, they always do and the next change becomes a configuration event, not a capital project.

Why CISOs Should Care
Let me be candid. The sample size of vendors who’ve overpromised on this exact topic is large. Every year we’re sold future proof, and every year it ages badly. What separates American Binary from the pattern is not the marketing. It’s that the central claims can be checked by someone other than the vendor.
- CNSA 2.0 isn’t theirs to grade. NSA defines it, and it is unforgiving enough that partial credit is not available.
- Proof came from outside. Symbolic proof and peer review by DARPA and Galois lineage researchers is a materially different evidentiary posture than a datasheet.
- Production customers exist. An early Oracle partnership and a growing enterprise and government base put this past the proof-of-concept stage.
- Tradeoff runs the right way. Speed and low touch operations mean the control does not have to win an argument against the network team every quarter.
Gaps I’d press on. Certifications are stated as arriving in mid-2026, several interoperability capabilities sit on a roadmap instead of shipping, and the public reference list is thin beyond Oracle. None of that is disqualifying. All of it is worth asking about directly.
Call to Action for CISOs
If you’re a security leader with a post quantum line item on your roadmap and if you’re not, that’s itself the finding four things are worth doing.
- Audit your own claims first. Ask every incumbent network security vendor to state in writing which of the four CNSA 2.0 components their product covers. Not “quantum safe.” Which four. The answers will clarify your roadmap faster than any assessment you could commission.
- Take the pilot. American Binary offers a low-risk pilot. Deploy alongside your current stack in hours, verify daily operations are unaffected, and validate the no touch model in your environment instead of on a slide.
- Read the attestation. It’s available on request. Have your cryptographers, or a trusted third party, actually read it. That’s the entire point of a company that submitted itself to proof.
- Model the transition twice. Price a hybrid step now plus a full migration later. Then price doing it once. The crypto agility claim is where the long-term economics live.
You’re not deciding whether to move to post quantum cryptography. Mathematics, NSA, and adversaries who are already collecting made that decision for you. What you’re deciding is whether you do it once, completely, and with proof or whether you do it in increments and find out years from now, without warning, which increment was the one that mattered. American Binary is betting that in a domain where partial compliance is failure, the shops that refuse partial answers will be the only ones that were ever actually protected.
Author’s Note
This piece follows a July 14, 2026 conversation with Cris Salas, EVP of Sales at American Binary, during a presentation and discussion of Ambit Client. Statements attributed to Salas are reported from that conversation and from American Binary’s technical and corporate documentation. The direct quotation from Dr. Kiniry and Dr. Shrimpton is reproduced from the company’s materials and requires confirmation of clearance prior to publication. Figures cited including CNSA 2.0 timelines, throughput and speed comparisons, and certification status should be verified with American Binary as of the publication date. Ambit, Inc. DBA American Binary, Kirkland, WA. For more information, visit www.ambit.inc.
About the Author
Paul C. James, Jr., known as Kip, is a five-time CISO, six-time CDM CISO of the Year, and retired Marine Corps Gunnery Sergeant with more than twenty years building security and technology programs across SaaS, financial services, defense, and government. A hands-on builder who still writes code, he is the founder of the security software company DarkShadowSec and the author of five books on cybersecurity and AI, including an Amazon bestseller. He holds the CISSP and CRISC. Kip lives in Castle Rock, Colorado, where he mountain bikes, makes chocolate from scratch, and games, and where a Marine’s bias for ownership still shows up in everything he does.

