Redefining data security for the post-quantum era

Presented by Qanapi Qanapi's logo

As defense agencies navigate the intersection of post-quantum threats, rapid artificial intelligence adoption and the evolution of autonomous battlefield capabilities, traditional cybersecurity methods no longer suffice. For many years, IT investments have prioritized digital perimeters — improving networks and firewalls — but data breaches continue to intensify year after year.  

“The cyber industry hasn’t changed much in 30 years,” said Trent Telford, CEO and founder of Qanapi. “The internet wasn’t designed to be secure, it was designed to share information, so now what the industry is trying to do is retrofit and plug it to secure the data.”

Recent federal guidance, including Executive Order 14028 and OMB Memo M-22-09, focuses on implementing zero trust across all five pillars of CISA’s Zero Trust Maturity Model: identity, devices, networks, applications and workloads, and data. Among these, the last pillar remains the most difficult to operationalize — and critical to success.

As highlighted by the Federal Zero Trust Data Security Guide, “defining data down to the cellular level as the new perimeter and adopting dynamic data tagging, labeling and encryption technology” will protect the most sensitive assets. 

Operationalizing post-quantum security

As agencies juggle government mandates, compliance and preparing for the post-quantum era, often with limited budget and workforce resources, security leaders are overwhelmed. They must navigate inefficient legacy systems while securing massive amounts of data and accelerating post-quantum readiness. 

NIST has released several post-quantum cryptography (PQC) standards to help agencies safeguard their information. While adopting these standards checks off an essential step, many leaders are left wondering, “What’s next?”

“You’ve got the NIST library, fantastic. Now, what are you going to do with it?” Telford said. “How are you going to go back and post-quantum ready terabytes, petabytes of data sitting in SQL databases or in legacy systems or cloud apps?”

It is this fundamental operational gap that Telford and Qanapi set out to close.

Zero trust at the data layer

Decades of experience building technology companies, pushing past legacy cybersecurity barriers and leading a startup all the way through an IPO helped Telford create the foundation for a pioneering approach to cybersecurity built for the post-quantum world. 

The answer lies at the data layer — binding identity, policy and encryption to the data object itself. 

“We built a platform on those principles: identity, policy and key management at the object level, through an API service,” Telford said. A quantum API, to be specific, or “Qan-api.”

“Massive cryptoagility on an API platform that can integrate with any combination of systems at huge scale, and the key management and distribution is tied to identity and policy, which completely changes the risk profile of distributing keys out in the wild,” he added. 

When keys are tied directly to an identity, whether a human user or a device, and situational conditions, exposure risks plummet. Telford likened it to leaving your home: rather than tossing keys all over the entryway where any passerby can take one, you only give keys to specific, trusted individuals.

“You already make a conscious decision with your keys that you might give it to your cleaner, or to your partner or to the maintenance guy,” Telford said. “But at least you knew who it was when you gave them that key.”

In practice, it’s about being able to prove who or what you are through credentials and context. For a human that might be clearance levels and classifications. For a drone, it could mean altitude, GPS location and wind speed. 

“If those things add up together as policies, and the identities are correct, and it's got certain encrypted information being sent to it or preloaded on it, we can manage keys based on those conditions,” Telford said. 

Securing AI with ‘dual provenance’

This granular protection extends directly to AI. As AI solutions become deeply integrated into critical missions, verifying data inputs and preventing sensitive data leaks is essential. Wherever data is coming from — sensors on the battlefield, drones in flight, medical devices, the cloud — Qanapi encrypts it at the source under strict policy conditions. 

“We can set conditions around it and then we encrypt it, so now that data can go over any network,” Telford said. “When it hits our gateway, we check: ‘Is it from an authorized trusted identity? Is the policy okay?’ If so we will release that into your, for example, .mil AI instance. If none of those conditions line up, we don't even let that data go into the military AI service.”

Moreover, encrypting specific data elements before AI processing prevents sensitive information from leaking into training inferences. Together, these features provide dual provenance: positive provenance, the ability to cryptographically prove that data going into an AI system can be trusted, and negative provenance, proof that sensitive data elements within a file were encrypted at the field level at source, so the LLM can’t read those elements — all while maintaining a cryptographically verifiable audit trail. Put simply, dual provenance ensures there will be no poisoned data and no confidential data leaked into frontier models or mission-critical AI systems.

From analysis paralysis to action 

For agency leaders who feel overwhelmed by the prospect of achieving post-quantum readiness, industry partnerships can help relieve some of the pressure. By the end of the year, agencies have been instructed by Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks," to “initiate a pilot project for PQC migration on an appropriate subset of information systems owned or operated by NIST.”

Telford urged agencies to begin with a discovery and immediate low hanging fruit remediation. From there, the strategy is simple: start small.

“After an automated discovery scan, start with data sets that aren't going to impact mission-critical systems day one, then you move up the difficulty curve over the next couple years to reach compliance by the deadline,” Telford said. “Let's start with a thin end of the wedge.”

The priority is showing progress with compliance orders now rather than delaying as deadlines approach. At the same time, industry plays a role in helping agencies move forward, with the responsibility to develop more digestible solutions rather than fragmented tools from numerous vendors.

“It’s overwhelming, but historically the industry hasn’t provided you with a holistic approach. We’ll raise our hand and say, ‘Give Qanapi a chance and we’ll give you that holistic approach,” Telford said. “You need a solution and outcome-based approach, not just piecemeal vendors who leave you with reports you can’t remediate, which turns into a risk bomb. We are happy to provide leadership on how we think this can be solved.”

In many ways, this story is about risk — the risks, known and unknown, of the post-quantum era, the risks inherent to emerging technologies, and the risks tied to both action and inaction. Trying a new approach or partner can be daunting, but Telford said defense leaders are beginning to embrace the concept that breakthrough innovations often come from agile, non-traditional vendors.

“Maybe you don’t have a budget issue; you have an allocation issue,” Telford said. “Instead of giving $200 million to a big company, why don’t you give them $180 million, reserve $20 million, and allocate it to smaller companies to see what they can do?”

Learn more about how Qanapi is helping government agencies revolutionize cybersecurity.

This content is made possible by our sponsor Qanapi; it is not written by and does not necessarily reflect the views of Defense One's editorial staff.

NEXT STORY: The Infrastructure Behind the Mission