Moeris
Prepares an organisation for the day today’s cryptography stops protecting its data.
What it is for
Prepare an organisation for the moment quantum computers render today’s protective cryptography useless, and defend it automatically in the meantime.
What it does
Inventories all the cryptography a company uses without knowing it, assesses what is at risk, proposes and executes the post-quantum migration, and runs an autonomous guardian that observes, decides and acts under human supervision with an auditable record of every decision.
Sector
Enterprise cybersecurity and regulatory compliance: banking, insurance, energy, public administration and defence.
What it improves
Post-quantum migration is done today with manual consulting, spreadsheets and months of work. Here it becomes a continuous, measurable, reversible process that can be demonstrated to an auditor.
Target client
Large regulated organisations and cybersecurity consultancies that want to offer the service.
Status and maturity
The most advanced asset in the portfolio: complete modular architecture (discovery, graph, risk, policy, migration, compliance), its own web interface and active development.
Differentiator
It does not merely use post-quantum cryptography: it governs cryptographic change as a living process, with anti-downgrade guarantees and signed evidence verifiable by third parties.
Commercial fit
Annual enterprise licence per environment plus implementation services, aligned with European regulatory pressure (NIS2, DORA) and national post-quantum migration plans.
Architecture
Layered architecture
A server platform deployable inside the client perimeter, organised as a governed autonomous core plus a battery of functional modules resting on three specialised stores: relational for business truth, graph for blast radius, cache for coordination.
-
01
Autonomous core
Observe–orient–decide–act loop with explicit governance: authorisation gates, emergency stop and a signed record of every decision. The default policy is deterministic; reinforcement learning and the language model are optional extensions, off by default.
-
02
Cryptographic agility
Sovereign key custody with secret sharing, epoch-versioned suite registry, hot rotation and a chained ledger whose signatures a third party can verify without access to the system.
-
03
Discovery and graph
Inventory of the cryptography actually in use — transport, certificates, configuration, code, key managers — projected onto an asset graph that answers the operational question: if I break this, what falls.
-
04
Risk and policy
Multi-factor risk engine for the harvest-now-decrypt-later threat, and a declarative policy engine with a built-in fallback evaluator when the external one is unavailable.
-
05
Orchestration and assurance
Migration executed through change proposals and tickets, plus post-hoc verification and drift detection: it checks that what was migrated stays migrated.
-
06
Boundary and observability
Versioned interface contract, dual authentication (operator and autonomous guardian), rate limits, hardened headers, traces and per-request metrics.
Inventory
Status per component
A real inventory of the asset’s components with their declared status. We publish capability, never code or internal figures.
-
Governance and audit core
Built and testedChained signed ledger, externally verifiable with a proprietary tool; emergency stop and hash-armed actions operational.
-
Functional modules (discovery, graph, risk, policy, orchestration, assurance, reporting)
Built and testedComplete modular architecture covered by an automated suite.
-
Real post-quantum cryptography
Functional with declared debtOptional post-quantum backend: if the library is absent the system degrades explicitly and fails rather than pretending.
-
Reinforcement learning in the decision policy
Functional with declared debtThe code exists but is not active by default. Without it the decision is a deterministic heuristic, not a learning agent. Declared as such on purpose.
-
Language-model copilot
Wired; depends on a third partyExternal provider, optional and off by default. Every call leaves a trace in the signed ledger; the full text is never stored.
-
Web operations console
Built and testedProprietary security-console interface with a typed client against the versioned contract.
This profile describes capabilities and status, not implementation. Code, architecture documentation and internal figures are shared under a confidentiality agreement during due diligence.
Platforms
Hecate
Protects dozens of client companies from a single console, without mixing their data.
Nemea
Turns bank debt and real-estate portfolios into exploitable investment intelligence.
Infinity
Publishes new-build real-estate developments automatically, with its own viewer and the client’s brand.
Taranis
Anticipates blackouts and grid instability before they happen.