Demo

Encrypted against the computers that do not exist yet.

Every hop of the network uses hybrid post-quantum key exchange, so traffic captured today stays unreadable tomorrow.

Real-time data is only an advantage while nobody else has it. An adversary who cannot break today's encryption can still record your traffic today and decrypt it later, once a cryptographically relevant quantum computer exists - and by then your subscriptions, your entities, and the timing of your interest are all readable history. EdgeOrigin closes that window now rather than at some later migration.

A guarantee is only as long as the path you own.

Encryption claims are easy to make and hard to check, so the question worth asking a vendor is not whether they encrypt but where the guarantee stops. A provider that collects in one place, enriches in another, and hands delivery to a third party can speak for the legs it operates and no more. The legs it does not own are where a session quietly falls back to whatever the intermediary negotiated.

Every hop between an event and your systems belongs to us: the edge node that heard it, the links between our own regions, and the point of presence that serves you. That is what makes "post-quantum on every hop" a statement about the whole path rather than about the last mile, and it is the same structural argument that makes a latency figure measurable and a provenance chain unbroken.

The choice inside each hop is deliberately conservative. Sessions negotiate a hybrid key exchange rather than a post-quantum scheme alone, because lattice cryptography is newer than the traffic it protects, and the classic curve it is paired with has had decades of attack behind it. Neither is trusted by itself. Combined with forward secrecy, what an eavesdropper stores today stays noise regardless of which half gives way first.

One handshake, two exchangesx25519mlkem768

X25519

Elliptic-curve exchange

Decades of analysis behind it. Falls to a large quantum computer.

ML-KEM-768

Lattice-based encapsulation

FIPS 203, published August 2024. No known quantum attack.

One session secret

Both results are combined, so the traffic is readable only to an adversary who breaks both schemes. A session recorded today stays unreadable when one of them eventually gives way.

every hop - node to network, region to region, network to you

Neither half is trusted alone. The classic exchange is the one with decades of scrutiny; the post-quantum one is the one a future computer cannot unwind. The session keys are derived from both.

What every connection actually negotiates.

Encryption is where vendors are vaguest, because vagueness is hard to disprove. So this is the specific answer: what is negotiated, on which legs of the path, against which published standard, and what remains true if one of those standards is broken later.

Hybrid key exchange, not a swap

Sessions negotiate X25519MLKEM768: classical X25519 and post-quantum ML-KEM-768 together, so a session is only breakable by someone who defeats both. Hybrid is the deliberate choice - a lattice scheme alone would stake everything on cryptography that is newer than the traffic it protects.

Applied to every hop

Edge node to network, network to your systems, and between our own regions. There is no leg of the path where a record travels under classic TLS alone, because we own every hop rather than handing delivery to a third party.

Standards, named

ML-KEM is specified in NIST FIPS 203 and ML-DSA in FIPS 204, both published in August 2024. X25519MLKEM768 is a registered, recommended TLS supported group. We name the designations so your security team can check them rather than take our word for it.

Forward secrecy that stays forward

Session keys are ephemeral and rotated, so forward secrecy holds and past sessions cannot be recovered from a later key compromise. Combined with post-quantum key exchange, a captured session stays captured noise. This is forward secrecy doing the half of the job a future computer cannot touch.

What an eavesdropper learns from encrypted traffic later.

The instinct is to treat this as a data-loss question, and for most vendors it is. For a data provider serving funds and research teams it is not: the records themselves are often public somewhere. What is never public is which of them a particular firm chose to watch, and when - which is why harvest now, decrypt later is a commercial risk here rather than a theoretical one. That is the asset in the ciphertext, and unlike a price it does not expire.

  1. 01

    Which entities you watch

    A subscription list is a portfolio map. Decrypted two years late, it still reveals what a desk was building, when it started, and what it abandoned.

  2. 02

    When your interest began

    Timing is the whole signal. The moment a fund starts consuming a particular stream is often more informative than any single record inside it.

  3. 03

    What your models train on

    For an ML team, the composition of the training data is the moat. Recovered traffic exposes the corpus, the refresh cadence, and the weighting.

  4. 04

    Your operating pattern

    Volumes, regions, and query rhythm describe how a firm works - the kind of detail that never appears in a filing.

This is why the transport matters as much as the data itself. Owning every hop of the network is what makes the guarantee enforceable end to end - see how the edge network is built.

Read the delivery docs

The questions a security reviewer asks.

Is post-quantum encryption actually necessary today?
The risk is not that a quantum computer reads your traffic today; it is that recorded traffic is cheap to store and can be decrypted whenever one arrives. Any data whose value outlives the storage cost of the ciphertext is exposed, and a trading or training strategy easily qualifies.
Why hybrid rather than post-quantum alone?
Hybrid combines a well-understood classic elliptic-curve exchange with a post-quantum one, so a break in either leaves the session protected by the other. Until the newer schemes have the same decades of analysis behind them, that is the conservative position.
Does this slow delivery down?
Hybrid key exchange adds bytes to the handshake, not to every record, and it happens once per connection. On streaming connections that stay open the cost is amortized to nothing, which is one more reason we prefer streams to polling.
What about data at rest and record signing?
Records are stored encrypted, and provenance metadata is signed so a record cannot be altered between the node that heard it and the system that consumes it. ML-DSA (FIPS 204) is the post-quantum signature standard this path is built toward.

Real-time data, at edge speed.

A live evaluation measures EdgeOrigin against your coverage requirements: decision-ready real-time data, delivery latency into your systems, and record-level provenance.